# Information Security Analyst III

> Datamark, Inc. · Chennai, India · Full-time · Posted 2026-08-02

**Workplace:** on_site

**Department:** Chennai

## Description

As an Information Security Analyst III, you are the senior member of the Information Security Team and the primary owner of DATMARK's most significant security work. Your main focus is leading the response to all High and Critical severity tickets and incidents, drawing from “hands-on” incident response experience to contain, eradicate, and recover from threats. You are responsible for implementing new Information Security controls and for the ongoing maintenance and upkeep of existing ones. You oversee the work of the Information Security Analyst I and II, mentoring and developing the team, with particular focus on growing the Analyst I while recommending risk mitigation solutions based on audit findings and threat intelligence to continuously strengthen DATAMARK's security posture.

**Primary Responsibilities:**

1. Systems Management and Technical Support (80%)

o    Serves as the primary responder and owner for all High and Critical severity tickets and incidents.

o    Leads Incident Response end to end; applying hands-on Incident Response experience to contain, eradicate, and recover from incidents, and conducts post-incident reviews and lessons learned.

o    Responsible for the implementation of new Information Security controls, from evaluation and design through deployment and validation.

o    Responsible for the ongoing maintenance, upkeep, and tuning of existing information security controls.

o    Collaborate with the Director of Information Security on Security Architecture, standards, and the Security Roadmap.

o    Oversees all Information Security Analyst I and II tasks, and assists, mentors, and develops the team with particular focus on growing the Analyst I.

o    Continuously analyzes all organizational systems and reviews daily threat intelligence to identify and prioritize risk.

o    Reviews and prioritizes vulnerability findings and drives remediation with the Information Security Analyst I/II and the IT Team through to closure.

o    Recommends risk mitigation solutions based on audit findings and threat intelligence.

o    Evaluates, pilots, and recommends new security tooling and technologies.

o    Maintains and reports on security and compliance metrics monthly.

o    Develops and maintains incident response playbooks, runbooks, and standard operating procedures.

o    Assists in reviewing and assessing technical deployments for risk before company-wide implementation and ensures compliance with security standards.

o    Administers, supports, and maintains enterprise IT security systems, including troubleshooting and remediation of complex system issues.

o    Works with the IT Team to provide timely, effective support and maintains system documentation, including network and data flow diagrams.

As the Senior owner (covering architecture, system maintenance and escalation) the Information Security Analyst III is responsible for the following security platforms and audits, with day-to-day operation performed by the Information Security Analyst I and II:

o    **SIEM/MDR (Security Information and Event Management) (Managed Detection Response)**

·          Regularly verify that all configured log sources (firewalls, servers, intrusion detection systems, etc.) send logs to the SIEM without errors.

·          Fine-tune existing correlation rules to reduce false positives and improve the accuracy of threat detection. This involves analyzing alerts, adjusting thresholds, and refining rule logic.

·          Investigate suspicious events and security incidents identified by the SIEM, using the available log data and other information to determine the root cause and scope of the issue.

·          Follow established incident response procedures to contain, eradicate, and recover from security incidents.

o    **PAM (Privileged Access Management)**

·          Maintain and update Privileged Access Management at the Application Level.

·          Maintain the use of Privileged Accounts.

·          Monitor abuse attempts of standard and Privileged Accounts.

o    **DLP (Data Loss Prevention) Management**

·          Regularly review alerts to identify potential data breaches or policy violations.

·          Fine-tune policies to minimize false positives and negatives.

·          Create new policies to address emerging threats and data protection needs.

·          Monitor system performance and resource utilization to ensure optimal operation.

o    **NAC (Network Access Control) Management**

·          Continuously monitor the NAC system dashboard for any alerts, alarms, or suspicious activities. This includes failed authentication attempts, unauthorized access attempts, and devices violating security policies.

·          Investigate and respond to NAC alerts promptly. Follow established incident response procedures to contain and mitigate any security incidents.

·          Ensure consistent enforcement of NAC policies across the network. Regularly audit policy configurations to verify effectiveness and identify potential gaps.

·          Monitor the overall health and performance of the NAC system. Check system resources, database integrity, and software updates.

·          Work with IT teams, system owners, and other stakeholders to implement remediation plans. This may involve patching systems, updating software, changing configurations, or implementing workarounds.

o    **NDR (Network Detection and Response) Management**

·          Monitor for unusual traffic spikes, unexpected connections, or communication with known malicious IPs/domains.

·          Investigate any events that seem suspicious or unusual.

·          Fine-tune model settings and thresholds to better align with Datamark's risk tolerance.

·          Regularly check system health and performance to ensure it is operating optimally.

o    **Microsoft Entra ID (working knowledge)**

·          Maintain working knowledge of identity and access configuration, conditional access policies, and sign-in/audit logging in Microsoft Entra ID.

o    **Cisco Secure Access (working knowledge)**

·          Maintain working knowledge of Cisco Secure Access (SSE) policy, secure connectivity, and access enforcement.

o    **Universal SSO (working knowledge)**

·          Maintain working knowledge of Universal Single Sign-On integrations and authentication flows for enterprise applications.

o    **Micro-Segmentation (working knowledge)**

·          Maintain working knowledge of network micro-segmentation design and policy enforcement to limit lateral movement.

o    **CSPM (working knowledge)**

·          Maintain working knowledge of Cloud Security Posture Management (CSPM) findings, misconfigurations, and overall cloud compliance posture.

o    **Ai Security (working knowledge)**

·          Maintain working knowledge of best practices to secure in house applications using Ai, external LLMs and Autonomous Agents. This includes working with the Director of Information Security to create an internal framework to properly secure how an agent connects from MCP Servers to APIs.

o    May also be responsible for any upcoming technical controls that may be implemented.

2. Compliance and Governance (10%)

o    Create and remediate any incidents found during the technical control review process.

o   Verify that assigned controls are working within agreed upon SLAs and vendor specifications.

o    Works independently to follow established security protocols to safeguard the organization's IT infrastructure.

o    Works independently to ensure compliance with relevant Security Frameworks and Regulations from CIS and NIST CSF to PCI, SOC 2 Type II, and ISO 27001.

3. Administrative Duties (10%)

o    Responsible for creating and updating Standard Operating Procedures.

o    Maintain assigned technical control documentation.

o    Create new documentation or procedures per the direction of the Director of Information Security.

o    Provide guidance and support to the Information Security Analyst I and II.

o    Willingness to travel to DATAMARK global sites as necessary.

## Requirements

**Minimum Qualifications:**

·         **Education Requirements:**

o   Bachelor’s degree in Computer Science or related field, field experience in lieu of degree can be considered

·         **Field Experience:**

o   At least five years of experience in Information Security.

·         **Position Experience:**

o    At least 1 year of experience in a senior or lead Information Security Analyst role, including hands-on incident response (detection, containment, eradication, and recovery).

o    Demonstrated experience with traditional vulnerability analysis: identifying, categorizing, prioritizing, tracking, and validating remediation of known vulnerabilities by accountable IT teams.

·         **Other Qualifications:**

o   One or more of the following:

ISC2 CISSP (Certified Information Systems Security Professional) is highly preferred

ISC2 CCSP (Certified Cloud Security Professional)

GIAC GCIH (Certified Incident Handler)

CompTIA CASP+ (Advanced Security Practitioner)

ISACA CISA (Certified Information Systems Auditor)

**Required Skills:**

-   Extremely organized and detail oriented 
-   Capable of holding team members accountable to timely delivery of audit evidences
-   Practices and methods of IT strategy, enterprise architecture and security architecture
-   Excellent analytical and problem-solving abilities to identify and remediate security risks
-   Team-work mentality to develop security solutions in collaboration with other IT professionals

## Benefits

Bundle of Benefits as follow;

PF

Gratuity

Mediclaim

## Apply

[Apply at Datamark, Inc.](https://apply.workable.com/datamark-inc/j/8638F3EA96/apply)

---
Powered by [Workable](https://www.workable.com)
