Senior Analyst - Cybersecurity Risk & Compliance
Freshworks
Skill Required
Key highlights
- 3–6 years of experience required
- Focus on AI governance and cybersecurity risk assessments
- Works with cross-functional teams (Product, Engineering, Legal, Privacy)
- Inclusive and diverse work environment
Role overview
Organizations struggle with complex and costly software solutions that often hinder rather than help their operations. Freshworks Inc. offers uncomplicated service software designed to deliver exceptional employee and customer experiences, reducing complexity and cost while enabling faster, more human support. Nearly 75,000 companies, including Bridgestone, New Balance, and Sony Music, trust Freshworks for their Employee Experience (EX) and Customer Experience (CX) needs. The Cybersecurity Risk & Compliance function at Freshworks is responsible for identifying, assessing, and managing cybersecurity and compliance risks, establishing security standards, and partnering with business and technology teams to strengthen the organization's security posture. As a Senior Analyst in this team, you will independently execute cybersecurity risk assessments, compliance reviews, and governance activities while supporting the organization's evolving AI adoption.
Responsibilities
- Conduct cybersecurity risk assessments for products, applications, infrastructure, vendors, and business initiatives, including New Product Initiatives (NPIs).
- Perform AI governance reviews for AI/ML use cases, GenAI integrations, third-party AI services, and agentic workflows by identifying potential security, privacy, and compliance risks.
- Evaluate security risks and recommend appropriate controls aligned with organizational policies and industry best practices.
- Support the implementation and operationalization of cybersecurity policies, standards, and control requirements across business and technology teams.
- Partner with Product, Engineering, Cloud, Privacy, Legal, and other stakeholders to provide practical security guidance throughout project lifecycles.
- Assist with readiness activities for security certifications and compliance frameworks by collecting evidence, validating controls, and supporting internal and external audits.
- Review the effectiveness of implemented security controls and track remediation activities through to closure.
- Support continuous monitoring activities by maintaining risk registers, dashboards, metrics, and compliance reporting.
- Participate in security awareness initiatives by providing guidance on cybersecurity policies, secure development practices, and responsible AI usage.
- Contribute to improving risk assessment methodologies, governance processes, templates, and documentation.
- Identify opportunities to automate repetitive risk and compliance activities to improve operational efficiency.
- Stay current with emerging cybersecurity threats, regulatory developments, cloud security trends, and AI governance practices.
- Independently execute cybersecurity and AI risk assessments.
- Review business initiatives for compliance with security policies and standards.
- Support audit readiness and evidence collection activities.
- Perform security reviews for new technologies and third-party services.
- Track remediation plans and validate control implementation.
- Maintain governance documentation, risk registers, and assessment artifacts.
- Provide day-to-day cybersecurity guidance to business and engineering teams.
- Contribute to continuous improvement of governance processes and automation initiatives.
Requirements
- 3–6 years of experience in Cybersecurity Risk & Compliance, Information Security, Governance, Risk & Compliance (GRC), or related domains.
- Experience conducting cybersecurity risk assessments, security reviews, compliance assessments, or control validation activities.
- Working knowledge of cloud security concepts, preferably AWS, and common cloud security controls.
- Familiarity with cybersecurity frameworks such as ISO 27001, SOC 2, NIST CSF, PCI DSS, HIPAA, NIST 800-171, or similar frameworks.
- Strong analytical and problem-solving skills with the ability to evaluate security risks and recommend practical solutions.
- Excellent written and verbal communication skills with experience working across cross-functional teams.
Nice to have
- Exposure to AI governance concepts, AI risk assessments, or emerging AI security considerations.
- Understanding of common AI/ML security risks, including: Data leakage, Prompt injection, Hallucination and model reliability, Third-party AI integrations, Bias and fairness considerations.
- Familiarity with software development and cloud technologies, including: AWS, Kubernetes, Docker, CI/CD pipelines, GitHub.
- Relevant certifications such as Security+, CISA, CISM, CRISC, AWS Security Specialty, or similar certifications.
Benefits
- An environment that enables everyone to find their true potential, purpose, and passion, welcoming colleagues of all backgrounds, genders, sexual orientations, religions, and ethnicities.
- Commitment to providing equal opportunity and a diverse, vibrant, and richer workplace.
Additional details
- The Cybersecurity Risk & Compliance function is responsible for identifying, assessing, and managing cybersecurity and compliance risks across the organization. The team establishes security standards, validates adherence to security controls, and partners with business and technology teams to strengthen the organization's security posture.