Analyst - Business Risk Controls Management

TIAA

Pune, INonsitePosted Jul 21, 2026
Posting intelligenceActively listedReposted 38×, possible evergreen/ghost posting

Skills

azureexcelgooglecloudaws

About the role

The Application Risk Assessment team serves as the first line of risk defense for the organization’s application landscape. The team works closely with engineering and product teams to identify, assess, and reduce security risks early in the application lifecycle. By applying structured methodologies aligned with frameworks such as NIST CSF and ISO 27001, the team ensures applications are designed and operated with strong security controls. This role places you at the intersection of technology and risk, where your assessments directly influence design decisions, strengthen security posture, and enable safe and reliable product delivery.

Key Responsibilities and Duties

Perform application risk assessments using defined frameworks.

Validate security controls across various application control programs.

Identify risks in enterprise applications, rate severity, and document findings based on the assessments.

Track remediation actions and follow up with application owners.

Support risk evaluations.

Maintain accurate records in GRC tools.

Contribute to playbooks, templates, and process improvements.

Educational Requirements

Vocational and/or Technical Education Preferred

Work Experience

3+ Years Required; 5+ Years Preferred

Physical Requirements

Physical Requirements: Sedentary Work

Career Level

4IC

Expectations

Deliver assessment results on time with clear documentation.

Communicate risks in simple, business friendly language.

Show ownership of assigned application related tasks.

Ask the right questions when requirements are unclear.

Continuously improve technical and risk knowledge.

Maintain confidentiality and data handling discipline.

Non-Negotiables

Strong integrity and ethical judgment.

Adherence to defined assessment methodology.

Clear and timely communication of risks.

Willingness to learn core security concepts within the first 90 days.

Required Skills

1+ years of experience in cybersecurity, risk, or application support.

Basic understanding of web applications and APIs.

Knowledge of common vulnerabilities such as those in OWASP Top 10.

Familiarity with authentication and access control concepts.

Ability to read and understand technical documentation.

Strong analytical and problem-solving ability.

Good written and verbal communication.

Working knowledge of Excel and documentation tools.

Preferred Skills

Exposure to secure SDLC practices.

Understanding of cloud basics in AWS, Azure, or GCP.

Familiarity with risk frameworks like NIST CSF 2.0 or ISO 27001.

Experience with any GRC tool.

Internship or project experience in cybersecurity.

Related Skills

Business Acumen, Business Process Improvement, Business Process Understanding, Communication, Compliance, Continuous Improvement Mindset, Detail-Oriented, General Risk Management, Influence, Relationship Management, Risk Mitigation, Risk Monitoring

_____________________________________________________________________________________________________

Company Overview

TIAA Global Capabilities was established in 2016 with a mission to tap into a vast pool of talent, reduce risk by insourcing key platforms and processes, as well as contribute to innovation with a focus on enhancing our technology stack. TIAA Global Capabilities is focused on building a scalable and sustainable organization , with a focus on technology , operations and expanding into the shared services business space.

Working closely with our U.S. colleagues and other partners, our goal is to reduce risk, improve the efficiency of our technology and processes and develop innovative ideas to increase throughput and productivity.

Our Culture of Impact

At TIAA, we're on a mission to build on our 100+ year legacy of delivering for our clients while evolving to meet tomorrow's challenges. We equip our associates with future-focused skills and AI tools that enable us to advance our mission. Together, we are fighting to ensure a more secure financial future for all and for generations to come. We are guided by our values: Champion Our People, Be Client Obsessed, Lead with Integrity, Own It, and Win As One. They influence every decision we make and how we work together to serve our clients every day. We thrive in a collaborative in-office environment where teams work across organizational boundaries with shared purpose, accelerating innovation and delivering meaningful results. Our workplace brings together TIAA and Nuveen's entrepreneurial spirit, where we work hard and work together to create lasting impact. Here, every associate can grow through meaningful learning experiences and development pathways - because when our people succeed, our impact on clients' lives grows stronger.

Accessibility Support

If you are a U.S. applicant and desire a reasonable accommodation to complete a job application please use one of the below options to contact our accessibility support team:

Phone: (800) 842-2755

Email: accessibility.support@tiaa.org

Questions about this role

Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

Compensation for Other roles in India varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Other hub for India medians across recent openings.

Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, Personio, Teamtailor and other major ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.