About this role
## Job Summary
Cybersecurity Risk Analyst
The Cybersecurity Risk Lead is a senior-level individual contributor responsible for helping mature NetApp’s cybersecurity risk management program from a primarily assessment and tracking function into a business decision-enablement capability. This position is based in Bangalore and requires a minimum of three days per week in office. This role will support the identification, assessment, quantification, communication, and monitoring of cybersecurity and AI-related risks across the enterprise. The Cybersecurity Risk Lead will partner with Global Security, Enterprise Risk Management, IT, Product, Engineering, Legal, Privacy, Compliance, Internal Audit, and business stakeholders to ensure risks are consistently evaluated, clearly communicated, appropriately owned, and used to inform business, technology, investment, and governance decisions.
This role requires strong cybersecurity risk experience, practical knowledge of AI risk management, and the ability to translate technical risk into business impact. The ideal candidate can help mature risk processes, improve risk reporting, develop meaningful KPIs and KRIs, support annual and event-driven risk assessments, and build influence across the enterprise by making risk information clear, measurable, and actionable for decision-makers.
## Job Requirements
Duties and Responsibilities
Lead or support cybersecurity risk assessments across business units, technology environments, products, services, vendors, AI-enabled capabilities, and enterprise initiatives.
Support the annual cybersecurity risk assessment process, including scoping, stakeholder engagement, data collection, risk analysis, documentation, reporting, and follow-up on identified risks.
Help mature the cybersecurity risk management program by improving risk intake, assessment methodology, scoring, prioritization, exception handling, risk treatment, remediation tracking, and executive reporting.
Integrate cybersecurity risk practices with Enterprise Risk Management, IT risk, third-party risk, product security, compliance, internal audit, and business planning processes to improve alignment and consistency.
Apply AI risk management concepts and emerging frameworks to support responsible AI adoption, AI-enabled workflows, AI agents, AI tools, and AI-related business or product initiatives.
Assist in defining AI risk assessment criteria, including security, privacy, data handling, transparency, accountability, resilience, human oversight, explainability, and regulatory considerations.
Lead or support the cybersecurity risk exception process across business units, through scoping, stakeholder engagement, and risk assessments. Establishing and maintaining a risk register and ensuring proper follow-through with stakeholders.
Develop and maintain risk metrics, KPIs, KRIs, dashboards, and reporting narratives that help leadership understand risk exposure, business impact, trends, and required decisions.
Support risk quantification activities by translating cybersecurity risks into financial, operational, regulatory, customer, reputational, and business-impact terms.
Use risk measures to communicate what the risk is, why it matters, what decision is needed, what tradeoffs exist, and what business outcomes may be affected.
Partner with business and technical stakeholders to document risk ownership, remediation plans, treatment decisions, compensating controls, escalation paths, and residual risk.
Identify gaps in current risk processes, risk data, tooling, metrics, or reporting and recommend practical improvements that increase consistency, transparency, and decision value.
Promote broader understanding and adoption of the cybersecurity risk program by helping business stakeholders make more informed, risk-based decisions.