Staff Information Security Analyst - Security Assurance

Druva Inc.
Posted on
Druva Inc. logo

Experience
10 - 15 yrs
Job Location
Pune, India
Vacancy
1
Designation
Information Security Analyst
Job Type
Not specified

Job Description

< p> < strong> Summary:-< /strong> < /p> < p> The Staff Technical Security Analyst, Security Assurance will be responsible for all activities directed at building trust and confidence in Druva s data security, privacy, and compliance posture with prospects and customers.< /p> < p> < strong> Preferred Qualifications/Skills:-< /strong> < /p> < ol> < li> Exceptional communication skills, critical thinking ability and strong bias for ownership learning< /li> < li> Working protocol level understanding of At-Rest and In-Motion Encryption fundamentals (TLS/SSL, BCrypt, PKI, SHA1, AES etc) and Key Management principles< /li> < li> Demostrable knowledge of MITRE ATT@CK framework, OWASP Top-10 Web Application Vulnerabilities and related risks and countermeasures< /li> < li> Knowledge of AWS, Azure services and security controls native to them< /li> < li> Technical Understanding of SaaS Multi-tenant architectures< /li> < li> Knowledge of technical domains such as network security, cloud security application security< /li> < li> Ability to threat model and assess security risk of interconnected systems and data flows< /li> < li> Background in or strong understanding of security compliance and Privacy frameworks (SOC 2, ISO27001, HIPPA, CSA STAR, NIST 800-53, NIST CSF), tools to develop SBOM and information gathering frameworks like SIG and CAIQ< /li> < li> Proven experience collaborating with sales, legal and engineering teams< /li> < li> At least 10 years of experience in a technology discipline, preferably 6+ years in the cyber security domain< /li> < li> Experience implementing or using any TPRM tools or platforms (for e.g. KY3P, ProcessUnity, ServiceNow, CyberGRX etc), familiarity with tools like Security Scorecard, Bitsight etc.< /li> < li> Experience in automating workflows< /li> < li> Demonstrable customer communication experience around security matters is a plus< /li> < /ol> < p> < strong> Responsibilities:-< /strong> < /p> < ol> < li> Own and drive the processes to provide expert internal support for security and compliance due diligence requests< /li> < li> Work and co-ordinate with internal security teams (Cyber Defence, Product Security, Compliance), Engineering, Legal functions and customer account teams to provide timely and high-quality responses to security queries from prospects and customers< /li> < li> Manage incoming security support requests including security focused questionnaires, customer audits, and client-driven penetration tests as needed< /li> < li> Develop and maintain customer facing security policies and documentation and manage the Druvas online trust portal< /li> < li> Ensure customer security documentation and external artifacts are up to date and accurate as per current state security policies< /li> < li> Evaluate and set the strategy for Druva s third-party risk management program< /li> < li> Conduct holistic security assessments of Druva s existing new vendors to identify and mitigate potential risks.< /li> < li> Stay informed about current security vulnerabilities, incidents and assess exposure through Druva s vendor landscape< /li> < li> Own and drive risk-reduction in Druva s External attack surface< /li> < li> Develop and execute on improvement strategy for phishing simulations and security training of our employees< /li> < /ol> Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.