Overview
Staff Information Security Analyst (Security Assurance) responsible for security assurance activities for Druva’s data security, privacy, and compliance posture.
Also leads third-party risk management, supports security due diligence, and drives improvement initiatives such as phishing and security awareness.
What you'll do
- Provide internal expert support for security and compliance due diligence requests.
- Coordinate with security, engineering, legal, and customer account teams to respond to prospect/customer security queries.
- Manage security support requests, including security questionnaires, customer audits, and penetration tests when needed.
- Develop and maintain customer-facing security policies and documentation and manage the online trust portal.
- Evaluate and set the third-party risk management strategy and conduct security assessments of existing and new vendors.
- Develop and execute improvement strategy for phishing simulations and employee security training.
What you'll need
- At least 10 years of experience in a technology discipline, preferably 6+ years in the cyber security domain.
- Working protocol-level understanding of at-rest and in-motion encryption fundamentals (TLS/SSL, BCrypt, PKI, SHA1, AES, etc.).
- Knowledge of MITRE ATT&CK, OWASP Top-10 vulnerabilities, and related risks and countermeasures.
- Knowledge of AWS and Azure services and native security controls.
- Technical understanding of SaaS multi-tenant architectures.
- Ability to threat model and assess security risk of interconnected systems and data flows.
- Background in security compliance and privacy frameworks including SOC 2, ISO27001, HIPPA, CSA STAR, NIST 800-53, and NIST CSF.
Nice to have
- Demonstrable customer communication experience around security matters.
Details
- Location: Pune, Maharashtra, India.
Read the full description and apply on the company’s own careers page.