D

Staff Information Security Analyst - Security Assurance

Druva

🟢 Active · Posted Today  ·  👁 5 views  ·  👥 4 applied

📍 LocationPune
💼 Job TypeFull-Time
⏱ Experience5+ years
🎓 QualificationAny Graduate
🛠 SkillsCommunication, Critical Thinking, Encryption & Key Management, MITRE ATT&CK & OWASP, Cloud Security (AWS/Azure), SaaS Multi-tenant Architecture, Threat Modeling, Security Compliance (SOC2, ISO27001, NIST)

Job Description

Druva is looking for a Staff Information Security Analyst to lead security assurance activities that build trust with prospects and customers. The role sits at the intersection of compliance, third‑party risk, and security culture, requiring a hands‑on approach to questionnaires, audits, and the company’s trust portal.

Key Responsibilities:

  • Own and drive the end‑to‑end process for security and compliance due‑diligence requests from customers and prospects.
  • Coordinate with Cyber Defence, Product Security, Compliance, Engineering, Legal, and account teams to deliver timely, high‑quality responses.
  • Manage incoming security questionnaires, customer audits, and client‑driven penetration tests.
  • Develop and maintain customer‑facing security policies and the online trust portal, keeping all artifacts current.
  • Define and execute the third‑party risk management strategy, assessing existing and new vendors for risk.
  • Monitor the external attack surface and stay ahead of emerging vulnerabilities across the vendor landscape.
  • Design and improve phishing simulation programs and security awareness training for employees.

Required Skills:

  • Strong communication, critical thinking, and ownership mindset.
  • Deep knowledge of encryption protocols (TLS/SSL, PKI, AES) and key‑management principles.
  • Familiarity with MITRE ATT&CK, OWASP Top‑10, and related countermeasures.
  • Hands‑on experience with AWS and Azure security controls.
  • Understanding of SaaS multi‑tenant architectures and threat‑modeling techniques.
  • Expertise in compliance frameworks such as SOC 2, ISO 27001, HIPAA, NIST 800‑53/CSF.
  • Experience with TPRM platforms (e.g., KY3P, ProcessUnity, ServiceNow, CyberGRX) and risk‑scoring tools like SecurityScorecard or BitSight.
  • Ability to automate workflows and communicate security posture to customers.

This role is verified by Employee Table — no fees to apply.

Apply Now ↗ 🔖 Save Job

✅ Verified by Employee Table — free to apply, no registration fee required.

Join WhatsApp m