Staff Information Security Analyst - Security Assurance

druva

Pune, INonsitePosted Jun 3, 2026
Posting intelligenceMay be filled, listed long ago

Skills

azureaws

About the role

About Druva Druva is the resilience foundation for the AI enterprise, helping organizations secure and recover from connected risk across data, cyber, identity, and AI. The Resilience Cloud is a fully managed, cloud-native SaaS platform that delivers air-gapped and immutable protection across cloud, SaaS, on-premises, endpoint, and edge environments. Powered by Dru MetaGraph, Druva’s graph-powered intelligence layer, the platform connects critical business context so customers can understand risk, respond faster, recover cleanly, and govern data with greater confidence.

Trusted by nearly 7,500 customers, including 75 of the Fortune 500, Druva helps safeguard the critical information and systems businesses depend on in an increasingly connected world.

Visit druva.com and follow us on LinkedIn, X and Facebook.

Summary:-

The Staff Technical Security Analyst, Security Assurance will be responsible for all activities directed at building trust and confidence in Druva’s data security, privacy, and compliance posture with prospects and customers.

Additionally, they will be responsible for Druva’s Third-Party Risk Management program and drive execution and improvement in Druva’s security culture improvement initiatives around phishing and security awareness.

Preferred Qualifications/Skills:-

Exceptional communication skills, critical thinking ability and strong bias for ownership & learning

Working protocol level understanding of At-Rest and In-Motion Encryption fundamentals (TLS/SSL, BCrypt, PKI, SHA1, AES etc) and Key Management principles

Demostrable knowledge of MITRE ATT@CK framework, OWASP Top-10 Web Application Vulnerabilities and related risks and countermeasures

Knowledge of AWS, Azure services and security controls native to them

Technical Understanding of SaaS Multi-tenant architectures

Knowledge of technical domains such as network security, cloud security & application security

Ability to threat model and assess security risk of interconnected systems and data flows

Background in or strong understanding of security compliance and Privacy frameworks (SOC 2, ISO27001, HIPPA, CSA STAR, NIST 800-53, NIST CSF), tools to develop SBOM and information gathering frameworks like SIG and CAIQ

Proven experience collaborating with sales, legal and engineering teams

At least 10 years of experience in a technology discipline, preferably 6+ years in the cyber security domain

Experience implementing or using any TPRM tools or platforms (for e.g. KY3P, ProcessUnity, ServiceNow, CyberGRX etc), familiarity with tools like Security Scorecard, Bitsight etc.

Experience in automating workflows

Demonstrable customer communication experience around security matters is a plus

Responsibilities:-

Own and drive the processes to provide expert internal support for security and compliance due diligence requests

Work and co-ordinate with internal security teams (Cyber Defence, Product Security, Compliance), Engineering, Legal functions and customer account teams to provide timely and high-quality responses to security queries from prospects and customers

Manage incoming security support requests including security focused questionnaires, customer audits, and client-driven penetration tests as needed

Develop and maintain customer facing security policies and documentation and manage the Druva's online trust portal

Ensure customer security documentation and external artifacts are up to date and accurate as per current state security policies

Evaluate and set the strategy for Druva’s third-party risk management program

Conduct holistic security assessments of Druva’s existing & new vendors to identify and mitigate potential risks.

Stay informed about current security vulnerabilities, incidents and assess exposure through Druva’s vendor landscape

Own and drive risk-reduction in Druva’s External attack surface

Develop and execute on improvement strategy for phishing simulations and security training of our employees

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on druva's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Security Engineer roles in India varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for India medians across recent openings.

You never touch the form - the application is filled and submitted for you on druva's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.