Sr. Manager - Security Assurance
Pune
Druva
Druva's SaaS platform is a fresh take on data security backed by a $10M guarantee. Protect your data wherever it lives with our cloud-based security solution.
About Druva
Druva, the autonomous data security company, puts data security on autopilot with a 100% SaaS, fully managed platform to secure and recover data from all threats. The Druva Data Security Cloud ensures the availability, confidentiality, and fidelity of data - providing customers with autonomous protection, rapid incident response, and guaranteed data recovery. The company is trusted by its more than 6,000 customers, including 65 of the Fortune 500, to defend business data in today’s ever-connected world. Amidst a rapidly evolving security landscape, Druva offers a $10 million Data Resiliency Guarantee ensuring customer data is protected and secured against every cyber threat. Visit druva.com and follow us on LinkedIn, Twitter and Facebook.
Establish a formal and robust Risk Management/Governance Program which will identify and assess risks to build realistic plans to remediate and sustain a control environment driven by multiple compliance frameworks.
Summary:-
The Sr. Manager of Security Assurance will be responsible for all initiatives directed at building trust and confidence in Druva’s data security, privacy, and compliance posture. Additionally, they will lead Druva’s Third-Party Risk Management program and drive execution and improvement in our security culture improvement initiatives around phishing and security awareness.
Preferred Qualifications:-
- Background in or strong understanding of security compliance and Privacy frameworks (SOC 2, ISO27001, HIPPA, CSA STAR, NIST)
- Demostrable knowledge of OWASP Top-10 Web Application Vulnerabilities and related risks and countermeasures
- Working protocol level understanding of At-Rest and In-Motion Encryption fundamentals (TLS/SSL, BCrypt, PKI, SHA1, AES etc)
- Knowledge of AWS and security controls native to AWS
- Technical Understanding of SaaS Multi-tenant architectures
- Ability to threat model and assess security risk of interconnected systems and data flows
- Proven experience collaborating with sales and engineering teams
- Demonstrable customer communication experience around security matters
- Experience implementing or using any TPRM tools or platforms (for e.g. KY3P, ProcessUnity, ServiceNow, CyberGRX etc)
- Knowledge of technical domains such as network security, cloud security & application security
- Exceptional communication skills, critical thinking ability and strong bias for ownership & learning
- Experience leading teams, building and monitoring cross-functional scaled-up processes to achieve business objectives
- At least 12 years of experience in a technology discipline, preferably 8+ years in the cyber security domain
Responsibilities:-
- Own and drive the processes to provide expert internal support for security and compliance due diligence requests
- Work and co-ordinate with internal security teams (Cyber Defence, Product Security, Compliance), Engineering functions and customer account teams to provide timely and high-quality responses to security queries from prospects and customers
- Manage incoming security support requests including security focused questionnaires, customer audits, and client-driven penetration tests as needed
- Develop and maintain customer facing security policies and documentation and manage the Druva's online trust portal
- Ensure customer security documentation and external artifacts are up to date and accurate as per current state security policies
- Evaluate and set the strategy for Druva’s third-party risk management program
- Conduct holistic security assessments of Druva’s existing & new vendors to identify and mitigate potential risks.
- Stay informed about current security vulnerabilities, incidents and assess exposure through Druva’s vendor landscape
- Own and drive risk-reduction in Druva’s External attack surface
- Develop and execute on improvement strategy for phishing simulations and security training of our employees
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: AES Application security Audits AWS Cloud Compliance Encryption Governance Incident response ISO 27001 Monitoring Network security NIST OWASP PKI Privacy Product security Risk management SaaS Security assessment SOC SOC 2 Strategy TLS Vulnerabilities
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.