Staff Information Security Analyst - Security Assurance
Druva · Pune, Maharashtra, India
experiencedPune, Maharashtra, IndiaPosted 3 Jun 2026
This listing is from the archive and may be closed. Browse the latest experienced jobs for current openings.
Druva is hiring a Staff Information Security Analyst - Security Assurance in Pune.
Responsibilities
- Own and drive the processes to provide expert internal support for security and compliance due diligence requests
- Work and co-ordinate with internal security teams (Cyber Defence, Product Security, Compliance), Engineering, Legal functions and customer account teams to provide timely and high-quality responses to security queries from prospects and customers
- Manage incoming security support requests including security focused questionnaires, customer audits, and client-driven penetration tests as needed
- Develop and maintain customer facing security policies and documentation and manage the Druva's online trust portal
- Ensure customer security documentation and external artifacts are up to date and accurate as per current state security policies
- Evaluate and set the strategy for Druva’s third-party risk management program
- Conduct holistic security assessments of Druva’s existing & new vendors to identify and mitigate potential risks.
- Stay informed about current security vulnerabilities, incidents and assess exposure through Druva’s vendor landscape
- Own and drive risk-reduction in Druva’s External attack surface
- Develop and execute on improvement strategy for phishing simulations and security training of our employees
Preferred qualifications
- Exceptional communication skills, critical thinking ability and strong bias for ownership & learning
- Working protocol level understanding of At-Rest and In-Motion Encryption fundamentals (TLS/SSL, BCrypt, PKI, SHA1, AES etc) and Key Management principles
- Demostrable knowledge of MITRE ATT@CK framework, OWASP Top-10 Web Application Vulnerabilities and related risks and countermeasures
- Knowledge of AWS, Azure services and security controls native to them
- Technical Understanding of SaaS Multi-tenant architectures
- Knowledge of technical domains such as network security, cloud security & application security
- Ability to threat model and assess security risk of interconnected systems and data flows
- Background in or strong understanding of security compliance and Privacy frameworks (SOC 2, ISO27001, HIPPA, CSA STAR, NIST 800-53, NIST CSF), tools to develop SBOM and information gathering frameworks like SIG and CAIQ
- Proven experience collaborating with sales, legal and engineering teams
- At least 10 years of experience in a technology discipline, preferably 6+ years in the cyber security domain
- Experience implementing or using any TPRM tools or platforms (for e.g. KY3P, ProcessUnity, ServiceNow, CyberGRX etc), familiarity with tools like Security Scorecard, Bitsight etc.
- Experience in automating workflows
- Demonstrable customer communication experience around security matters is a plus
About Druva
Druva is the resilience foundation for the AI enterprise, helping organizations secure and recover from connected risk across data, cyber, identity, and AI. The Resilience Cloud is a fully managed, cloud-native SaaS platform that delivers air-gapped and immutable protection across cloud, SaaS, on-premises, endpoint, and edge environments. Powered by Dru MetaGraph, Druva’s graph-powered intelligence layer, the platform connects critical business context so customers can understand risk, respond f