Principal GRC Analyst (Risk, IA, Controls)

Posted 17 Days Ago
Be an Early Applicant
Pune, Maharashtra
7+ Years Experience
Cloud • Information Technology • Security • Software • Cybersecurity
Data Protection for the cloud era.
The Role
Establish a formal and robust Risk Management/Governance Program to identify and assess risks, develop control environments, and provide oversight for technology and information security risks. Responsibilities include internal audit, risk management, strategic planning, assessment, and collaboration with internal partners.
Summary Generated by Built In


About Druva 

Druva, the autonomous data security company, puts data security on autopilot with a 100% SaaS, fully managed platform to secure and recover data from all threats. The Druva Data Security Cloud ensures the availability, confidentiality, and fidelity of data - providing customers with autonomous protection, rapid incident response, and guaranteed data recovery. The company is trusted by its more than 6,000 customers, including 65 of the Fortune 500, to defend business data in today’s ever-connected world. Amidst a rapidly evolving security landscape, Druva offers a $10 million Data Resiliency Guarantee ensuring customer data is protected and secured against every cyber threat. Visit druva.com and follow us on LinkedIn, Twitter and Facebook.

Establish a formal and robust Risk Management/Governance Program which will identify and assess risks to build realistic plans to remediate and sustain a control environment driven by multiple compliance frameworks.

Responsibilities:

Internal Audit

  • Evaluate the adequacy and effectiveness of applicable policies, procedures, processes, systems and internal controls.
  • Perform gap analysis on policy requirements aligned to various operational and Technology processes.
  • Provide monitoring and independent oversight of the execution of technology, info security, and information management risk as they relate to policy and standards, including the independent oversight of the build out of a new front line process dedicated to the end-to-end risk management lifecycle.
  • Develop, implement, and support an effective control review and challenge process to provide transparency, accountability and escalation of control effectiveness.
  • Validate/evaluate appropriateness, completeness, effectiveness and sustainability of corrective actions taken to address situations defined as issues.

Risk Management

            Strategic Planning 

  • Provide input into the annual business strategy and planning processes to ensure strategic risks are identified, appropriately considered and documented.
  • - Embedding an appropriate risk culture

Assessment

  • Perform on-going monitoring and assessments of risks captured in the risk register to enable the identification of top risks, potential new risks or emerging risks
  • Provide oversight and support to ensure the Company’s risk appetite, control framework and policies are clearly documented, communicated and adhered to
  • Create and maintain appropriate key risk indicators (KRIs) and trigger limits to track the trends in risk exposures.
  • Ensure appropriate and insightful risk reporting including reporting to the Risk Committee and development and monitoring of KRIs
  • Own allocated risks in the risk register and facilitate regular risk and control assessments. This may include strategic and operational (including data, IT and cyber security), risks.
  • Monitor and assess operational risk exposures, events, business and IT incidents to ensure such cases are appropriately escalated.
  • Support the business in development and implementation of appropriate risk controls to mitigate such incidents.

Collaboration

  • Collaborate with internal partners to ensure effective key controls are appropriately designed and are operating effectively to mitigate identified risks in the risk register.
  • Where relevant, partner with relevant business stakeholders to design and implement pragmatic recommendations and actions for reducing exposures to risk where these exceed appetite or tolerance, ensuring the timely communication of such with the Risk Owner.
  • To lead and conduct risk assessments, reviews or investigations of topics that may arise from time to time. This may include risk assessments on important outsourcing or third-party risk management arrangements, second line of hot risk topics or areas of concerns, emerging risks, new business initiatives or regulatory topics.
  • Lead, contribute and/or deliver risk training and awareness initiatives on behalf of the Risk team as may be required.


Skills

  • Strong foundation with active experiences in delivering multiple frameworks including SOC2, ISO, CSA etc.
  • Experience in a cloud environment like AWS being used as an IaaS.
  • Relevant experience with risk frameworks like NIST RMF, FAIR model
  • Experience in creating and delivering risk reports to senior management.
  • Strong analytical and problem-solving skills
  • Excellent communication and interpersonal skills.
  • Ability to work independently and as part of a team
  • Strong attention to detail and organisational skills.
  • Proficiency in risk management software and tools.
  • Knowledge of regulatory requirements and industry standards.

Qualifications

  • Bachelor's degree in any discipline with relevant experience in an information security environment.
  • Relevant certifications in compliance, audit, cloud security, or related fields (e.g. CRISC, CISSP, CISM CISA, etc.)
  • 10+ years experience with at least 5 years experience in risk management or relevant fields.
The Company
Pune, Maharashtra
800 Employees
Hybrid Workplace
Year Founded: 2008

What We Do

Druva delivers data protection and management for the cloud era. Druva Cloud Platform is built on AWS and offered as-a-Service; customers drive down costs by over 50 percent by freeing themselves from the burden of unnecessary hardware, capacity planning, and software management.

Why Work With Us

We are the leader in cloud data protection and cloud is the way of the future! With over $300M in funding and our Pre-IPO status, it is the perfect time to jump on board. Two of our company values are "challenger mentality" and "one team". We truly believe in the impact we can make together and we are not afraid to push the status quo.

Gallery

Gallery

Jobs at Similar Companies

SharkNinja Logo SharkNinja

Environmental Manager

Beauty • Robotics • Design • Appliances • Manufacturing
Easy Apply
London, Greater London, England, GBR
3600 Employees

SharkNinja Logo SharkNinja

Senior Marketing Communications Insight Manager

Beauty • Robotics • Design • Appliances • Manufacturing
Easy Apply
London, Greater London, England, GBR
3600 Employees

SharkNinja Logo SharkNinja

eCommerce IT Operations Coordinator

Beauty • Robotics • Design • Appliances • Manufacturing
Easy Apply
London, Greater London, England, GBR
3600 Employees

Verkada Inc Logo Verkada Inc

Enterprise Development Representative - DACH

Cloud • Hardware • Security • Software
London, Greater London, England, GBR
2000 Employees

Similar Companies Hiring

Acquia Thumbnail
Software • Productivity • Marketing Tech • Cloud • Automation • Analytics • AdTech
Boston, MA
1100 Employees
CrowdStrike Thumbnail
Security • Sales • Information Technology • Cybersecurity • Cloud
Austin, TX
10000 Employees
Wipfli Thumbnail
Software • Fintech • Financial Services • Consulting • Cloud • Business Intelligence
Milwaukee, WI
3300 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account