Druva Logo

Druva

Senior GRC Analyst

Posted 2 Days Ago
Be an Early Applicant
Pune, Maharashtra
Senior level
Pune, Maharashtra
Senior level
Seeking a Federal GRC Analyst to manage the POAM process, work with Federal agencies, analyze vulnerability scans, and provide support for compliance with the FedRAMP program. Responsibilities include managing POAM items, addressing security concerns, conducting security assessments, and collaborating cross-functionally. Qualifications include a degree in Computer Science, 8+ years of experience, and familiarity with federal compliance and governance standards and regulations.
The summary above was generated by AI


About Druva 

Druva, the autonomous data security company, puts data security on autopilot with a 100% SaaS, fully managed platform to secure and recover data from all threats. The Druva Data Security Cloud ensures the availability, confidentiality, and fidelity of data - providing customers with autonomous protection, rapid incident response, and guaranteed data recovery. The company is trusted by its more than 6,000 customers, including 65 of the Fortune 500, to defend business data in today’s ever-connected world. Amidst a rapidly evolving security landscape, Druva offers a $10 million Data Resiliency Guarantee ensuring customer data is protected and secured against every cyber threat. Visit druva.com and follow us on LinkedIn, Twitter and Facebook.

We are seeking a Federal GRC Analyst to join our team. The candidate will be responsible for managing the POAM (Plan of Actions and Milestones) process, working with Federal agencies, analyzing vulnerability, application, web, and database scans for multiple environments, and providing support for compliance with the FedRAMP program.  The candidate should have experience in building and maintaining network architecture diagrams, data flow diagrams, System Security Plans, Ports, Protocols, and Services Management (PPSM) documentation. The role requires knowledge of NIST Risk Management Framework (RMF), FedRAMP High, Moderate,baselines. Familiarity with StateRAMP and TX-RAMP is also a plus.


Primary Responsibilities

  • Manage the POAM process, including creating, tracking, and reporting on POAM items
  • Work with Federal agencies to address security concerns and ensure compliance with FedRAMP requirements
  • Analyse vulnerability scans to identify security risks and recommend remediation actions
  • Provide support for compliance with FedRAMP program requirements, including conducting security assessments and preparing security documentation
  • Maintain and update a System Security Plan
  • Collect and maintain artifacts used and needed for FedRAMP annual assessment
  • Collaborate with third-party assessment organisation (3PAO) for assessments
  • Stay up-to-date on changes to regulations and standards related to federal compliance and security
  • Work cross-functionally with engineering, product, advisory, legal, and sales teams to provide customer and stakeholder support


Qualifications & Skills

Education and Training:

  • Degree in Computer Science or equivalent
  • Understanding of multiple technology domains including Cloud, Software Development, MS Windows, Database management, Networking, and UNIX (preferred).
  • Understanding of information security standards, best practices for securing computer systems, and applicable laws and regulations.

Technical or Professional Experience:

  • Total of 8+ years with a minimum    of relevant experience
  • 2+ years experience in federal compliance and governance, including experience with FedRAMP, NIST, FISMA and other relevant regulations and standards
  • Progressive achievement in one or more of the traditional IT disciplines (applications, operations, infrastructure, and management).
  • Experience with SaaS Cloud Operations required.
  • Familiarity with AWS GovCloud environment and its related services
  • Experience in using scanning solutions to gather and review container, database, web application and other vulnerability scans.

Skills Requirements:

  • Outstanding interpersonal and communications skills; ability to communicate effectively with technical and non-technical audiences.
  • Strong verbal and written English language competency.
  • Strong knowledge of information security/Compliance standards(NIST/ISO are examples).
  • Expert knowledge of internal auditing, internal controls, risk management, and practices and methods.
  • Comprehensive understanding of internal control environments within the IT function.
  • Experience with multiple technology domains including aspects of Windows, Unix and/or database administration, software development and networking.
  • Excellent leadership and teamwork skills.
  • Proactive, hands-on, detail-oriented and results-driven orientation required.
  • Ability to produce high quality work products for both the IT groups and Senior Management.

 

Additional Desirable Qualifications:

  • Recognized accounting/auditing/information system certifications (e.g. CISA, CISSP)
  • Experience with a reputed auditing firm



Top Skills

Cloud
Database Management
Ms Windows
Networking
Software Development
Unix

Druva Pune, Mahārāshtra, IND Office

Muttha Chambers II, Level VI, Senepati Bapat Marg, Senepati Bapat Marg,, Pune, Maharashtra , India, 411046

Similar Jobs

8 Hours Ago
Hybrid
Mumbai, Maharashtra, IND
Mid level
Mid level
Financial Services
As a Regulatory Reporting Analyst, you will ensure compliance with regulations, monitor controls, and resolve issues promptly, while working closely with multiple teams. Your role involves understanding OTC derivative instruments, implementing control frameworks, conducting UAT testing, and managing key projects in a dynamic environment.
15 Hours Ago
Remote
Hybrid
2 Locations
Senior level
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
SailPoint seeks a Senior Data Engineer to design and implement robust data ingestion and processing systems. Responsibilities include developing scalable data pipelines, integrating diverse data sources, leveraging AWS services, and using tools like Apache Airflow for orchestration. Candidates should have extensive experience in data engineering and relevant technologies.
Top Skills: Apache AirflowAWSDockerFlinkKubernetesSpark
15 Hours Ago
Hybrid
4 Locations
Senior level
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The Legal Operations Data Analyst at CrowdStrike will design and implement data analysis and visualization tools, optimize workflows, and work towards increased automation for the Legal Team. Responsibilities include presenting complex data insights and maintaining dashboards using business intelligence tools.
Top Skills: JavaPythonRScalaSQL

What you need to know about the Pune Tech Scene

Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account