Druva
About this role
Druva sells cloud backup and cyber resilience to nearly 7,500 customers, including 75 of the Fortune 500, and this role is about proving that its security holds up. Security assurance means being the person who answers when a prospect or customer interrogates Druva's data security, privacy and compliance posture, which at enterprise scale is a technical job rather than a paperwork one. You also own Druva's third party risk management programme, and you drive the internal security culture work around phishing and awareness training. The technical bar is specific: protocol level understanding of encryption at rest and in motion, covering TLS and SSL, BCrypt, PKI, SHA1 and AES, plus key management principles. Apply if you have 10 or more years in technology with at least 6 in cyber security and you are comfortable being questioned by other people's security teams.
Who this is for
Requirements as published:
- At least 10 years of experience in a technology discipline, preferably with 6+ years in the cyber security domain.
- Working protocol level understanding of encryption at rest and in motion: TLS and SSL, BCrypt, PKI, SHA1, AES and similar, plus key management principles.
- Proven experience collaborating with sales, legal and engineering teams.
- Familiarity with assurance frameworks and questionnaires including SIG and CAIQ.
- Exceptional communication, critical thinking and a strong bias for ownership and learning.
The actual day to day:
- Owning all activity aimed at building trust and confidence in Druva's data security, privacy and compliance posture with prospects and customers.
- Running Druva's third party risk management programme.
- Driving improvement in Druva's internal security culture, specifically phishing simulation and security awareness work.
Location and office reality:
- Pune. Office days are not stated in the posting.
Honest fit guidance:
- This is a customer facing security role, so if you want to be heads down building detections or breaking things, look elsewhere. Druva has separate engineering security roles.
- The collaboration with sales is named in the requirements, which tells you assurance work here supports deals. That is normal for the discipline, and there is no quota attached.
- The encryption depth requested is at protocol level, not conceptual. Expect to be asked how TLS actually works rather than what it is for.
- At least 10 years of experience in a technology discipline, preferably with 6+ years in the cyber security domain.
- Working protocol level understanding of encryption at rest and in motion: TLS and SSL, BCrypt, PKI, SHA1, AES and similar, plus key management principles.
- Proven experience collaborating with sales, legal and engineering teams.
- Familiarity with assurance frameworks and questionnaires including SIG and CAIQ.
- Exceptional communication, critical thinking and a strong bias for ownership and learning.
The actual day to day:
- Owning all activity aimed at building trust and confidence in Druva's data security, privacy and compliance posture with prospects and customers.
- Running Druva's third party risk management programme.
- Driving improvement in Druva's internal security culture, specifically phishing simulation and security awareness work.
Location and office reality:
- Pune. Office days are not stated in the posting.
Honest fit guidance:
- This is a customer facing security role, so if you want to be heads down building detections or breaking things, look elsewhere. Druva has separate engineering security roles.
- The collaboration with sales is named in the requirements, which tells you assurance work here supports deals. That is normal for the discipline, and there is no quota attached.
- The encryption depth requested is at protocol level, not conceptual. Expect to be asked how TLS actually works rather than what it is for.
Apply on company site
Opens www.druva.com, the employer's own application page. Applying is always free.