Senior Grc Analyst (fed Support)

Year    MH, IN, India

Job Description

About Druva



Druva enables cyber, data, and operational resilience for every organization with the Data Resiliency Cloud, the industry's first and only at-scale SaaS solution. Customers can radically simplify data protection, streamline data governance, and gain data visibility and insights as they accelerate cloud adoption. Druva pioneered a SaaS-based approach to eliminate complex infrastructure and related management costs and deliver data resilience via a single platform spanning multiple geographies and clouds. Druva is trusted by thousands of enterprises, including 60 of Fortune 500, to make data more resilient and accelerate their journey to the cloud.





We are seeking a Federal GRC Analyst to join our team. The candidate will be responsible for managing the POAM (Plan of Actions and Milestones) process, working with Federal agencies, analyzing vulnerability, application, web, and database scans for multiple environments, and providing support for compliance with the FedRAMP program. The candidate should have experience in building and maintaining network architecture diagrams, data flow diagrams, System Security Plans, Ports, Protocols, and Services Management (PPSM) documentation. The role requires knowledge of NIST Risk Management Framework (RMF), FedRAMP High, Moderate,baselines. Familiarity with StateRAMP and TX-RAMP is also a plus.




Primary Responsibilities


• Manage the POAM process, including creating, tracking, and reporting on POAM items
• Work with Federal agencies to address security concerns and ensure compliance with FedRAMP requirements
• Analyse vulnerability scans to identify security risks and recommend remediation actions
• Provide support for compliance with FedRAMP program requirements, including conducting security assessments and preparing security documentation
• Maintain and update a System Security Plan
• Collect and maintain artifacts used and needed for FedRAMP annual assessment
• Collaborate with third-party assessment organisation (3PAO) for assessments
• Stay up-to-date on changes to regulations and standards related to federal compliance and security
• Work cross-functionally with engineering, product, advisory, legal, and sales teams to provide customer and stakeholder support




Qualifications & Skills



• Education and Training:


• Degree in Computer Science or equivalent
• Understanding of multiple technology domains including Cloud, Software Development, MS Windows, Database management, Networking, and UNIX (preferred).
• Understanding of information security standards, best practices for securing computer systems, and applicable laws and regulations.

• Technical or Professional Experience:


• Total of 8+ years with a minimum of relevant experience
• 2+ years experience in federal compliance and governance, including experience with FedRAMP, NIST, FISMA and other relevant regulations and standards
• Progressive achievement in one or more of the traditional IT disciplines (applications, operations, infrastructure, and management).
• Experience with SaaS Cloud Operations required.
• Familiarity with AWS GovCloud environment and its related services
• Experience in using scanning solutions to gather and review container, database, web application and other vulnerability scans.


Skills Requirements:


• Outstanding interpersonal and communications skills; ability to communicate effectively with technical and non-technical audiences.
• Strong verbal and written English language competency.
• Strong knowledge of information security/Compliance standards(NIST/ISO are examples).
• Expert knowledge of internal auditing, internal controls, risk management, and practices and methods.
• Comprehensive understanding of internal control environments within the IT function.
• Experience with multiple technology domains including aspects of Windows, Unix and/or database administration, software development and networking.
• Excellent leadership and teamwork skills.
• Proactive, hands-on, detail-oriented and results-driven orientation required.
• Ability to produce high quality work products for both the IT groups and Senior Management.




Additional Desirable Qualifications:

• Recognized accounting/auditing/information system certifications (e.g. CISA, CISSP)
• Experience with a reputed auditing firm

Beware of fraud agents! do not pay money to get a job

MNCJobsIndia.com will not be responsible for any payment made to a third-party. All Terms of Use are applicable.


Related Jobs

Job Detail

  • Job Id
    JD3403652
  • Industry
    Not mentioned
  • Total Positions
    1
  • Job Type:
    Full Time
  • Salary:
    Not mentioned
  • Employment Status
    Permanent
  • Job Location
    MH, IN, India
  • Education
    Not mentioned
  • Experience
    Year