About NetApp
NetApp is the intelligent data infrastructure company, turning a world of disruption into opportunity for every customer. No matter the data type, workload or environment, we help our customers identify and realize new business possibilities. And it all starts with our people.
If this sounds like something you want to be part of, NetApp is the place for you. You can help bring new ideas to life, approaching each challenge with fresh eyes. Of course, you won't be doing it alone. At NetApp, we're all about asking for help when we need it, collaborating with others, and partnering across the organization - and beyond.
Senior Risk Lead
Bengaluru, IndiaJob Summary
The Senior Risk Lead provides technical governance to supplier risk management programs in the governance, risk and compliance functions. Responsible for reviewing security compliance in terms of SaaS configuration, compliance sets such as SOC2 and performing risk assessments. Accountable for security frameworks and adherence to industry best practices and standards. Works with application and infrastructure teams to ensure that policies and standards are integrated and applied appropriately across the environment.
The Analyst is expected to have a thorough understanding IT system, experienced in enterprise systems integration and stays up to date with the latest security standards, emerging security technologies, as well as security best practices.
The Senior Risk Lead will also assist with facilitating the identification, documentation, review, and mitigation of information security risks to support organizational strategic objectives. This role will analyze information security risks and controls based on established risk criteria and methodology, conduct security risk assessments of information systems to identify vulnerabilities associated with critical assets, recommend controls to mitigate security risks identified through the risk assessment process, and communicate results that are clear and actionable to business stakeholders.
The Senior Risk Lead will monitor the risk landscape through emerging threat intelligence, actionable situational awareness, and other sources. While working with the overall Global Security GRC team and other internal business units, the analyst will ensure proper documentation and reporting analytics, including KPIs, through the development and maintenance of appropriate records related to risks, controls, and assessments in the GRC system of record.
Duties and Responsibilities
- Conducts reviews for projects related to infrastructure and general information security to ensure they meet requirements and target-state architecture.
- Participates in risk assessment activities as subject matter expert for infrastructure and general information security concerns
- Determines security requirements by evaluating business strategies and requirements; researching information security standards; evaluating risk assessments; studying architecture/platform and identifying integration issues
- Ensures all risks are documented and updated according to Global Security policies, standards, and processes
- Engages with technical and security teams to identify and assess risks, driving towards appropriate risk mitigation activities aligned with the enterprise risk appetite
- Monitors identified risks, reassessing as needed and/or as directed by management
- Reports on risk remediation status through facilitation of risk metrics, analytics, and scorecards
- Helps facilitate the annual enterprise information security risk assessment
- Manages issue resolution due to control breaks and audit findings
- Analyzes business problems through software, analytical tools and techniques, business processes and technical knowledge to guide in risk-based decisions
- Organizes and leads GRC-related meetings, prepares meeting agendas, sends out meeting minutes and coordinates follow-up activities as appropriate
- Manages exceptions to policy and standards
- Communicate with all levels of technical and executive staff in matters related risk identification and remediation
- Works with GRC Compliance, Internal Audit, and outside consultants as appropriate on required security assessments and audits
Minimum Qualifications
- Bachelor's degree in business, accounting, finance, computer science, information systems, engineering, or a related field strongly preferred; equivalent combination of education and experience may be substituted in lieu of degree
- At least eight (8) years of GRC (governance, risk, compliance) experience with methodologies, activities, tools, and enablers in a technology related industry including experience in business process analysis, project methodology, or systems development life cycle through education or on-the-job experience, required
- Knowledge in creating architectures (IaaS, SaaS, PaaS) for public, private and hybrid cloud services
- Ability to demonstrate a strong understanding of various compliance and regulatory areas (e.g., ISO27001, SOC2, DORA)
- Experience with risk management and managing the risk lifecycle
- Working knowledge of configuration management, change control, security baselines and frameworks (NIST CSF, NIST 800-171, CIS)
- Identify gaps in existing and proposed architectures and security controls and provide recommendations for risk resolution
- Ability to develop security policies and standards and guidelines based on best practices and industry standards
- Strong oral and written communication skills; including presentation skills
- Strong analytical and problem-solving skills
- Ability to work both independently and as part of a team to deliver quality work products in a timely fashion in a fast-paced environment
- Ability to multi-task and prioritize tasks with little supervision
- The ability to work well with people from many different disciplines with varying degrees of technical experience
- The ability to adapt to a dynamic, rapidly changing business and technical environment
- Ability to exercise skilled professional judgment
- Ability to maintain confidentiality
- Ability to oversee all aspects of projects and manage projects through the entirety of the life cycle
Preferred Qualifications
- Information security related training or certifications such as CISSP, CSSP, CRISC or CISA
- Knowledge of Vulnerability management topics: Common Vulnerability Scoring System (CVSS), Common Vulnerabilities and Exposures (CVE), and Open Web Application Secure Project (OWASP)
- Experience with AI standards (e.g. ISO 42001) and assessing AI risks
- Experience performing information security risk assessments
- Experience with KPI/KRI metrics analysis and management
- Proven ability to drive process improvement through strategic thinking, plan development and implementation
At NetApp, we embrace a hybrid working environment designed to strengthen connection, collaboration, and culture for all employees. This means that most roles will have some level of in-office and/or in-person expectations, which will be shared during the recruitment process.
Equal Opportunity Employer:
NetApp is firmly committed to Equal Employment Opportunity (EEO) and to compliance with all laws that prohibit employment discrimination based on age, race, color, gender, sexual orientation, gender identity, national origin, religion, disability or genetic information, pregnancy, and any protected classification.
Why NetApp?
We are all about helping customers turn challenges into business opportunity. It starts with bringing new thinking to age-old problems, like how to use data most effectively to run better - but also to innovate. We tailor our approach to the customer's unique needs with a combination of fresh thinking and proven approaches.
We enable a healthy work-life balance. Our volunteer time off program is best in class, offering employees 40 hours of paid time off each year to volunteer with their favourite organizations. We provide comprehensive benefits, including health care, life and accident plans, emotional support resources for you and your family, legal services, and financial savings programs to help you plan for your future. We support professional and personal growth through educational assistance and provide access to various discounts and perks to enhance your overall quality of life.
If you want to help us build knowledge and solve big problems, let's talk.
Submitting an application
To ensure a streamlined and fair hiring process for all candidates, our team only reviews applications submitted through our company website. This practice allows us to track, assess, and respond to applicants efficiently. Emailing our employees, recruiters, or Human Resources personnel directly will not influence your application.
Jobs for you
- Consulting Solutions Engineer, Enterprise Sales (Tampa, FL) Tampa, Florida, United States
- Professional Services Project Manager , United States
- Services Account Executive New York, New York, United States; , United States; Waltham, Massachusetts, United States; Philadelphia, Pennsylvania, United States
Your recently viewed jobs will appear here.
You have no saved jobs. Start browsing jobs here
Recruitment scam warning
When conducting a job search, you’re bombarded with outreach. Here are tips to keep you safe from recruitment fraud.
Stay in touch
Equal Opportunity Employer*
NetApp is firmly committed to Equal Employment Opportunity (EEO) and to compliance with all federal, state and local laws that prohibit employment discrimination based on age, race, color, gender, sexual orientation, gender identity, national origin, religion, disability or genetic information, pregnancy, protected veteran status and any other protected classification. We pledge to take every reasonable step to ensure that our applicants and employees are respected, treated fairly and with dignity. See the EEO poster, Know your rights poster, and NetApp EEO policy. NetApp makes reasonable accommodations, consistent with applicable laws, for religious purposes and for the known physical or mental limitations of an otherwise qualified applicant or employee with a disability, who can perform the essential job functions unless undue hardship would result.
State-specific postings/notices to applicants regarding contract compliance can be found here in English and here in Spanish, and fair employment practice information can be found here.
Reasonable accommodation
If you are an applicant with a physical or mental disability requiring an accommodation, or you require a religious accommodation for any part of our application process, please email careers@netapp.com. Each request for reasonable accommodation will be considered on a case-by-case basis, consistent with applicable laws and regulations. Please note, this email address is only for accommodation requests; we do not accept unsolicited resumes.
Data privacy
We care about your privacy and, therefore, ask that you read our Candidate Privacy Notice before you submit any personal information to us.
NetApp does not carry out any solely automated decision making (i.e. the process of making a decision by automated means without any human involvement) in determining your suitability or eligibility for specific roles.
However, the processing of your personal information is carried out with the aid of manual and automated tools. In particular, NetApp may use an automated employment evaluation tool or similar tool as one of several tools, actions, and/or steps to assist with NetApp’s review of candidate applications for various hiring needs. Currently, when addressing certain hiring needs, NetApp uses the Eightfold tool which can provide an initial ranking of a candidate’s skills and experience, based on information provided by the applicant in the application and/or supporting documentation, in comparison to the NetApp designated key requirements of a specific role. Additionally, the tool may be used to help review and/or rank internal employees seeking promotion or other internal mobility. However, our talent acquisition team or our recruiters will ultimately select the candidates for further consideration, following human review of any automated evaluation results and associated underlying documentation (or lack thereof) submitted with the candidates’ application.
An independent audit of the Eightfold Matching Model tool can be found at https://eightfold.ai/nyc-eightfoldmatching-model.
Candidates may request an alternative selection process which will not be subject to the Eightfold matching tool or to any electronic automated employment evaluation by contacting NetApp at careers@netapp.com. To bypass the Eightfold matching tool or any electronic automated employment evaluation, you must include a resume and job ID with your email to careers@netapp.com and you must include in the subject line of your email: Data Privacy Request. Candidates who have questions or want to request additional information on the source of data, type of data, and/or collection of data related to the candidate review process should contact NetApp at careers@netapp.com
Submitting an application
To ensure a streamlined and fair hiring process for all candidates, our team only reviews applications submitted through our company website or to our careers@netapp.com email address as outlined above. This practice allows us to track, assess, and respond to applicants efficiently. Emailing our employees, recruiters, or Human Resources personnel directly will not influence your application.