We’re in an unbelievably exciting area of tech and are fundamentally reshaping the data storage industry. Here, you lead with innovative thinking, grow along with us, and join the smartest team in the industry.
This type of work—work that changes the world—is what the tech industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us.
THE ROLE
As a GRC Security Analyst at Everpure, you will turn complex security, risk, and compliance requirements into pragmatic, scalable processes that safeguard our business and enable global growth. Partnering cross-functionally across Product Business Units, Digital Technology, Legal, Privacy, Procurement, and Customer Trust, you will own critical risk workstreams end-to-end to drive actionable risk reduction. Operating as an autonomous practitioner, you will balance strong control discipline with business agility to elevate the maturity of our Global Information Security Office (GISO).
WHAT YOU'LL DO
- Third-Party Risk & Vendor Governance: Lead end-to-end third-party security risk assessments and SaaS vendor reviews—analyzing questionnaires, SOC reports, and architecture gaps—to minimize supply chain vulnerability across global vendor ecosystems.
- Security Exception & Risk Register Ownership: Own the enterprise security exception lifecycle and risk register, collaborating with technical owners to evaluate tradeoffs, establish compensating controls, and track remediation to measurable closure.
- Security Awareness & Phishing Operations: Direct operational execution of annual security awareness programs and phishing simulation campaigns, leveraging metrics and trend analysis to measurably reduce human-factor risk across global employee populations.
- Audit Preparedness & Compliance Alignment: Drive continuous compliance evidence gathering and control assessments supporting ISO 27001 and SOC 2 audits, ensuring Everpure maintains its customer trust and regulatory posture.
- GRC Process Scaling & Automation: Maintain and mature GRC platform workflows (Jira, ServiceNow IRM, Graphite Connect), converting manual assessment tasks into streamlined, automated dashboards that give leadership clear visibility into open risk trends.
WHAT YOU BRING
- Experience & Background: 8+ years of professional experience in governance, risk, compliance (GRC), information security, IT audit, or third-party risk management within a global technology or cloud environment.
- Core GRC & Risk Assessment Expertise: Practical expertise in risk identification, exception lifecycle management, control mapping, and third-party vendor security assessments aligned with frameworks such as ISO 27001, SOC 2, NIST, or CIS Controls.
- Business-Oriented Risk Communication: Strong communication skills with a proven ability to translate complex technical risks into clear business terms (likelihood, impact, operational trade-offs) while collaborating effectively with technical and non-technical stakeholders across regions.
- Tooling & Process Execution: Proficiency utilizing GRC platforms and workflow tools (ServiceNow IRM, Jira, Graphite Connect) to structure execution plans, maintain risk register integrity, and drive cross-functional follow-through.
- Location Requirements: We are primarily an in-office environment and therefore, you will be expected to work from the Bangalore office in compliance with Everpure’s policies, unless you are on PTO, or work travel, or other approved leave.
WHAT YOU CAN EXPECT FROM US:
- Innovation: We celebrate those who think critically, like a challenge, and aspire to be trailblazers.
- Growth: We give you the space and support to grow along with us and to contribute to something meaningful. We have been named Fortune's Best Workplaces in Technology™, Fortune's Best Workplaces in the Bay Area™, and certified as a Great Place to Work®!
- Team: We build each other up and set aside ego for the greater good.
And because we understand the value of bringing your full and best self to work, we offer a variety of perks to manage a healthy balance, including flexible time off, wellness resources, and company-sponsored team events. Check out purebenefits.com for more information.
ACCOMMODATIONS AND ACCESSIBILITY:
Candidates with disabilities may request accommodations for all aspects of our hiring process. For more on this, contact us at [email protected] if you’re invited to an interview.
OUR COMMITMENT TO A STRONG AND INCLUSIVE TEAM:
We’re forging a future where everyone finds their rightful place and where every voice matters. Where uniqueness isn’t just accepted but embraced. That’s why we are committed to fostering the growth and development of every person, cultivating a sense of community through our Employee Resource Groups and advocating for inclusive leadership.
Everpure is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other characteristic legally protected by the laws of the jurisdiction in which you are being considered for hire.
Join us and bring your best.
Bring your bold.
Pure and simple.
Skills Required
- 8+ years professional experience in governance, risk, compliance (GRC), information security, IT audit, or third-party risk management within a global technology or cloud environment.
- Practical expertise in risk identification, exception lifecycle management, control mapping, and third-party vendor security assessments aligned with ISO 27001, SOC 2, NIST, or CIS Controls.
- Proven ability to translate complex technical risks into clear business terms and collaborate with technical and non-technical stakeholders.
- Proficiency with GRC platforms and workflow tools, specifically ServiceNow IRM, Jira, and Graphite Connect.
- Experience directing security awareness programs and phishing simulation campaigns.
- Experience supporting ISO 27001 and SOC 2 audits including continuous compliance evidence gathering and control assessments.
- Ability to work from the Bangalore office (in-office requirement).
Everpure Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Everpure and has not been reviewed or approved by Everpure.
-
Equity Value & Accessibility — Equity and stock purchase programs are described as meaningful parts of total compensation, with RSUs and an ESPP highlighted as strengths.
-
Strong & Reliable Incentives — Sales compensation is structured to support long sales cycles, including policies that pay full commission until the first sale for new or white‑space accounts.
-
Healthcare Strength — Health coverage is portrayed as comprehensive, with multiple medical options, fully covered vision, dental PPO choices, mental‑health resources, and company HSA contributions.
Everpure Insights
Similar Jobs
What We Do
Pure Storage (NYSE:PSTG) helps innovators build a better world with data. Pure's data solutions enable SaaS companies, cloud service providers, and enterprise and public sector customers to deliver real-time, secure data to power their mission-critical production, DevOps, and modern analytics environments in a multi-cloud environment. One of the fastest growing enterprise IT companies in history, Pure Storage enables customers to quickly adopt next-generation technologies, including artificial intelligence and machine learning, to help maximize the value of their data for competitive advantage. And with a Satmetrix-certified NPS customer satisfaction score in the top one percent of B2B companies, Pure's ever-expanding list of customers are among the happiest in the world.



.jpeg)





