Workato Logo

Workato

Senior GRC Analyst

Posted 10 Days Ago
Be an Early Applicant
Bangalore, Bengaluru, Karnataka
Senior level
Bangalore, Bengaluru, Karnataka
Senior level
The Senior GRC Analyst leads security compliance programs, conducts audits, communicates risks, and implements improvements to Workato’s security framework. Requires strong cybersecurity experience and cloud knowledge.
The summary above was generated by AI
About Workato

Workato transforms technology complexity into business opportunity. As the leader in enterprise orchestration, Workato helps businesses globally streamline operations by connecting data, processes, applications, and experiences. Its AI-powered platform enables teams to navigate complex workflows in real-time, driving efficiency and agility.

Trusted by a community of 400,000 global customers, Workato empowers organizations of every size to unlock new value and lead in today’s fast-changing world. Learn how Workato helps businesses of all sizes achieve more at workato.com.

Why join us?

Ultimately, Workato believes in fostering a flexible, trust-oriented culture that empowers everyone to take full ownership of their roles. We are driven by innovation and looking for team players who want to actively build our company. 

But, we also believe in balancing productivity with self-care. That’s why we offer all of our employees a vibrant and dynamic work environment along with a multitude of benefits they can enjoy inside and outside of their work lives. 

If this sounds right up your alley, please submit an application. We look forward to getting to know you!

Also, feel free to check out why:

  • Business Insider named us an “enterprise startup to bet your career on”

  • Forbes’ Cloud 100 recognized us as one of the top 100 private cloud companies in the world

  • Deloitte Tech Fast 500 ranked us as the 17th fastest growing tech company in the Bay Area, and 96th in North America

  • Quartz ranked us the #1 best company for remote workers

Note: 
This role requires working during overlapping hours with the US PST zone.
Are you flexible and available to work between 3:00 PM IST onwards?
We need significant experience with auditing PCI, NIST 800-171, NIST 9-800-53, SOC2, and possibly IRA. Responsibilities

Workato is seeking a detail-oriented, highly motivated, technology-savvy and passionate Senior GRC Analyst professional who wants to support, promote and further mature the company's security GRC program.

Responsible for leading NIST 800-171, NIST 800-53, and IRAP assessments and certification.

Responsible for executing various security compliance initiatives such as risk assessments, security control audits and 3rd party risk assessments. You will use your strong communication, analytical and troubleshooting abilities to quickly identify and report on controls from various security domains, control and/or process gaps and to identify process and technology opportunities.

Primary responsibilities include, but are not limited to:

  • Lead internal and external audits related to ISO 27001/ISO 27701, PCI-DSS, NIST 800-171, NIST 800-53, and IRAP.

  • Overseeing risk, compliance, and governance programs across departments

  • Leverage broad experience to coordinate work assignments with process owners, control owners, external auditors, and consultants to ensure issues are documented and monitored.

  • Document and perform assessments as needed and review contracts for security requirements.

  • Exhibit strategic agility and proactively identify and correct process gaps and improvements to further the maturity of Workato’s information security program in alignment with company goals and objectives.

  • Clearly and effectively communicate security issues and risks to diverse audiences and ensure compliance with applicable controls based on a unified framework.

  • Conduct periodic user access reviews

  • Support developing remediation plans for issues and risks, coordinate activities with control owners, and track remediation to completion.

  • Maintaining and documenting the risk register.

  • Oversight of the vendor security assurance program

  • Ability to work independently and as part of a team with a professional attitude and demeanor

  • Partner with stakeholders to design internal controls based on regulatory requirements and best practices for ongoing risk mitigation of information systems.

  • Support and guide information risk and security discussions with technical and non-technical groups

  • Build and cultivate positive working relationships with stakeholders across various teams.

  • Performs other related duties as assigned.

RequirementsQualifications / Experience / Technical Skills

  • 8+ years of applied work experience in cyber security programs, audits, assessments, risk, remediation, or cyber security compliance management.

  • Relevant experience working with AWS, Azure, Google or any other cloud computing environment.

  • Experience negotiating prioritization of risks and remediation findings with internal teams.

  • B.S. degree in Management Information Systems, Computer Science, Information Security, or any security technology-related field

  • Solid understanding of technical security controls related to perimeter security operations, including Cloud service providers, firewalls, IDS/IPS, Vulnerability Management, and services offered by cloud service providers. Ability to prioritize and multitask with minimal supervision.

  • Excellent skills in troubleshooting, problem-solving, analytical thinking, and project management

  • Technical knowledge/Experience in security control technologies such as firewalls, IDS, DLP, Vulnerability Management, AWS environment, Application Security, Monitoring and logging tools,  etc.

  • Working knowledge of the controls and implementation of DFARS Clause 252.204-7012 (NIST 800-171) and NIST Risk Management Framework (NIST 800-53)

  • Experience auditing security standards/frameworks such as PCI-DSS, SOC, and ISO 27001/27701, etc.

  • CISSP, CISA, PCI ISA, PCIP, CMMC RP, or similar security certifications preferred

  • It may require working outside of normal business hours periodically

  • It may require some international travel

Soft Skills / Personal Characteristics

  • Excellent communication skills that translate compliance requests into technical recommendations. 

  • High level of energy and a desire to thrive in a fast-paced organization; ability to balance multiple projects under pressure

  • Excellent team player with a willingness to share knowledge with others.

  • Excellent personal and time management skills

  • Very high attention to detail, high integrity, and business ethics

  • Willing to learn and take on new responsibilities

Top Skills

AWS
Azure
Security Compliance Technologies

Similar Jobs

Yesterday
Hybrid
Bengaluru, Karnataka, IND
Mid level
Mid level
Cloud • eCommerce • Information Technology • Professional Services • Software
The Support Engineer will manage EDI environments, troubleshoot issues, and ensure high support levels for customers, focusing on incident responses and root cause analysis.
Top Skills: APIsAs2Cleo ProductsEdiFlat FilesFtpHTTPSftpSpreadsheetsSQLXML
Yesterday
Hybrid
Bangalore, Bengaluru, Karnataka, IND
Junior
Junior
Cloud • eCommerce • Information Technology • Professional Services • Software
The Support Engineer II will manage EDI systems, respond to incidents, troubleshoot issues, and ensure customer satisfaction while collaborating with internal teams.
Top Skills: Ansi X12As2Edi MappingEdifactFlat FilesFtpHTTPSftpSpreadsheetsSQLXML
Yesterday
Easy Apply
Remote
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
Easy Apply
Mid level
Mid level
Artificial Intelligence • Machine Learning • Software
As a Support Engineer, you'll troubleshoot customer issues, own problem resolution, enhance support processes, and collaborate cross-functionally to improve customer experience.
Top Skills: Chrome Dev ToolsCSSHTMLJavaScriptJIRASalesforce

What you need to know about the Mumbai Tech Scene

From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account