Grc Analyst

Fivetran Fivetran · Data AI · Bangalore, India · IT & Sec Department

Fivetran is seeking a GRC Analyst to join their Security team in Bangalore. This role focuses on ensuring the integrity, confidentiality, and availability of customer data by managing controls, conducting audits, and partnering with cross-functional teams. The analyst will work with IT general controls, application controls, and various compliance frameworks like ISO 27001, PCI-DSS, SOC 1, and SOC 2, as well as cloud platforms (AWS, Azure, GCP). Responsibilities include control testing, policy development, vendor assessments, and SOX participation. Experience in security audit, IT audit, risk management, and compliance frameworks is required, with bonus points for FedRAMP familiarity and certifications.

What you'd actually do

  1. Conduct control walkthroughs, testing, and evaluation of IT general controls and application controls across a complex systems landscape, with coverage spanning ISO 27001, PCI-DSS, SOC 1, SOC 2, and other applicable frameworks
  2. Partner with cross-functional teams to design, implement, and continuously improve control processes and related documentation
  3. Support third-party vendor assessments, evaluating vendors against established security and privacy standards and requirements
  4. Develop, maintain, and update Information Security Policies and Standards in alignment with industry best practices and regulatory obligations
  5. Participate in IT SOX scoping, risk assessment, and control design activities, contributing to the organization's overall internal control environment
  6. Prepare and deliver clear, accurate internal status reports to communicate control findings, remediation progress, and program updates to relevant stakeholders

Skills

Required

  • Demonstrated experience in security audit, IT audit, and risk management, with a strong understanding of control frameworks and audit methodologies
  • Working knowledge of industry compliance frameworks, including NIST, ISO 27001, SOC 1, SOC 2, and PCI-DSS
  • Familiarity with cloud technologies and environments, including one or more of GCP, AWS, and Azure, with an understanding of cloud-specific security and control considerations
  • Strong analytical and technical problem-solving skills, with the ability to assess complex control environments and draw well-supported conclusions
  • Proven ability to work collaboratively across functions, taking initiative and contributing constructively to shared team objectives
  • Effective at managing multiple concurrent workstreams, with strong organizational skills and the ability to prioritize in a fast-paced environment
  • Excellent written, verbal, and interpersonal communication skills, with the ability to present complex information clearly to both technical and non-technical audiences

Nice to have

  • Familiarity with FedRAMP compliance requirements and the associated authorization process and control framework
  • Professional certifications in audit or information security, such as CISA, CISSP, AWS, or SANS GIAC designations, are strongly preferred
  • Prior experience working at or directly with a Big 4 public accounting firm, with exposure to large-scale audit and advisory engagements
  • Experience leveraging AI tools to build workflow automations and drive operational efficiencies within a GRC or security context

What the JD emphasized

  • continuous integrity, confidentiality, and availability of customer data
  • critical, core component of both our product and our business
  • control-focused audit professional
  • strong understanding of IT systems and infrastructure
  • Strong communication skills are essential
  • ability to collaborate and influence across functions and levels of the organization
  • ISO 27001, PCI-DSS, SOC 1, SOC 2
  • security audit, IT audit, and risk management
  • strong understanding of control frameworks and audit methodologies
  • Working knowledge of industry compliance frameworks
  • Familiarity with cloud technologies and environments
  • understanding of cloud-specific security and control considerations
  • Strong analytical and technical problem-solving skills
  • assess complex control environments
  • Proven ability to work collaboratively across functions
  • taking initiative and contributing constructively to shared team objectives
  • managing multiple concurrent workstreams
  • strong organizational skills
  • ability to prioritize in a fast-paced environment
  • Excellent written, verbal, and interpersonal communication skills
  • present complex information clearly to both technical and non-technical audiences