Sr. Grc Analyst

Fivetran Fivetran · Data AI · Bangalore, India · IT & Sec Department

Fivetran is seeking a Senior GRC Analyst to join their Security team in Bangalore. This role focuses on ensuring the integrity, confidentiality, and availability of customer data by managing IT controls, supporting vendor assessments, developing policies, and participating in SOX activities. The ideal candidate has a strong background in security audit, IT audit, and risk management, with knowledge of compliance frameworks and cloud technologies. Experience with FedRAMP and AI tools for GRC automation are considered bonus skills.

What you'd actually do

  1. Conduct control walkthroughs, testing, and evaluation of IT general controls and application controls across a complex systems landscape, with coverage spanning ISO 27001, PCI-DSS, SOC 1, SOC 2, and other applicable frameworks
  2. Partner with cross-functional teams to design, implement, and continuously improve control processes and related documentation
  3. Support third-party vendor assessments, evaluating vendors against established security and privacy standards and requirements
  4. Develop, maintain, and update Information Security Policies and Standards in alignment with industry best practices and regulatory obligations
  5. Participate in IT SOX scoping, risk assessment, and control design activities, contributing to the organization's overall internal control environment

Skills

Required

  • Demonstrated experience in security audit, IT audit, and risk management, with a strong understanding of control frameworks and audit methodologies.
  • Working knowledge of industry compliance frameworks, including NIST, ISO 27001, SOC 1, SOC 2, and PCI-DSS
  • Familiarity with cloud technologies and environments, including one or more of GCP, AWS, and Azure, with an understanding of cloud-specific security and control considerations
  • Strong analytical and technical problem-solving skills, with the ability to assess complex control environments and draw well-supported conclusions
  • Proven ability to work collaboratively across functions, taking initiative and contributing constructively to shared team objectives
  • Effective at managing multiple concurrent workstreams, with strong organizational skills and the ability to prioritize in a fast-paced environment
  • Excellent written, verbal, and interpersonal communication skills, with the ability to present complex information clearly to both technical and non-technical audiences

Nice to have

  • Familiarity with FedRAMP compliance requirements and the associated authorization process and control framework
  • Professional certifications in audit or information security, such as CISA, CISSP, AWS, or SANS GIAC designations, are strongly preferred
  • Prior experience working at or directly with a Big 4 public accounting firm, with exposure to large-scale audit and advisory engagements
  • Experience leveraging AI tools to build workflow automations and drive operational efficiencies within a GRC or security context

What the JD emphasized

  • critical, core component
  • strong understanding of control frameworks and audit methodologies
  • strong analytical and technical problem-solving skills
  • strong organizational skills
  • Excellent written, verbal, and interpersonal communication skills