Senior GRC Analyst
Job description
About the role
Workato is seeking a seasoned GRC professional to own the strategy, execution, and oversight of security governance, risk, and compliance initiatives with a primary focus on FedRAMP authorization. The successful candidate will be responsible for driving the federal compliance lifecycle, ensuring that our integration platform meets the stringent requirements of U.S. government agencies. This position involves close collaboration with technical and business stakeholders to translate complex regulatory frameworks into actionable controls and processes. You will own the documentation and evidence collection necessary for authorization packages and maintain the integrity of our security posture. The role requires a deep understanding of federal risk management practices and the ability to scale compliance operations as the organization grows. You will act as a subject matter expert, guiding internal teams through the complexities of government regulations. This is a critical role in enabling Workato to serve public sector customers and expand our footprint in the government technology space.
Key facts
What you'll do
- Orchestrate end-to-end management of FedRAMP authorization cycles, including authoring and maintaining System Security Plans, reviewing Security Assessment Reports, and updating the Plan of Action and Milestones.
- Drive continuous monitoring strategies by overseeing monthly vulnerability scans, managing incident reporting workflows, and preparing documentation for annual assessments.
- Serve as the central point of coordination for audits related to FedRAMP, ISO 27001, ISO 27701, PCI-DSS, NIST 800-171, and IRAP, ensuring timely execution and closure of findings.
- Conduct comprehensive risk assessments and perform vendor reviews with a focus on supply chain integrity and boundary security to identify potential threats.
- Partner with engineering and product teams to implement, test, and document NIST 800-53 Rev 5 controls within cloud environments and integration workflows.
- Analyze and review contracts and service-level agreements to verify compliance with flow-down requirements and regulatory obligations.
- Lead user access review programs to enforce least-privilege principles and ensure that access rights are aligned with job functions and security policies.
- Provide specialized compliance expertise to support sales engagements and customer success initiatives, assisting with responses to security questionnaires and federal proposals.
- Leverage automation and artificial intelligence tools to streamline GRC workflows, improve data accuracy, and reduce manual effort in compliance activities.
- Maintain current awareness of evolving federal mandates and industry standards to proactively adjust policies and controls.
- Develop and maintain strong documentation practices to ensure audit trails are clear, consistent, and easily retrievable.
- Act as a liaison between technical teams and executive leadership to communicate risk posture and compliance status effectively.
Requirements
- Hold a Bachelor degree in Information Systems, Computer Science, Information Security, or a closely related field that provides foundational knowledge in technology and risk principles.
- Bring a minimum of 8 years of cumulative professional experience in cybersecurity, audit, risk management, or compliance roles, demonstrating depth in at least one of these domains.
- Possess direct, hands-on experience with FedRAMP authorization processes, including the creation of System Security Plans and coordination with Third-Party Assessment Organizations.
- Demonstrate comprehensive, practical knowledge of NIST 800-53 Rev 5 controls and the associated FedRAMP templating, policies, and procedures.
- Have proven experience operating within government cloud environments, specifically AWS GovCloud, Azure Government, or Google Cloud government regions, understanding their unique security considerations.
- Show familiarity with a broad set of frameworks including NIST 800-171, CMMC, PCI-DSS, SOC 2, and ISO 27001/27701, and the ability to apply them appropriately.
- Be capable of working exclusively during U.S. Pacific Time business hours, aligning schedule and responsiveness with West Coast operations.
- Be eligible to work on U.S. federal government programs, holding the necessary citizenship or employment status to handle classified or controlled unclassified information.
Nice to have
- Possess industry-recognized professional certifications such as CISSP, CISA, or have completed FedRAMP PMO training, indicating a commitment to professional excellence.
- Have the ability to support federal security clearance processes, including the collection and verification of necessary documentation for personnel eligibility.
Practical notes
- This role may require occasional international travel.
- Reference REQ ID: 2761.