Workato

Workato

Senior GRC Analyst

Palo Alto, California · Senior

No sponsorship$53k-$800kDetected 1 day ago
AWSGCPAzureCloud PlatformsCybersecurityComplianceCRMAuditingSupply ChainCustomer SuccessCommunicationCollaborationProblem SolvingTime ManagementAdaptabilityOrganizational SkillsCISSP

About the role

  • A leader in Enterprise MCP and trusted by 50% of the Fortune 500, Workato's cloud-native architecture connects every application, data source, and process to power real-time orchestration at scale.
  • With enterprise-grade security and continuous innovation at its core, Workato provides the trusted foundation for organizations to automate with confidence and operationalize AI across the business.
  • To learn more, visit www.workato.com Why join us?

Responsibilities

  • Maintain and update FedRAMP authorization documentation, including SSP, CIS, CRM, and associated artifacts
  • Lead internal and external audits for frameworks including FedRAMP (NIST 800-53), ISO 27001/27701, PCI-DSS, NIST 800-171, and IRAP
  • Develop and track remediation plans for identified risks and POA&M items
  • Maintain and update the risk register with federal risk considerations
  • Collaborate with engineering, infrastructure, and product teams to design and implement controls aligned with NIST 800-53 baselines
  • This role will lead FedRAMP readiness, authorization, and continuous monitoring activities in alignment with NIST 800-53 requirements, while also supporting broader compliance frameworks including ISO 27001, NIST 800-171, PCI-DSS, and IRAP.
  • Perform regular user access reviews aligned to least-privilege and FedRAMP AC control requirements
  • Support federal-facing sales and customer success discussions with compliance expertise
  • Build strong working relationships across departments and with federal agency AOs (Authorizing Officials)

Requirements

  • 8+ years of experience in cybersecurity, audits, risk management, compliance, or remediation
  • Experience working with cloud platforms such as AWS GovCloud, Azure Government, or Google Cloud (government regions)
  • Proven ability to negotiate and prioritize risk remediation with internal and federal stakeholders
  • Bachelor's degree in Information Systems, Computer Science, Information Security, or a related field
  • Strong understanding of security controls in cloud environments, including boundary definition, encryption, access control, and vulnerability management
  • Familiarity with NIST 800-171 and CMMC as complementary federal frameworks
  • Experience auditing frameworks such as PCI-DSS, SOC 2, and ISO 27001/27701

Nice to have

  • This position requires overlap with U.S. Pacific Time (PST) working hours.
  • Strong hands-on experience with FedRAMP, NIST 800-53, ISO 27001, NIST 800-171, PCI-DSS, SOC 2, and potentially IRAP is required.
  • May involve some international travel.
  • Must be eligible to work on U.S. federal government-related programs
  • Strong communication skills with the ability to translate federal compliance requirements into technical actions and executive-level summaries
  • High energy and adaptability in a fast-paced, high-stakes compliance environment
  • Strong collaboration and knowledge-sharing mindset across engineering, legal, and customer-facing teams
  • Excellent time management and organizational skills - particularly for managing concurrent ConMon and audit cycles

Skills

  • About Workato
  • To learn more, visit www.workato.com
  • Why join us?
  • Ultimately, Workato believes in fostering a flexible, trust-oriented culture that empowers everyone to take full ownership of their roles.
  • If this sounds right up your alley, please submit an application.
  • Business Insider named us an "enterprise startup to bet your career on"
  • Forbes' Cloud 100 recognized us as one of the top 100 private cloud companies in the world

Compensation

  • Owning continuous monitoring (ConMon) activities in accordance with FedRAMP requirements, including monthly vulnerability scanning, incident reporting, and annual assessments

Company info

  • Communicate FedRAMP requirements, risks, and compliance status clearly to both technical and non-technical stakeholders, including federal agency customers

Visa & Work Authorization

  • federal government-related programs; ability to obtain or support federal security clearance processes is a plus

This listing is sourced directly from Workato's careers page and normalized into a canonical job model.