03 Sep
|
SolarWinds
|
Bengaluru
03 Sep
SolarWinds
Bengaluru
Job Summary
The GRC Analyst - Continuous Monitoring Control Assurance plays a pivotal role in executing the organizations continuous control monitoring (CCM) program. Under the direction of GRC leadership, this role is responsible for validating the effectiveness of critical IT and security controls, driving remediation efforts, and championing evidence automation. The goal is to enhance audit readiness and ensure that daily activities are aligned with the overarching GRC assurance strategy.
Responsibilities
- Continuous Control Monitoring Execution: Perform recurring, risk-based monitoring across critical domains such as access management, change management, segregation of duties, vulnerability management, and disaster recovery. Maintain testing schedules, coordinate evidence collection with control owners, and document exceptions using established methodologies.
- Technical Integration Automation: Partner with Security Operations, IT, and Engineering to extract and evaluate evidence directly from operational platforms (SIEM, IAM, Cloud Security, ITSM, Jira). Identify opportunities to transition from manual collection to automated, system-generated reporting and repeatable queries.
- Deficiency Management Technology Transitions: Analyze evidence to identify control gaps, establish root causes with control owners, and track corrective actions through validation and closure. Proactively assess and document the control impacts of technology implementations, migrations, or retirements to prevent monitoring gaps.
- Audit Support Risk Integration:
Leverage CCM activities to build a repository of reusable evidence, reducing audit fatigue for operational teams and supporting external audits (e.g., ISO, SOC 2). Identify recurring control weaknesses or material gaps and provide analysis to GRC leadership to support formal risk treatment.
- Metrics Reporting: Prepare regular reports and dashboards highlighting monitoring completion rates, remediation aging, repeat findings, and automation coverage to provide GRC leadership with clear visibility into systemic issues and control trends.
Qualifications
- Bachelors degree in Information Systems, Computer Science, or a related field.
- Proven experience in IT audit, security compliance, or a related field.
- Familiarity with frameworks such as ISO, SOC 2, and their control requirements.
- Robust understanding of IT and security controls, including access management, change management, and vulnerability management.
- Experience with tools such as SIEM, IAM, Cloud Security platforms, ITSM, and Jira.
- Excellent analytical, problem-solving, and communication skills.
- Ability to work independently and collaboratively with technical and non-technical stakeholders.
- Strong organizational skills and attention to detail.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Governance Risk and Compliance Analyst (Bengaluru)
🏢 SolarWinds
📍 Bengaluru