Governance Risk and Compliance Analyst

at SolarWinds (View all jobs)

Bangalore, India

Req ID: 202799

At SolarWinds, we’re a people-first company. Our purpose is to enrich the lives of the people we serve—including our employees, customers, shareholders, partners, and communities. Join us in our mission to help customers accelerate business transformation with simple, powerful, and secure solutions.

The ideal candidate thrives in an innovative, fast-paced environment and is collaborative, accountable, ready, and empathetic. We’re looking for individuals who believe they can accomplish more as a team and create lasting growth for themselves and others. We hire based on attitude, competency, and commitment. Solarians are ready to advance our world-class solutions in a fast-paced environment and accept the challenge to lead with purpose. If you’re looking to build your career with an exceptional team, you’ve come to the right place. Join SolarWinds and grow with us!

Summary: The GRC Analyst – Continuous Monitoring & Control Assurance plays a pivotal role in executing the organization’s continuous control monitoring (CCM) program. Under the direction of GRC leadership, this role is responsible for validating the effectiveness of critical IT and security controls, driving remediation efforts, and championing evidence automation. The goal is to enhance audit readiness and ensure that daily activities are aligned with the overarching GRC assurance strategy.

 

Responsibilities:

  • Continuous Control Monitoring Execution: Perform recurring, risk-based monitoring across critical domains such as access management, change management, segregation of duties, vulnerability management, and disaster recovery. Maintain testing schedules, coordinate evidence collection with control owners, and document exceptions using established methodologies.
  • Technical Integration & Automation: Partner with Security Operations, IT, and Engineering to extract and evaluate evidence directly from operational platforms (SIEM, IAM, Cloud Security, ITSM, Jira). Identify opportunities to transition from manual collection to automated, system-generated reporting and repeatable queries.
  • Deficiency Management & Technology Transitions: Analyze evidence to identify control gaps, establish root causes with control owners, and track corrective actions through validation and closure. Proactively assess and document the control impacts of technology implementations, migrations, or retirements to prevent monitoring gaps.
  • Audit Support & Risk Integration: Leverage CCM activities to build a repository of reusable evidence, reducing audit fatigue for operational teams and supporting external audits (e.g., ISO, SOC 2). Identify recurring control weaknesses or material gaps and provide analysis to GRC leadership to support formal risk treatment.
  • Metrics & Reporting: Prepare regular reports and dashboards highlighting monitoring completion rates, remediation aging, repeat findings, and automation coverage to provide GRC leadership with clear visibility into systemic issues and control trends.

Qualifications:

  • Bachelor’s degree in Information Systems, Computer Science, or a related field.
  • Proven experience in IT audit, security compliance, or a related field.
  • Familiarity with frameworks such as ISO, SOC 2, and their control requirements.
  • Strong understanding of IT and security controls, including access management, change management, and vulnerability management.
  • Experience with tools such as SIEM, IAM, Cloud Security platforms, ITSM, and Jira.
  • Excellent analytical, problem-solving, and communication skills.
  • Ability to work independently and collaboratively with technical and non-technical stakeholders.
  • Strong organizational skills and attention to detail.

 

SolarWinds is an Equal Employment Opportunity Employer. SolarWinds will consider all qualified applicants for employment without regard to race, color, religion, sex, age, national origin, sexual orientation, gender identity, marital status, disability, veteran status or any other characteristic protected by law.

All applications are treated in accordance with the SolarWinds Privacy Notice: https://www.solarwinds.com/applicant-privacy-notice