Compliance Analyst

PENN ENGINEERING

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

PENN ENGINEERING is seeking a Compliance Analyst to join the Corporate Global Information System team in Bengaluru. You will own defined compliance sub-components, perform audits and assessments, and drive day-to-day compliance operations across the enterprise.

You will support audits, maintain controls, and collaborate with Security Engineering to enhance evidence and reporting. Strong English communication and IT risk experience are required.

Qualifications

  • Bachelor’s degree in a related field and 3–5 years IT compliance/risk experience.
  • Hands-on use of Varonis for access governance, monitoring, or audits.
  • Strong documentation and stakeholder communication skills in English.

Responsibilities

  • Support execution and monitoring of assigned compliance controls and domains.
  • Validate controls operate as designed and documented.
  • Assist with compliance reporting, tracking, metrics and remediation status.
  • Serve as the operational owner of the Varonis platform.
  • Collaborate with Security Engineering to improve alerting and coverage.
  • Assist with audits, including evidence collection and walkthroughs.

Skills

Documentation
Analytical skills
Stakeholder communication
English proficiency

Education

Bachelor's degree in Information Systems, Cybersecurity, Risk Management, or related field

Tools

Varonis
Jira
GRC platforms (Archer, Drata, Vanta)
KnowBe4
Active Directory / LDAP
M365 Entra / Purview

Job description

Department: Corporate Global Information System

Position Summary:

The Compliance Analyst is a senior individual contributor within the PennEngineering IS Risk & Compliance team who supports the Compliance Program Owner by owning defined compliance sub-components, executing audits and assessments, and driving day-to-day compliance operations.

This role supports the Sr. IT Risk & Security Engineer and Sr. Compliance Analyst to ensure regulatory, audit, and governance requirements are met across the enterprise.

The Compliance Analyst reports to the Senior Manager, IT Risk, Security & Compliance.

Key Responsibility

Compliance Execution

  • Support the execution and ongoing monitoring of assigned compliance controls and domains (e.g., access governance, data access reviews, system compliance checks, operational controls).
  • Perform assigned reviews to validate that controls are operating as designed and documented.
  • Support compliance reporting, tracking, metrics, and remediation status using Jira or other internal governance tools.
  • Identify and report control gaps, risks, and systemic issues to the Compliance Program Owner with clear analysis and recommendations.
  • Serve as the operational owner of the Varonis platform.
  • Enhance and validate the use of Varonis to:
    • Monitor and review user access rights to sensitive data
    • Identify excessive, inappropriate, or anomalous access
    • Support periodic access reviews and audit evidence collection
    • Apply data classification labeling to relevant data
  • Partner with Security Engineering to:
    • Improve Varonis alerting, reporting, and coverage to better support compliance objectives
    • Identify opportunities to automate or streamline compliance evidence using Varonis data
  • Translate Varonis findings into:
    • Actionable remediation tasks
    • Audit-ready evidence
    • Clear risk summaries for the Compliance Program Owner
  • Continuously evaluate how Varonis is being used and recommend enhancements to improve compliance visibility, control assurance, and audit readiness.
  • Support internal and external audits, including:
    • Evidence collection and validation (including Varonis-based evidence)
    • Control walkthrough preparation
    • Interview preparation. documentation and coordination with system and process owners
  • Assist with audit responses and remediation plans for assigned findings.
  • Help track remediation progress through closure and report status to the Compliance Program Owner.
  • Support the Program Owner during audit planning, auditor interactions, and final reporting.

Policy & Documentation Maintenance

  • Assist with maintenance and policy updates under the direction of the Compliance Program Owner.
  • Support policy gap assessments related to assigned systems or regulatory areas.
  • Support policy revisions and documentation review and approval.
  • Manage policy publication, attestation, and training coordination through platforms such as KnowBe4.

Vendor & Third-Party Risk Management

  • Support assigned (sub) section of vendor security and compliance assessments.
  • Assist with Vendor outreach and feedback for assigned reviews.

Training, Awareness & Operational Support

  • Support security training initiatives by assisting with tracking completion, identifying non-compliance trends, and assisting with reporting and follow up communications.
  • Maintain and review KnowBe4 users, groups and assigned training curriculum and campaign roll-outs.
  • Identify opportunities to improve compliance workflows, tooling usage, documentation quality, and reporting efficiency.
  • Assist with implementation and optimization of compliance tooling and processes.
  • Collaborate with and support compliance staff as needed.
Requirements:
  • Bachelor's degree in Information Systems, Cybersecurity, Risk Management, or related field (or equivalent experience).
  • 3-5years of experience in IT compliance, audit and risk management.
  • Hands-on experience and skills in using Varonis for access governance, monitoring, or audit support.
  • Experience supporting audits and maintaining compliance controls.
  • Strong documentation, analytical, and stakeholder communication skills.
  • Demonstrated professional fluency in English (written and spoken) required for collaboration with global stakeholders and preparation of technical and compliance documentation
Preferred Qualifications:
  • Experience with ISO 27001, TISAX SOC, or similar frameworks.
  • Strong familiarity with Jira, GRC platforms (e.g Archer, Drata, Vanta), and compliance training tools (KnowBe4)
  • Experience with Active Directory (LDAP), M365 Entra and Purview
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Compliance Analyst
Senior Compliance Analyst

PENN ENGINEERING • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Security Compliance Analyst
Senior Security Compliance Analyst

TaskUs • India

On-site
INR 1,400,000 - 2,100,000
Security & Compliance Engineer
Security & Compliance Engineer

Kognitive Networks Inc. • Chennai District

Hybrid
INR 1,200,000 - 1,600,000
Group health insurance
Flexible working hours
Hybrid work model
Senior GRC Analyst
Senior GRC Analyst

Exotel • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Staff Risk & Compliance Analyst
Staff Risk & Compliance Analyst

GE-Vernova- • Bengaluru

Hybrid
INR 800,000 - 1,500,000
Relocation assistance
Audit & Compliance Analyst
Audit & Compliance Analyst

Codincity Digital Technologies • Chennai District

On-site
INR 1,200,000 - 1,800,000
Info/Security - Analyst
Info/Security - Analyst

Ascendion Engineering • Hyderabad

Hybrid
INR 2,500,000 - 3,800,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Bigshare Services • Mumbai

On-site
INR 1,200,000 - 2,100,000
IT Security And Compliance Engineer
IT Security And Compliance Engineer

Rapyuta Robotics • Chennai District

On-site
INR 1,500,000 - 2,500,000
Competitive salary
Great team culture
Cybersecurity & Compliance Advisor
Cybersecurity & Compliance Advisor

Siemens • Gurugram District

On-site
INR 2,800,000 - 4,200,000