Base Career helps you apply smarter for this job.
Key skills for this role
The Compliance Analyst is a senior individual contributor within the PennEngineering IS Risk & Compliance team who supports the Compliance Program Owner by owning defined compliance sub-components, executing audits and assessments, and driving day-to-day compliance operations.
This role supports the Sr. IT Risk & Security Engineer and Sr. Compliance Analyst to ensure regulatory, audit, and governance requirements are met across the enterprise.
The Compliance Analyst reports to the Senior Manager, IT Risk, Security & Compliance.
The Compliance Analyst is a senior individual contributor within the PennEngineering IS Risk & Compliance team who supports the Compliance Program Owner by owning defined compliance sub-components, executing audits and assessments, and driving day-to-day compliance operations.
This role supports the Sr. IT Risk & Security Engineer and Sr. Compliance Analyst to ensure regulatory, audit, and governance requirements are met across the enterprise.
The Compliance Analyst reports to the Senior Manager, IT Risk, Security & Compliance.
Support the execution and ongoing monitoring of assigned compliance controls and domains (e.g., access governance, data access reviews, system compliance checks, operational controls).
Perform assigned reviews to validate that controls are operating as designed and documented.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Bengaluru, IND
Bengaluru, IND
Bengaluru, IND
Bengaluru, IND
Bengaluru, IND
Bengaluru, IND
Bengaluru, IND
, USA
, USA
Support compliance reporting, tracking, metrics, and remediation status using Jira or other internal governance tools.
Identify and report control gaps, risks, and systemic issues to the Compliance Program Owner with clear analysis and recommendations.
Serve as the operational owner of the Varonis platform.
Enhance and validate the use of Varonis to: Monitor and review user access rights to sensitive data Identify excessive, inappropriate, or anomalous access Support periodic access reviews and audit evidence collection Apply data classification labeling to relevant data
Monitor and review user access rights to sensitive data
Identify excessive, inappropriate, or anomalous access
Support periodic access reviews and audit evidence collection
Apply data classification labeling to relevant data
Partner with Security Engineering to: Improve Varonis alerting, reporting, and coverage to better support compliance objectives Identify opportunities to automate or streamline compliance evidence using Varonis data
Improve Varonis alerting, reporting, and coverage to better support compliance objectives
Identify opportunities to automate or streamline compliance evidence using Varonis data
Translate Varonis findings into: Actionable remediation tasks Audit-ready evidence Clear risk summaries for the Compliance Program Owner
Actionable remediation tasks
Audit-ready evidence
Clear risk summaries for the Compliance Program Owner
Continuously evaluate how Varonis is being used and recommend enhancements to improve compliance visibility, control assurance, and audit readiness.
Support internal and external audits, including: Evidence collection and validation (including Varonis-based evidence) Control walkthrough preparation Interview preparation. documentation and coordination with system and process owners
Evidence collection and validation (including Varonis-based evidence)
Control walkthrough preparation
Interview preparation. documentation and coordination with system and process owners
Assist with audit responses and remediation plans for assigned findings.
Help track remediation progress through closure and report status to the Compliance Program Owner.
Support the Program Owner during audit planning, auditor interactions, and final reporting.
Assist with maintenance and policy updates under the direction of the Compliance Program Owner.
Support policy gap assessments related to assigned systems or regulatory areas.
Support policy revisions and documentation review and approval.
Manage policy publication, attestation, and training coordination through platforms such as KnowBe4.
Support assigned (sub) section of vendor security and compliance assessments.
Collect vendor documentation (e.g., SOC reports, questionnaires).
Assist with Vendor outreach and feedback for assigned reviews.
Support security training initiatives by assisting with tracking completion, identifying non-compliance trends, and assisting with reporting and follow up communications.
Maintain and review KnowBe4 users, groups and assigned training curriculum and campaign roll-outs.
Identify opportunities to improve compliance workflows, tooling usage, documentation quality, and reporting efficiency.
Assist with implementation and optimization of compliance tooling and processes.
Collaborate with and support compliance staff as needed.
Privately owned manufacturing group serving automotive, electronics, datacom, electric-vehicle, and industrial markets with fasteners and installation equipment.
Visit company websiteJobs and hiring trendsFull-time
Mid · 3+ years experience
Onsite
Apply faster on company sites with our extension.