Loading jobs…
Loading jobs…
Workato — Altona, Manitoba
About Workato Workato delivers enterprise infrastructure for the agentic era, redefining iPaaS and helping enterprises unify data, applications, processes, and AI into a single, governed platform. A leader in Enterprise MCP and trusted by 50% of the Fortune 500, Workato’s cloud-native architecture connects every application, data source, and process to power real-time orchestration at scale. With enterprise-grade security and continuous innovation at its core, Workato provides the trusted foundation for organizations to automate with confidence and operationalize AI across the business.
Why Join Us
Ultimately, Workato believes in fostering a flexible, trust-oriented culture that empowers everyone to take full ownership of their roles . We are driven by innovation and looking for team players who want to actively build our company. But, we also believe in balancing productivity with self-care .
Benefits
they can enjoy inside and outside of their work lives. If this sounds right up your alley, please submit an application. We look forward to getting to know you!
Responsibilities
Workato is seeking a detail-oriented, driven, and technically experienced Senior GRC Analyst to strengthen and advance its security governance, risk, and compliance (GRC) program — with a primary focus on FedRAMP authorization and ongoing federal compliance operations.
Requirements
, while also supporting broader compliance frameworks including ISO 27001, NIST 800-171, PCI-DSS, and IRAP. The ideal candidate will bring deep federal compliance expertise combined with strong analytical, communication, and problem-solving skills to evaluate controls, identify gaps, and drive improvements across security domains.
, including monthly vulnerability scanning, incident reporting, and annual assessments Maintain and update FedRAMP authorization documentation, including SSP, CIS, CRM, and associated artifacts Lead internal and external audits for frameworks including FedRAMP (NIST 800-53), ISO 27001/27701, PCI-DSS, NIST 800-171, and IRAP Coordinate with process owners, control owners, 3PAOs, and federal agency stakeholders to ensure findings are tracked and remediated Conduct risk assessments, security audits, and third-party/vendor risk reviews with a focus on FedRAMP boundary and supply chain risk Review contracts to ensure security and compliance
— including FedRAMP flow-down clauses — are met Identify control gaps and recommend improvements to enhance the organization's federal security posture Communicate FedRAMP
, risks, and compliance status clearly to both technical and non-technical stakeholders, including federal agency customers Perform regular user access reviews aligned to least-privilege and FedRAMP AC control
Develop and track remediation plans for identified risks and POA M items Maintain and update the risk register with federal risk considerations Oversee vendor and subservice provider security assurance pr