Sr. GRC Analyst
SprinklrAbout the role
Sprinklr is the definitive, AI-native platform for Unified Customer Experience Management (Unified-CXM), empowering brands to deliver extraordinary experiences at scale — across every customer touchpoint.
By combining human instinct with the speed and efficiency of AI, Sprinklr helps brands earn trust and loyalty through personalized, seamless, and efficient customer interactions. Sprinklr’s unified platform provides powerful solutions for every customer-facing team — spanning social media management, marketing, advertising, customer feedback, and omnichannel contact center management — enabling enterprises to unify data, break down silos, and act on real-time insights.
Today, 1,900+ enterprises and 60% of the Fortune 100 rely on Sprinklr to help them deliver consistent, trusted customer experiences worldwide.
Job Description
The Sr. Governance, Risk, and Compliance (GRC) Analyst plays a key role in supporting the organization’s security and compliance programs across multiple frameworks. This position assists with maintaining security documentation, supporting security audits, and coordinating with internal teams, external assessors, and customers. Responsibilities include contributing to FedRAMP activities, handling customer security questionnaires and due‑diligence requests, advancing process automation within the GRC program, and supporting vendor risk management to strengthen the organization’s overall security posture. As this is a global organization, the Sr. GRC Security Analyst may occasionally be asked to attend meetings or respond to requests outside of normal respective office hours.
Responsibilities:
- Create and maintain core FedRAMP security artifacts (SSP, POA&M, checklists/templates); develop Significant Change Request documentation and support related assessments.
- Apply FedRAMP, NIST SP 800 53, and NIST SP 800 37 RMF to cloud environments; support control implementation and evidence.
- Support monthly/annual FedRAMP continuous monitoring; assist with vulnerability identification/mitigation and POA&M tracking; monitor and maintain in scope asset inventory.
- Manage and support audit engagements (SOC 2, ISO 27001, C5, SOX, PCI DSS, HIPAA).
- Assist with vendor risk management activities: intake, due diligence assessments, risk rating, contract/security terms review, remediation tracking, and periodic reviews.
- Drive GRC process automation to streamline evidence collection, control testing, workflows, and reporting using the GRC platform and integrations.
- Respond to customer security questionnaires, RFPs, and due diligence requests;
- Coordinate evidence and liaise with SMEs, assessors, and customers.
- Manage the control and process libraries; assist the business in implementing internal controls; document, assess, and remediate issues from audits and risk assessments.
- Contribute to meetings by preparing agendas, documenting minutes, and tracking follow up actions; assist with management of Sprinklr security standards/policies and maintain GRC repositories (Confluence, shared drives).
Qualifications:
- 3–4+ years in information security, risk, or compliance.
- Prior FedRAMP operational support experience.
- FedRAMP authorization and sustainment experience: develop/maintain SSP, POA&M, IR/Contingency/Configuration Management plans, and related artifacts.
- Strong understanding of FISMA; NIST RMF (SP 800 37) and NIST SP 800 53 Rev. 5; familiarity with the Cloud Computing SRG.
- FedRAMP Continuous Monitoring experience: vulnerability scanning/analysis, POA&M updates, and monthly/annual reporting.
- Cloud security across AWS, Google Cloud, and Azure with working knowledge of networking (IPsec, firewalls, routing, addressing); ability to apply FedRAMP control requirements to cloud services.
- Knowledge of security control frameworks and audits (NIST 800 53, ISO 27001/27002, SOC 2, SOX, PCI DSS, HIPAA); control design/testing and evidence management.
- Customer facing experience: responding to security questionnaires, RFPs, and customer audits/due diligence with clear written and verbal communication.
- Process automation: interest and experience automating GRC/compliance workflows, evidence collection, and reporting (e.g., within GRC platforms and via integrations/scripts).
- Vendor risk management experience across the third party lifecycle (intake, due diligence, risk rating, contract/security terms review, remediation, and periodic reviews).
We focus on our mission: Sprinklr was founded in 2009 to solve a big problem: growing enterprise complexity that separated brands from their customers. Our vision was clear: to unify fragmented team
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s