FloQast is looking for a Senior GRC Manager to join our growing Compliance team. Based in our Pune, India office, this position will support the management of compliance controls, organizational policies, procedures, and standards in support of regulatory compliance needs as well as organizational information security practices for the region. You will advise and build relationships with key team members across multiple core departments, aligning department workflows to build a best-in-class compliance program.
The Compliance department at FloQast reports directly to the General Counsel and is responsible for ensuring FloQast maintains compliance with an array of security and privacy frameworks, including GDPR, CPRA, ISO 27001, ISO 27701, ISO 42001, SOC 1, and SOC 2. We are a team of in-house subject matter experts that advise, direct, train, and monitor the organization, resulting in daily interactions with all departments working together on a variety of unique and interesting business initiatives.
\nBe the primary point of contact for all things GRC for our Puna, India office acting as an internal resource for compliance-related questions and initiatives.
Support implementation of FloQast's internal controls inventory as new controls are added and existing controls are changed
Build upon the controls inventory to ensure control owners, testing procedures, related policies, and other pertinent information is accurately documented and kept up to date for the Pune office.
Work with control owners in Pune to ensure process narratives are documented and updated annually for all controls
Initiate, monitor, and follow up on monthly and quarterly control activities to ensure they are completed on time and proper evidence is documented to meet audit requirements.
Serve as a trusted advisor and advocate for security and compliance, engaging with teams across the company to foster a strong risk-aware culture.
Facilitate the development and maintenance of policies, standards, processes, and guidelines by drafting the documentation update, gathering the appropriate approvals, and reporting on all changes in policy review meetings.
Support annual internal and external ISO 27001, ISO 27701, ISO 42001 SOC 1, SOC 2, and other similar audits by scheduling audit interviews, submitting evidence requests to control owners, following up as needed to obtain evidence on time, reviewing evidence provided for accuracy, and facilitating follow up requests as needed to ensure our audits remain on schedule.
Aggregate identified internal control issues and perform a root cause analysis and collaborate on remediation efforts
Be an advocate for compliance best practices and the point of contact for stakeholders from departments throughout the company
Support customer assurance activities, including completion of security questionnaires and participation in customer discussions.
Participate in and contribute to cross-functional project teams
Any other tasks that may be assigned to help the company meet its goals
4+ years of relevant experience
Knowledge and familiarity with at least one security, privacy, and compliance practices (SOC 1, SOC 2, ISO 27001, ISO 27701, ISO 42001, PCI, HIPAA, etc)
Understanding of information security and privacy fundamentals
Certification preferred in one of the following: CompTIA, CISSP, CISA, CISM, Cloud platforms such as AWS, Azure or GCP
Confidence and willingness to ask questions, raise issues, and concerns in a timely manner
Understanding of AI governance or leveraging AI tools to improve compliance and audit efficiency
Familiarity with NIST, CIS, and other information security frameworks is a bonus but not required
Experience working for a software development company is a bonus but not required
Highly collaborative, detail-oriented, intellectually curious, with strong organizational skills and an authentically friendly demeanor
Builder mindset, comfortable sharing ideas, trying new approaches and is focused on achieving team and company short and long term goals
Flexible and adaptable in high growth, start-up environment
FloQast is the leading Accounting Transformation Platform in accounting workflow automation created by actual former accountants for accountants. By streamlining and modernizing daily accounting tasks, FloQast helps teams collaborate more effectively and complete their work with greater efficiency and precision. This cloud-based, AI-powered software is trusted by over 3,000 accounting teams, including those at Snowflake, Twilio, Instacart, and The Golden State Warriors—and continues to grow. Our mission is to continuously elevate the accounting profession, enhancing both its practice and perception.
By applying for this position, you acknowledge and consent to FloQast’s collection, use, processing, and storage of your personal information and application materials in accordance with our privacy policy and applicable law, including, but not limited to, your resume, cover letter, contact information, employment history, references, and any other details or information provided during the application and interview process. Your information may be shared with hiring managers, HR personnel, and other employees involved in the hiring process, as well as authorized third-party service providers who assist with our hiring process. You have the right to access, correct or request the deletion of your personal information at any time. To exercise these rights, or for other questions related to our data practices, please contact us at recruiting@floqast.com. Your consent is voluntary, but please note that providing this consent is necessary for us to process your application and consider you for employment opportunities. For more details, please see our privacy policy at https://www.floqast.com/legal/privacy-policy.
FloQast, Inc is committed to operating fair and unbiased recruitment procedures allowing all applicants an equal opportunity for employment, free from discrimination on the basis of religion, race, sex, age, sexual orientation, disability, color, ethnic or national origin, or any other classification as may be protected by applicable law. We aim to recruit the right people for the jobs we have to offer, and to assess applications on the basis of relevant skills, education, and experience. We welcome people of different backgrounds, experiences, abilities, and perspectives. We are an equal opportunity employer and strive to provide a professional and welcoming workplace for all employees.