Sr GRC Analyst
| Hours | Full-time, Part-time |
|---|---|
| Location | Herndon, Virginia |
About this job
04-Sep-2026
US (Remote)
11223BR
Company Summary
As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America's Best Midsize Employers by Forbes, a Best Place to Work by Glassdoor, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. www.deltek.com
At Deltek, security isn't a gate at the end of the process - it's in the foundation. Enterprise Security & Technology Services (ESTS) brings together security, infrastructure, and technology operations under one organization, led by our CISO, with a mandate to make sure Deltek builds and operates with integrity at every layer.
We're a passionate team of technologists and security professionals who work across the entire company - embedded in how services are built, delivered, and supported. We run agile, we embrace intelligent automation to amplify what our people can do, and we hold ourselves to a high standard because the organizations that depend on Deltek's platform are doing work that can't afford mistakes. If you take your craft seriously, want visibility into how a complex, global technology organization really operates, and believe security should be a first principle - not an afterthought - this is a team that will feel like home.
Business Summary
Built on 40 years of industry expertise, Deltek is a leading provider of ERP solutions for Government contractors of all sizes. & whether these firms call them a contract within the government contracting space, an engagement within professional services firms or refer to them as a project within the AEC space, these organizations share the same ultimate goal-to win & deliver successful projects.
Deltek offers complete & integrated software solutions that connect & automate every stage of the project lifecycle, enhancing project intelligence, management, & collaboration. With Deltek's industry-focused expertise & end-to-end visibility into project & financial performance, we empower businesses to make data-driven decisions, mitigate risks, & deliver projects on time & within budget.
Position Responsibilities
Responsibilities:
As a Senior GRC Analyst, you will support assessment, audit readiness, cloud security compliance, risk management, & security tooling across SaaS/cloud environments. You ensure controls are documented, measurable, continuously monitored, & aligned with applicable frameworks, laws, & regulations. This role supports customer trust by delivering clear evidence, accurate reporting, & well-managed remediation across Engineering, Product, & IT.
Priorities:
(1) Audit readiness & evidence delivery,
(2) Control documentation, continuous monitoring, &
(3) Risk/PoA&M reporting, assigned deliverables end-to-end & coordinating inputs from Engineering, Product, & IT.
Audit & frameworks:
- Lead or support audits & assessments for cloud SaaS applications across frameworks such as SOC 1, SOC 2, NIST 800-53, NIST 800-171, CMMC, ISO, FedRAMP, PCI DSS, CIS, CSA CCM, & other security or regulatory standards/frameworks.
- Manage scoping, evidence requests, control testing, issue tracking, remediation follow-up, & final report support.
- Assess & communicate administrative, technical, & security controls across OCI, AWS, Azure, & related cloud services.
- Apply project management practices to plan, track, & deliver assessments, including use of Jira for epics, stories, backlog management, & stakeholder reporting.
- Use automation & AI responsibly to streamline evidence collection, control mapping, & recurring reporting, with appropriate human review.
- Build & maintain GRC metrics & dashboards for reporting.
- Present trends, risks, remediation status, & control health to leadership.
- Draft & maintain security policies, standards, System Security Plans, control narratives, implementation details, & evidence references.
- Produce high-quality audit deliverables, including narratives, evidence packages, status reports, & remediation updates.
- Manage risk register items & PoA&Ms from identification through closure, including control gap analysis, remediation planning, owner coordination, & progress tracking.
- Translate control requirements & regulatory obligations into clear, testable expectations for technical teams.
Program ownership & documentation:
- Own or backup for key GRC programs by maintaining procedures, SLAs, & artifacts for audits & customer requests (e.g., policy management & security due diligence questionnaires to support RFIs & RFPs).
- Actively participate in initiatives aimed at enhancing team processes & procedures.
- Help maintain & curate annual compliance training content & improve training process.
- Interpret control requirements & regulatory obligations accurately, & translate them into clear, testable expectations for technical teams.
- Participate in incident response reviews & RCAs by documenting control failures, corrective actions, & follow-up evidence for closure.
Qualifications
Technical Requirements:
Independently lead audit workstreams, driving stakeholder follow-through, & owning evidence/control documentation through completion (years of experience are a guideline, but demonstrated scope & impact are key).
- B.S. degree (Information Security, Computer Science, MIS, or equivalent program preferred) from an accredited college/university.
- 3+ years supporting audits & compliance work across common frameworks (see framework list above), with demonstrated evidence collection, control testing, & remediation tracking.
- Minimum 3 years of combined experience with implementing and/or assessing: IT audit, IT risk management, Cloud security & compliance, internal audit function, Information Technology General Controls (ITGC), Information security operations.
- Experience supporting government-related compliance efforts (e.g., FedRAMP- or DoD-aligned expectations) within cloud environments, including evidence packaging & stakeholder coordination.
- Hold (or be actively pursuing) relevant certifications such as CISA, CISSP, CCSK/CCAK, or major cloud security certifications (Azure/AWS/GCP), with active status preferred.
- Work independently, exercise good judgment & proactively seeks guidance as needed.
- Manage time effectively across multiple priorities & concurrent projects.
- Demonstrate strong analytical & critical-thinking skills with business & technical acumen.
- Communicate clearly in writing, verbally & collaborate effectively with diverse stakeholders.
- Thrives in a fast-paced, collaborative environment & contribute to shared outcomes.
- Follow directions from senior staff & supports peers to deliver high-quality, time-bound work.
- Continuously learn through structured, on-the-job, & self-directed development.