Just postedUrgently hiring Use left and right arrow keys to navigate
Hours Full-time, Part-time
Location Herndon, Virginia

About this job

04-Sep-2026

Senior GRC Analyst

US (Remote)

11223BR

Company Summary

As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America's Best Midsize Employers by Forbes, a Best Place to Work by Glassdoor, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. www.deltek.com

At Deltek, security isn't a gate at the end of the process - it's in the foundation. Enterprise Security & Technology Services (ESTS) brings together security, infrastructure, and technology operations under one organization, led by our CISO, with a mandate to make sure Deltek builds and operates with integrity at every layer.
We're a passionate team of technologists and security professionals who work across the entire company - embedded in how services are built, delivered, and supported. We run agile, we embrace intelligent automation to amplify what our people can do, and we hold ourselves to a high standard because the organizations that depend on Deltek's platform are doing work that can't afford mistakes. If you take your craft seriously, want visibility into how a complex, global technology organization really operates, and believe security should be a first principle - not an afterthought - this is a team that will feel like home.

Business Summary

Built on 40 years of industry expertise, Deltek is a leading provider of ERP solutions for Government contractors of all sizes. & whether these firms call them a contract within the government contracting space, an engagement within professional services firms or refer to them as a project within the AEC space, these organizations share the same ultimate goal-to win & deliver successful projects.
Deltek offers complete & integrated software solutions that connect & automate every stage of the project lifecycle, enhancing project intelligence, management, & collaboration. With Deltek's industry-focused expertise & end-to-end visibility into project & financial performance, we empower businesses to make data-driven decisions, mitigate risks, & deliver projects on time & within budget.

Position Responsibilities

Responsibilities:
As a Senior GRC Analyst, you will support assessment, audit readiness, cloud security compliance, risk management, & security tooling across SaaS/cloud environments. You ensure controls are documented, measurable, continuously monitored, & aligned with applicable frameworks, laws, & regulations. This role supports customer trust by delivering clear evidence, accurate reporting, & well-managed remediation across Engineering, Product, & IT.

Priorities:
(1) Audit readiness & evidence delivery,
(2) Control documentation, continuous monitoring, &
(3) Risk/PoA&M reporting, assigned deliverables end-to-end & coordinating inputs from Engineering, Product, & IT.

Audit & frameworks:

  • Lead or support audits & assessments for cloud SaaS applications across frameworks such as SOC 1, SOC 2, NIST 800-53, NIST 800-171, CMMC, ISO, FedRAMP, PCI DSS, CIS, CSA CCM, & other security or regulatory standards/frameworks.
  • Manage scoping, evidence requests, control testing, issue tracking, remediation follow-up, & final report support.
  • Assess & communicate administrative, technical, & security controls across OCI, AWS, Azure, & related cloud services.
  • Apply project management practices to plan, track, & deliver assessments, including use of Jira for epics, stories, backlog management, & stakeholder reporting.
  • Use automation & AI responsibly to streamline evidence collection, control mapping, & recurring reporting, with appropriate human review.
Reporting & continuous improvement:
  • Build & maintain GRC metrics & dashboards for reporting.
  • Present trends, risks, remediation status, & control health to leadership.
  • Draft & maintain security policies, standards, System Security Plans, control narratives, implementation details, & evidence references.
  • Produce high-quality audit deliverables, including narratives, evidence packages, status reports, & remediation updates.
  • Manage risk register items & PoA&Ms from identification through closure, including control gap analysis, remediation planning, owner coordination, & progress tracking.
  • Translate control requirements & regulatory obligations into clear, testable expectations for technical teams.

Program ownership & documentation:
  • Own or backup for key GRC programs by maintaining procedures, SLAs, & artifacts for audits & customer requests (e.g., policy management & security due diligence questionnaires to support RFIs & RFPs).
  • Actively participate in initiatives aimed at enhancing team processes & procedures.
  • Help maintain & curate annual compliance training content & improve training process.
  • Interpret control requirements & regulatory obligations accurately, & translate them into clear, testable expectations for technical teams.
  • Participate in incident response reviews & RCAs by documenting control failures, corrective actions, & follow-up evidence for closure.

Qualifications

Technical Requirements:
Independently lead audit workstreams, driving stakeholder follow-through, & owning evidence/control documentation through completion (years of experience are a guideline, but demonstrated scope & impact are key).

  • B.S. degree (Information Security, Computer Science, MIS, or equivalent program preferred) from an accredited college/university.
  • 3+ years supporting audits & compliance work across common frameworks (see framework list above), with demonstrated evidence collection, control testing, & remediation tracking.
  • Minimum 3 years of combined experience with implementing and/or assessing: IT audit, IT risk management, Cloud security & compliance, internal audit function, Information Technology General Controls (ITGC), Information security operations.
  • Experience supporting government-related compliance efforts (e.g., FedRAMP- or DoD-aligned expectations) within cloud environments, including evidence packaging & stakeholder coordination.
  • Hold (or be actively pursuing) relevant certifications such as CISA, CISSP, CCSK/CCAK, or major cloud security certifications (Azure/AWS/GCP), with active status preferred.
Core Competencies
  • Work independently, exercise good judgment & proactively seeks guidance as needed.
  • Manage time effectively across multiple priorities & concurrent projects.
  • Demonstrate strong analytical & critical-thinking skills with business & technical acumen.
  • Communicate clearly in writing, verbally & collaborate effectively with diverse stakeholders.
  • Thrives in a fast-paced, collaborative environment & contribute to shared outcomes.
  • Follow directions from senior staff & supports peers to deliver high-quality, time-bound work.
  • Continuously learn through structured, on-the-job, & self-directed development.
Prefer

Nearby locations

Posting ID: 1294286807 Posted: 2026-09-05 Job Title: Senior Grc Analyst