As a Senior GRC Analyst, you will support assessment, audit readiness, cloud security compliance, risk management, & security tooling across SaaS/cloud environments. You ensure controls are documented, measurable, continuously monitored, & aligned with applicable frameworks, laws, & regulations. This role supports customer trust by delivering clear evidence, accurate reporting, & well-managed remediation across Engineering, Product, & IT.
Priorities:
(1) Audit readiness & evidence delivery,
(2) Control documentation, continuous monitoring, &
(3) Risk/PoA&M reporting, assigned deliverables end-to-end & coordinating inputs from Engineering, Product, & IT.
Audit & frameworks:
- Lead or support audits & assessments for cloud SaaS applications across frameworks such as SOC 1, SOC 2, NIST 800-53, NIST 800-171, CMMC, ISO, FedRAMP, PCI DSS, CIS, CSA CCM, & other security or regulatory standards/frameworks.
- Manage scoping, evidence requests, control testing, issue tracking, remediation follow-up, & final report support.
- Assess & communicate administrative, technical, & security controls across OCI, AWS, Azure, & related cloud services.
- Apply project management practices to plan, track, & deliver assessments, including use of Jira for epics, stories, backlog management, & stakeholder reporting.
- Use automation & AI responsibly to streamline evidence collection, control mapping, & recurring reporting, with appropriate human review.
Reporting & continuous improvement:
- Build & maintain GRC metrics & dashboards for reporting.
- Present trends, risks, remediation status, & control health to leadership.
- Draft & maintain security policies, standards, System Security Plans, control narratives, implementation details, & evidence references.
- Produce high-quality audit deliverables, including narratives, evidence packages, status reports, & remediation updates.
- Manage risk register items & PoA&Ms from identification through closure, including control gap analysis, remediation planning, owner coordination, & progress tracking.
- Translate control requirements & regulatory obligations into clear, testable expectations for technical teams.
Program ownership & documentation:
- Own or backup for key GRC programs by maintaining procedures, SLAs, & artifacts for audits & customer requests (e.g., policy management & security due diligence questionnaires to support RFIs & RFPs).
- Actively participate in initiatives aimed at enhancing team processes & procedures.
- Help maintain & curate annual compliance training content & improve training process.
- Interpret control requirements & regulatory obligations accurately, & translate them into clear, testable expectations for technical teams.
- Participate in incident response reviews & RCAs by documenting control failures, corrective actions, & follow-up evidence for closure.
Independently lead audit workstreams, driving stakeholder follow-through, & owning evidence/control documentation through completion (years of experience are a guideline, but demonstrated scope & impact are key).
- B.S. degree (Information Security, Computer Science, MIS, or equivalent program preferred) from an accredited college/university.
- 3+ years supporting audits & compliance work across common frameworks (see framework list above), with demonstrated evidence collection, control testing, & remediation tracking.
- Minimum 3 years of combined experience with implementing and/or assessing: IT audit, IT risk management, Cloud security & compliance, internal audit function, Information Technology General Controls (ITGC), Information security operations.
- Experience supporting government-related compliance efforts (e.g., FedRAMP- or DoD-aligned expectations) within cloud environments, including evidence packaging & stakeholder coordination.
- Hold (or be actively pursuing) relevant certifications such as CISA, CISSP, CCSK/CCAK, or major cloud security certifications (Azure/AWS/GCP), with active status preferred.
Core Competencies
- Work independently, exercise good judgment & proactively seeks guidance as needed.
- Manage time effectively across multiple priorities & concurrent projects.
- Demonstrate strong analytical & critical-thinking skills with business & technical acumen.
- Communicate clearly in writing, verbally & collaborate effectively with diverse stakeholders.
- Thrives in a fast-paced, collaborative environment & contribute to shared outcomes.
- Follow directions from senior staff & supports peers to deliver high-quality, time-bound work.
- Continuously learn through structured, on-the-job, & self-directed development.
Preferences
- CCAK/CCSK, CISSP, CISA, or other related information security certification desired.
- Demonstrable FedRAMP, ISO & SOC Security Framework experience desired.
- Experience with effective AI usage, data analysis, report preparation, automation, & templating of repeat processes.
Benefits and perks listed here may vary depending on the nature of employment with Deltek. Employees have access to healthcare benefits, a 401(k) plan and company match, paid vacation time and holidays, well-living programs, short-term and long-term disability coverage, basic life insurance and tuition reimbursement.
At Deltek, security isn’t a gate at the end of the process — it’s in the foundation. Enterprise Security & Technology Services (ESTS) brings together security, infrastructure, and technology operations under one organization, led by our CISO, with a mandate to make sure Deltek builds and operates with integrity at every layer.
We’re a passionate team of technologists and security professionals who work across the entire company — embedded in how services are built, delivered, and supported. We run agile, we embrace intelligent automation to amplify what our people can do, and we hold ourselves to a high standard because the organizations that depend on Deltek’s platform are doing work that can’t afford mistakes. If you take your craft seriously, want visibility into how a complex, global technology organization really operates, and believe security should be a first principle — not an afterthought — this is a team that will feel like home.
Deltek offers complete & integrated software solutions that connect & automate every stage of the project lifecycle, enhancing project intelligence, management, & collaboration. With Deltek’s industry-focused expertise & end-to-end visibility into project & financial performance, we empower businesses to make data-driven decisions, mitigate risks, & deliver projects on time & within budget.
Candidate Privacy Notice
Additionally, we have not sold and do not sell Personal Data you provide to us through the job application process.
Important: Protect Yourself from Recruitment Scams
Bad actors or scammers may try to impersonate Deltek and send fake job offers to people. Messages from Deltek about employment opportunities will be from an @deltek.com account or Enterprise@trm.brassring.com, never from free services like Gmail or Yahoo. Please look carefully at the email address that provides any job offer, as some fake accounts are created to look like a legitimate domain name or email address. We will also never ask you to pay money at any point in the hiring process, whether for training, equipment, background checks, or anything else. If you receive a suspicious offer claiming to be from Deltek, do not share personal or financial information. Report any suspicious communication to Secure@deltek.com and consider reporting it to law enforcement.
Why Join #TeamDeltek
Grow. Collaborate. Innovate.
The work we do is important. The way we do it is just as important. Our values guide the decisions we make, how we work together, and how we help our customers succeed. That’s what makes Deltek more than a place to work — it’s a place where you can grow, make an impact, and help others do the same.



