Senior GRC Analyst
Deltek
Senior GRC Analyst | Deltek, Inc
You will be part of the GRC team responsible for assessment, audits of cloud environments, information systems, risk management, and security tools to ensure adherence to applicable frameworks, laws, and regulations. As a Senior GRC Analyst, you will help maintain audit readiness and customer trust by ensuring our SaaS/cloud controls are well-documented, measurable, and aligned to applicable frameworks and regulatory expectations. Our goal is to help customers deliver successful projects with strong financial visibility, risk management, and on-time delivery—supported by secure, compliant products. Priorities: (1) Audit readiness and evidence delivery, (2) Control documentation, continuous monitoring, and (3) Risk/PoA&M reporting, assigned deliverables end-to-end and coordinating inputs from Engineering, Product, and IT. Core Role Requirements
- As a senior analyst: lead cloud SaaS application through various audit frameworks and assessments such as SOC 1, SOC 2, NIST 800-53, NIST 800-171, CMMC, ISO, FedRAMP, PCI DSS, CIS, CSA CSM, or other information security regulations.
- Lead and/or support end-to-end audit engagements (internal and external), including scoping, evidence requests, control testing, issue tracking, and final report support.
- Assess and communicate administrative, technical, and security controls across major cloud platforms, including Oracle Cloud Infrastructure (OCI), Amazon Web Services (AWS), and Microsoft Azure.
- Demonstrate the ability to apply project management practices to plan, track, and deliver security assessments, including hands-on use of Jira for epics/stories, backlog grooming, and stakeholder reporting.
- Use automation and AI responsibly to streamline evidence collection, control mapping, and recurring reporting while maintaining appropriate human review.
Reporting & continuous improvement
- Define, build, and maintain recurring GRC metrics and dashboards (monthly/quarterly), and present trends, risks, and remediation status to senior leadership.
- Draft, maintain, and socialize security policies/standards and System Security Plans (SSPs), including control narratives, implementation details, and evidence references.
- Communicate clearly with engineering, product, and auditors, and produce high-quality audit deliverables (e.g., narratives, evidence packages, and status reporting).
- Manage risk register items and PoA&Ms end-to-end—identify control gaps, partner with stakeholders on remediation plans, and track progress through continuous monitoring.
Program ownership & documentation
- Own (or serve as backup owner for) key GRC programs by maintaining procedures, SLAs, and artifacts for audits and customer requests (e.g., policy management and security due diligence questionnaires to support RFIs and RFPs).
- Actively participate in initiatives aimed at enhancing team processes and procedures.
- Help maintain and curate annual compliance training content and improve training process.
- Interpret control requirements and regulatory obligations accurately, and translate them into clear, testable expectations for technical teams.
- Participate in incident response reviews and RCAs by documenting control failures, corrective actions, and follow-up evidence for closure.
Qualifications
- B.S. degree (Information Security, Computer Science, MIS, or equivalent program preferred) from an accredited college/university or equivalent experience.
- Demonstrated experience supporting audits and compliance work across common frameworks (see framework list above), with demonstrated evidence collection, control testing, and remediation tracking.
- Relevant combined experience with implementing and/or assessing: IT audit, IT risk management, Cloud security and compliance, internal audit function, Information Technology General Controls (ITGC), Information security operations.
- Experience supporting government-related compliance efforts (e.g., FedRAMP- or DoD-aligned expectations) within cloud environments, including evidence packaging and stakeholder coordination.
Core Competencies
- Works independently, exercises good judgment, and seeks guidance as needed.
- Manages time effectively across multiple priorities and concurrent projects.
- Demonstrates strong analytical and critical-thinking skills with solid business and technical acumen.
- Collaborates effectively with diverse stakeholders, leveraging clear written & verbal communication.
- Thrives in a fast-paced, collaborative environment and contributes to shared outcomes.
- Follows directions from senior staff and supports peers to deliver high-quality, time-bound work.
- Continuously learns through structured, on-the-job, and self-directed development.
Preferences
- Hold (or be actively pursuing) relevant certifications such as CISA, CISSP, CCSK/CCAK, or major cloud security certifications (Azure/AWS/GCP), with active status preferred.
- Demonstrable FedRAMP, ISO and SOC Security Framework experience desired.
- Experience with effective AI usage, data analysis, report preparation, automation, and templating of repeat processes.
- ...scrutinize during procurement and something customers depend on to justify their trust. This role owns all of it. As our Senior GRC Analyst, you'll be the owner of Doppler's security and compliance program; maintaining our SOC 2 Type II and ISO 27001 certifications...SeniorRemote work
$130k - $160k
...Benepass | Candidate Resource Page Benepass Listed on Inc. Magazine's Best Workplaces of 2023 Team & Role As a Senior GRC Analyst at Benepass, you will help operate and mature the governance, risk, compliance, audit readiness, and customer assurance programs...SeniorWork at officeRemote workWork from homeFlexible hours- ...to its workforce, Kokosing is the winning team.Job Description:We are looking for a Security Governance, Risk, and Compliance (GRC) Analyst to support and mature our security and compliance programs across a large construction organization. This role focuses on maintaining...SeniorFor contractors
$140k - $165k
...while learning, having fun, and making a profound difference for the dreamers and builders in the world. We’re looking for a Senior GRC Analyst to serve as the primary architect for our expanding ISO ecosystem. As a Senior GRC Analyst at DigitalOcean, you will lead the...SeniorLocal areaWorldwideFlexible hours- ...Senior GRC Analyst Location: Atlanta, GA Need local with availibilty of onsite interview in required Type: 5-Month Contract (Possibility of Extension) GC/USC GRC frameworks (ISO 27001, NIST, GDPR, CMMC), risk assessment, compliance audits,...SeniorContract workLocal area
- ...Despite our growth and scale, we're still just getting started. That's where you come in. About the role We're hiring a Senior GRC Analyst to help scale Radar's security and compliance programs, with a focus on third-party risk and modern SaaS governance. You'...SeniorWork at officeRemote work
- ...Senior GRC Analyst Palo Alto, California Workato delivers enterprise infrastructure for the agentic era, redefining iPaaS and helping enterprises unify data, applications, processes, and AI into a single, governed platform. A leader in Enterprise MCP and trusted...SeniorRemote workFlexible hours
- ...The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third-Party & Human Risk Management (TPHRM) is a risk focused, highly analytical role that ensures all human and third‑party risk to Clayco is identified, quantified...SeniorImmediate startFlexible hours
- ...entertainment related building projects. The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk Register. This role is...SeniorFor contractorsImmediate startFlexible hours
$132k - $165k
...Senior GRC Analyst Remote Garner's mission is to transform the healthcare economy, delivering high-quality and affordable care for all. We are fundamentally reimagining how healthcare works in the U.S. by partnering with employers to redesign healthcare benefits...SeniorWork at officeRemote workFlexible hours$130k - $150k
...build with us at Crusoe. About This Role We're seeking a GRC Analyst to support the day-to-day execution of our Governance, Risk,... ...questionnaires and due diligence requests with guidance from senior team members Maintaining and updating audit and compliance...SeniorTemporary work$110k - $130k
...Senior GRC Analyst Blue J is the leading generative AI solution for tax professionals. As a B2B SaaS company, our customers are accountants and tax experts who rely on our market-leading software to deliver fast, accurate, and defensible answers to complex tax questions...SeniorWork at officeImmediate startRemote work$130k - $160k
...Alumni Ventures is seeking a Senior GRC Analyst to operate and mature governance, risk, compliance, and audit readiness programs. This role involves collaboration across departments to ensure effective compliance practices. Ideal candidates have 5+ years in GRC and experience...SeniorRemote workFlexible hours$161.6k - $202k
...— and that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program! You'll join the Security team and work across four pillars: security certifications (HITRUST...SeniorWork from homeFlexible hours- Forrester Research, based in Cambridge, MA, is seeking a Senior Analyst to deliver strategic advice and conduct research for risk management leaders. The ideal candidate will possess strong knowledge of risk practices, cyber risk quantification, and excellent communication...Senior
- Itlearn360 is seeking an experienced Third Party Governance, Risk and Compliance (GRC) Analyst in Los Angeles, CA. The ideal candidate should have at least three years of experience, preferably with Big 4 consulting or in regulated industries. This role involves executing...Senior
- A staffing agency based in Dallas, Texas is seeking a Senior Security Analyst to identify and mitigate security risks within the IT environment.... ...Information Security or IT and at least 3 years of experience in GRC/risk management. Competitive compensation and benefits...Senior
- Gilder Search Group is looking for a Sr. GRC Analyst focused on Third-Party & Human Risk Management in St. Louis, Missouri. The role ensures all human and third-party risks to Clayco are identified and treated appropriately. Key responsibilities include owning the TPRM...Senior
- A community-focused healthcare organization in California is seeking a Senior Analyst for IT Governance, Risk & Compliance. This role involves managing the Information Security GRC program, ensuring compliance with various regulations including HIPAA and PCI. Candidates...Senior
- PTR Global is seeking an experienced Information Security Analyst 4 for a contingent role based in Chandler, Arizona. This senior-level position emphasizes performing governance work related to data protection and enterprise risk management. Responsibilities include managing...SeniorContract work
- Crunchyroll is seeking an experienced Risk Analyst to support our Information Security GRC team. This role emphasizes governance, risk, and compliance, ensuring technology evolution aligns with employee needs and strategic goals. Successful candidates will have over 8 years...SeniorFlexible hours
- A leading fast food company in Columbus, OH, is seeking a Senior Analyst specializing in Governance, Risk & Compliance. This role involves collaborating across departments to develop and implement security measures, risk assessments, and compliance with regulations like...Senior
- Phase2 Technology is seeking a Senior Analyst to conduct research and provide strategic guidance for risk management leaders. The successful candidate will leverage their expertise in cyber risk quantification and risk management practices to deliver insights across multiple...Senior
- Gilder Search Group is looking for a Sr. GRC Analyst focusing on Third-Party & Human Risk Management in Atlanta, Georgia. This role involves risk analysis, compliance assessments, vendor management, and developing security awareness training. The ideal candidate has 6-8...Senior
- Sky Mavis is seeking a Senior GRC Analyst focused on Third-Party and Human Risk Management in St. Louis, Missouri. This role requires 6-8+ years of experience in Risk Assessment and Information Security, with strong analytical skills. You will lead the Vendor Risk Management...Senior
- Radar is hiring a Senior GRC Analyst in New York City to enhance security and compliance programs, focusing on third-party risk and SaaS governance. You will work with various teams to evaluate vendors, shape security strategies, and improve workflows, reporting to the...Senior
- Sky Mavis seeks a Sr. GRC Analyst in Phoenix, AZ, to manage Third-Party and Human Risk Management. This analytical role involves vendor risk assessment, security awareness training, and compliance evaluation, ensuring holistic risk management. Candidates should have significant...Senior
- Amynta Group in Fort Worth is seeking a Senior GRC Analyst to enhance its risk management and compliance program. This hybrid role requires an individual to assess information security risks and support audits across operations. The ideal candidate should possess a Bachelor...Senior
$119k - $193k
Phase2 Technology is seeking a Senior Analyst to conduct research and provide strategic advice to risk management leaders. The ideal candidate will possess a deep understanding of risk management trends, practices, and compliance management. This role involves producing...Senior- A global beverage solutions provider is seeking a Sr IT Governance Risk and Controls Analyst in Tampa, Florida. This role focuses on maintaining and improving the IT governance, risk, and compliance program, particularly in SOX compliance. Responsibilities include conducting...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
- grc analyst United States
- senior licensing manager United States
- senior cloud service delivery manager United States
- senior business analyst contract United States
- senior product design engineer United States
- senior game producer United States
- senior software manager United States
- senior creative strategist United States
- senior manager business analytics United States
- senior marketing account manager United States

