Senior GRC Analyst
Deltek
Senior GRC Analyst | Deltek, Inc
As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America's Best Midsize Employers by Forbes, a Best Place to Work by Glassdoor, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. At Deltek, security isn't a gate at the end of the process — it's in the foundation. Enterprise Security & Technology Services (ESTS) brings together security, infrastructure, and technology operations under one organization, led by our CISO, with a mandate to make sure Deltek builds and operates with integrity at every layer. We're a passionate team of technologists and security professionals who work across the entire company — embedded in how services are built, delivered, and supported. We run agile, we embrace intelligent automation to amplify what our people can do, and we hold ourselves to a high standard because the organizations that depend on Deltek's platform are doing work that can't afford mistakes. If you take your craft seriously, want visibility into how a complex, global technology organization really operates, and believe security should be a first principle — not an afterthought — this is a team that will feel like home.
Built on 40 years of industry expertise, Deltek is a leading provider of ERP solutions for Government contractors of all sizes. Whether these firms call them a contract within the government contracting space, an engagement within professional services firms or refer to them as a project within the AEC space, these organizations share the same ultimate goal—to win & deliver successful projects. Deltek offers complete & integrated software solutions that connect & automate every stage of the project lifecycle, enhancing project intelligence, management, & collaboration. With Deltek's industry-focused expertise & end-to-end visibility into project & financial performance, we empower businesses to make data-driven decisions, mitigate risks, & deliver projects on time & within budget.
Responsibilities: As a Senior GRC Analyst, you will support assessment, audit readiness, cloud security compliance, risk management, & security tooling across SaaS/cloud environments. You ensure controls are documented, measurable, continuously monitored, & aligned with applicable frameworks, laws, & regulations. This role supports customer trust by delivering clear evidence, accurate reporting, & well-managed remediation across Engineering, Product, & IT. Priorities : (1) Audit readiness & evidence delivery, (2) Control documentation, continuous monitoring, & (3) Risk/PoA&M reporting, assigned deliverables end-to-end & coordinating inputs from Engineering, Product, & IT. Audit & frameworks:
- Lead or support audits & assessments for cloud SaaS applications across frameworks such as SOC 1, SOC 2, NIST 800-53, NIST 800-171, CMMC, ISO, FedRAMP, PCI DSS, CIS, CSA CCM, & other security or regulatory standards/frameworks.
- Manage scoping, evidence requests, control testing, issue tracking, remediation follow-up, & final report support.
- Assess & communicate administrative, technical, & security controls across OCI, AWS, Azure, & related cloud services.
- Apply project management practices to plan, track, & deliver assessments, including use of Jira for epics, stories, backlog management, & stakeholder reporting.
- Use automation & AI responsibly to streamline evidence collection, control mapping, & recurring reporting, with appropriate human review.
Reporting & continuous improvement:
- Build & maintain GRC metrics & dashboards for reporting.
- Present trends, risks, remediation status, & control health to leadership.
- Draft & maintain security policies, standards, System Security Plans, control narratives, implementation details, & evidence references.
- Produce high-quality audit deliverables, including narratives, evidence packages, status reports, & remediation updates.
- Manage risk register items & PoA&Ms from identification through closure, including control gap analysis, remediation planning, owner coordination, & progress tracking.
- Translate control requirements & regulatory obligations into clear, testable expectations for technical teams.
Program ownership & documentation:
- Own or backup for key GRC programs by maintaining procedures, SLAs, & artifacts for audits & customer requests (e.g., policy management & security due diligence questionnaires to support RFIs & RFPs).
- Actively participate in initiatives aimed at enhancing team processes & procedures.
- Help maintain & curate annual compliance training content & improve training process.
- Interpret control requirements & regulatory obligations accurately, & translate them into clear, testable expectations for technical teams.
- Participate in incident response reviews & RCAs by documenting control failures, corrective actions, & follow-up evidence for closure.
Qualifications:
- B.S. degree (Information Security, Computer Science, MIS, or equivalent program preferred) from an accredited college/university.
- 3+ years supporting audits & compliance work across common frameworks (see framework list above), with demonstrated evidence collection, control testing, & remediation tracking.
- Minimum 3 years of combined experience with implementing and/or assessing : IT audit, IT risk management, Cloud security & compliance, internal audit function, Information Technology General Controls (ITGC), Information security operations.
- Experience supporting government-related compliance efforts (e.g., FedRAMP- or DoD-aligned expectations) within cloud environments, including evidence packaging & stakeholder coordination.
- Hold (or be actively pursuing) relevant certifications such as CISA, CISSP, CCSK/CCAK, or major cloud security certifications (Azure/AWS/GCP), with active status preferred.
Core Competencies:
- Work independently, exercise good judgment & proactively seeks guidance as needed.
- Manage time effectively across multiple priorities & concurrent projects.
- Demonstrate strong analytical & critical-thinking skills with business & technical acumen.
- Communicate clearly in writing, verbally & collaborate effectively with diverse stakeholders.
- Thrives in a fast-paced, collaborative environment & contribute to shared outcomes.
- Follow directions from senior staff & supports peers to deliver high-quality, time-bound work.
- Continuously learn through structured, on-the-job, & self-directed development.
Preferences:
- CCAK/CCSK, CISSP, CISA, or other related information security certification desired.
- Demonstrable FedRAMP, ISO & SOC Security Framework experience desired.
- Experience with effective AI usage, data analysis, report preparation, automation, & templating of repeat processes.
$130k - $170k
...extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks... ...organization.WHOOP is seeking an execution-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support the ongoing...SeniorFull timeWork at officeRelocation$80.05k - $165k
...end-to-end issue management activities, including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory...SeniorFull timeWork at office- ...leading risk assessments, vendor security reviews, and client-facing security discussions with professionalism and tact. Familiarity with GRC platforms, role-based access controls, and a broad range of security technologies and tools. Working knowledge of areas such as...Senior
$138k - $173k
THE POSITIONOur roster has an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers...SeniorTemporary workWork at officeLocal areaWorldwideShift work$183k - $205k
...security governance, risk and compliance initiatives. This person will guide the company from foundational Governance, Risk & Compliance (GRC) maturity through to steady-state operations, leveraging AI to automate and improve old practices and tools, ensuring ongoing...SeniorFull timeWork at officeLocal area2 days per week3 days per week- ...Owning and advancing the governance, risk, and compliance program, the full-time Senior GRC Analyst will manage compliance frameworks, conduct risk assessments, and collaborate with cross-functional teams in a remote capacity. Key Responsibilities: Lead the GRC program...SeniorFull timeRemote work
- ...including business leaders, technical personnel, audit personnel, senior management, and the board of directors Applies Cybersecurity... ...operational compliance metrics General Governance, Risk, and Compliance (GRC) Support Leads process analysis, development, & improvement...SeniorWork experience placementWork at officeLocal areaRemote workRelocation
- ...Sr. GRC Analyst, Risk Management Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk Register. This role is responsible for ensuring all identified...SeniorFor contractorsImmediate startFlexible hours
- ...The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third-Party & Human Risk Management (TPHRM) is a risk-focused, highly analytical role that ensures all Human and Third-Party risk to Clayco is identified, quantified...SeniorImmediate startFlexible hours
- Apply For This Job *indicates a required field FanDuelSenior
- ...; equivalent relevant experience may be considered.5+ years of progressive experience in cybersecurity governance, risk, compliance (GRC), IT audit, risk management, control assurance, or related disciplines.Experience assessing control design, operating effectiveness,...SeniorPermanent employmentFor contractors
- ...C2 Labs is hiring a Senior FedRAMP Consultant (GRC Analyst III equivalent) to act as a lead technical writer for FedRAMP authorization packages and ongoing ConMon operations. If you can translate real-world cloud security implementations into crisp FedRAMP documentation...SeniorFor contractorsRemote work
- Texas Health and Human Services Commission (HHSC) seeks a senior RSA Archer GRC Analyst in Austin. This onsite role requires working from an HHSC office and collaborates with executive leadership on security programs and Archer eGRC solutions. You will implement Archer...SeniorWork at office
- BERRY Appleman & Leiden (BAL) is seeking a GRC/Information Security professional to lead internal audits and manage ISO 27001/27701 programs from its Richardson, TX location. You’ll drive risk-based audits, support privacy operations, and help shape AI governance and vendor...Senior
- Request Technology, LLC is seeking an Information Security professional with a strong background in security frameworks and risk management to support client-facing security initiatives in a fast-paced environment. The role focuses on leading risk assessments, maintaining...Senior
- Gilder Search Group is looking for a Sr. GRC Analyst focused on Third-Party & Human Risk Management in St. Louis, Missouri. The role ensures all human and third-party risks to Clayco are identified and treated appropriately. Key responsibilities include owning the TPRM...Senior
- Crunchyroll is seeking an experienced Risk Analyst to support our Information Security GRC team. This role emphasizes governance, risk, and compliance, ensuring technology evolution aligns with employee needs and strategic goals. Successful candidates will have over 8 years...SeniorFlexible hours
- Texas Health and Human Services Commission (HHSC) seeks a Cybersecurity Analyst III to lead Archer eGRC development and administer security controls across agency systems. Based in Austin, this role involves collaboration with executives and teams to design, implement,...Senior
- Ellenco Estágios e Treinamentos is seeking a Senior Information Security GRC Analyst to manage security audits and compliance efforts. The role requires over 10 years of experience in information security and a strong understanding of NIST standards. This position allows...SeniorRemote job
- Berry Appleman & Leiden (BAL) is seeking an experienced GRC/Audit professional to help manage security, privacy, and AI governance across the firm. You will lead audits, shape ISMS/PIMS maintenance, and align controls with global standards. You will collaborate with cross...Senior
- Sky Mavis is seeking a Senior GRC Analyst focused on Third-Party and Human Risk Management in St. Louis, Missouri. This role requires 6-8+ years of experience in Risk Assessment and Information Security, with strong analytical skills. You will lead the Vendor Risk Management...Senior
- A global beverage solutions provider is seeking a Sr IT Governance Risk and Controls Analyst in Tampa, Florida. This role focuses on maintaining and improving the IT governance, risk, and compliance program, particularly in SOX compliance. Responsibilities include conducting...Senior
- A leading consulting firm is seeking a Senior Business Analyst specialized in ServiceNow GRC/IRM to enhance risk management processes. This contract role involves defining business requirements, translating them into functional specifications, and collaborating with the...SeniorContract work
- Gilder Search Group is looking for a Sr. GRC Analyst focusing on Third-Party & Human Risk Management in Atlanta, Georgia. This role involves risk analysis, compliance assessments, vendor management, and developing security awareness training. The ideal candidate has 6-8...Senior
- ...Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC... .... What You Will Do As an Experienced or Senior GRC Analyst at Hotman Group you will work directly with clients to help them...SeniorPermanent employmentFull timeContract workTemporary workRemote work
- Sky Mavis seeks a Sr. GRC Analyst in Phoenix, AZ, to manage Third-Party and Human Risk Management. This analytical role involves vendor risk assessment, security awareness training, and compliance evaluation, ensuring holistic risk management. Candidates should have significant...Senior
- Gilder Search Group is looking for a Sr. GRC Analyst to manage Third-Party & Human Risk while ensuring risks are identified and treated satisfactorily. The role requires 6-8 years in risk assessment, with a bachelor's degree and required certifications expected. You'll...SeniorFlexible hours
- Description The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader IT...SeniorWork at officeRemote work
- Job Description Insight Global is seeking a Senior Cybersecurity Governance Analyst to support their Cybersecurity Strategy & Governance team. This individual... ...5+ years of experience in Cybersecurity Governance, GRC, Cyber Risk, Security Compliance, or a related field...Senior
- ...We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program — maintaining our control framework, leading risk assessments, supporting...SeniorFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
- grc analyst United States
- senior technical analyst United States
- senior piping designer United States
- senior associate attorney United States
- senior developer United States
- senior bridge engineer United States
- sr industrial security specialist United States
- IT senior auditor United States
- senior aws cloud engineer United States
- senior manager business development United States


