Company Summary
Deltek is the intelligent, industry‑tuned platform that powers the project lifecycle – from ERP and accounting to delivery and analysis. Trusted by 30,000 organizations, Deltek delivers speed, clarity, and control. The platform brings everything project‑based businesses need into one unified platform, built on the Deltek Native Architecture (DNA) – the secure engine for data, compliance, and control – connecting every stage of the project lifecycle seamlessly. Modular, cloud‑based, and powered by AI, Deltek helps teams work smarter, make faster decisions, and deliver with confidence. Every capability is shaped by deep industry knowledge and refined through decades of experience, ensuring governance, control, and insight across the lifecycle, enabling teams to win more pursuits, plan and forecast effectively, and deliver with real‑time visibility.
Position Responsibilities
You will be part of the GRC team responsible for assessment, audits of cloud environments, information systems, risk management, and security tools to ensure adherence to applicable frameworks, laws, and regulations. As a Senior GRC Analyst, you will help maintain audit readiness and customer trust by ensuring our SaaS/cloud controls are well‑documented, measurable, and aligned to applicable frameworks and regulatory expectations.
Priorities
- Audit readiness and evidence delivery
- Control documentation, continuous monitoring
- Risk/PoA&M reporting, assigned deliverables end‑to‑end and coordinating inputs from Engineering, Product, and IT
Core Role Requirements
- Lead cloud SaaS applications through audit frameworks such as SOC 1, SOC 2, NIST 800‑53, NIST 800‑171, CMMC, ISO, FedRAMP, PCI DSS, CIS, CSA CSM or similar.
- Lead or support end‑to‑end audit engagements (internal and external), including scoping, evidence requests, control testing, issue tracking, and final report support.
- Assess and communicate administrative, technical, and security controls across major cloud platforms including OCI, AWS, and Azure.
- Apply project management practices to plan, track, and deliver security assessments, using Jira for epics, stories, backlog grooming, and stakeholder reporting.
- Use automation and AI responsibly to streamline evidence collection, control mapping, and recurring reporting while maintaining appropriate human review.
Reporting & Continuous Improvement
- Define, build, and maintain recurring GRC metrics and dashboards (monthly/quarterly) and present trends, risks, and remediation status to senior leadership.
- Draft, maintain, and socialize security policies, standards, and System Security Plans including control narratives and evidence references.
- Communicate clearly with engineering, product, and auditors, and produce high‑quality audit deliverables.
- Manage risk register items and PoA&Ms end‑to‑end, identify control gaps, partner with stakeholders on remediation plans, and track progress through continuous monitoring.
Program Ownership & Documentation
- Own (or serve as backup owner for) key GRC programs by maintaining procedures, SLAs, and artifacts for audits and customer requests.
- Participate in initiatives aimed at enhancing team processes and procedures.
- Maintain and curate annual compliance training content and improve the training process.
- Interpret control requirements and regulatory obligations accurately and translate them into clear, testable expectations for technical teams.
- Participate in incident response reviews and RCAs, documenting control failures, corrective actions, and follow‑up evidence for closure.
Qualifications
- B.S. degree in Information Security, Computer Science, MIS, or equivalent (preferred).
- Experience supporting audits and compliance work across common frameworks with evidence collection, control testing, and remediation tracking.
- Relevant combined experience with IT audit, IT risk management, cloud security and compliance, internal audit function, ITGC, and information security operations.
- Experience supporting government‑related compliance efforts (e.g., FedRAMP or DoD) within cloud environments.
Core Competencies
- Works independently, exercises good judgment, and seeks guidance as needed.
- Manages time effectively across multiple priorities and concurrent projects.
- Demonstrates strong analytical and critical‑thinking skills with solid business and technical acumen.
- Collaborates effectively with diverse stakeholders, leveraging clear written and verbal communication.
- Thrives in a fast‑paced, collaborative environment and contributes to shared outcomes.
- Follows directions from senior staff and supports peers to deliver high‑quality, time‑bound work.
- Continuously learns through structured, on‑the‑job, and self‑directed development.
Preferences
- Current or pursuing certifications such as CISA, CISSP, CCSK/CCAK, or major cloud security certifications (Azure, AWS, GCP).
- Demonstrable FedRAMP, ISO, and SOC security framework experience.
- Experience with effective AI usage, data analysis, report preparation, automation, and templating repeat processes.
Position Type
Full Time
Travel Requirements
10%
Applicant Privacy Notice
Deltek is committed to the protection and promotion of your privacy. In connection with your application for employment with us at Deltek, it is necessary for us to collect, store and use information about you (“Personal Data”) to administer and evaluate your application. We are the “controller” of the Personal Data you provide us and will process any such Personal Data in accordance with applicable law and the statements contained in this Employment Candidate Privacy Notice. Additionally, we have not sold and do not sell Personal Data you provide to us through the job application process.