Principal GRC Analyst

Communitech

United States

Remote

USD 19,000 - 25,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Deltek seeks a Principal GRC Analyst in India-Bangalore (Remote) to lead cloud SaaS audit programs, drive evidence readiness, and maintain regulatory alignment across SOC, NIST, ISO, FedRAMP and other standards.

You will own control documentation, narrative development, and PoA&M tracking, coordinating with Engineering, Product, and IT to ensure secure, compliant SaaS delivery.

Qualifications

  • Bachelor's degree in information security, computer science, MIS or equivalent program is preferred.
  • 3+ years supporting audits and compliance with common frameworks is required.
  • Experience with IT audit, IT risk management, cloud security and compliance.
  • Active certifications such as CISA, CISSP, CCSK/CCAK or cloud certs are desirable.

Responsibilities

  • Lead cloud SaaS audits across frameworks (SOC 1/2, NIST 800-53/171, ISO, FedRAMP, PCI DSS, CIS, CSA etc.).
  • Manage end-to-end audit engagements including scoping, evidence requests, testing, and reporting.
  • Prepare narratives, evidence packages, and SSPs; maintain control mappings and documentation.
  • Coordinate remediation with engineering, product, and IT; monitor PoA&M and risk registers.

Skills

Analytical thinking
Critical thinking
Project management
Communication

Education

B.S. degree in Information Security / Computer Science / MIS or equivalent

Tools

Jira
Oracle Cloud Infrastructure (OCI)
Amazon Web Services (AWS)
Microsoft Azure

Job description

05-Oct-2026


Principal GRC Analyst

India-Bangalore (Remote)


11285BR


Company Summary

As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America's Best Midsize Employers by Forbes, a Best Place to Work by Glassdoor, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. www.deltek.com


Business Summary

At Deltek, security isn't a gate at the end of the process — it's in the foundation. Enterprise Security & Technology Services (ESTS) brings together security, infrastructure, and technology operations under one organization, led by our CISO, with a mandate to make sure Deltek builds and operates with integrity at every layer.
We're a passionate team of technologists and security professionals who work across the entire company — embedded in how services are built, delivered, and supported. We run agile, we embrace intelligent automation to amplify what our people can do, and we hold ourselves to a high standard because the organizations that depend on Deltek's platform are doing work that can't afford mistakes. If you take your craft seriously, want visibility into how a complex, global technology organization really operates, and believe security should be a first principle — not an afterthought — this is a team that will feel like home.


Position Responsibilities

You will be part of the GRC team responsible for assessment, audits of cloud environments, information systems, risk management, and security tools to ensure adherence to applicable frameworks, laws, and regulations. As a Senior GRC Analyst, you will help maintain audit readiness and customer trust by ensuring our SaaS/cloud controls are well-documented, measurable, and aligned to applicable frameworks and regulatory expectations. Our goal is to help customers deliver successful projects with strong financial visibility, risk management, and on-time delivery—supported by secure, compliant products.
Priorities:(1) Audit readiness and evidence delivery,
(2) Control documentation, continuous monitoring, and
(3) Risk/PoA&M reporting, assigned deliverables end-to-end and coordinating inputs from Engineering, Product, and IT.
Core Role Requirements



  • As a senior analyst: lead cloud SaaS applications through various audit frameworks and assessments such as SOC 1, SOC 2, NIST 800-53, NIST 800-171, CMMC, ISO, FedRAMP, PCI DSS, CIS, CSA CSM, or other information security regulations.

  • Lead and/or support end-to-end audit engagements (internal and external), including scoping, evidence requests, control testing, issue tracking, and final report support.

  • Assess and communicate administrative, technical, and security controls across major cloud platforms, including Oracle Cloud Infrastructure (OCI), Amazon Web Services (AWS), and Microsoft Azure.

  • Demonstrate the ability to apply project management practices to plan, track, and deliver security assessments, including hands-on use of Jira for epics/stories, backlog grooming, and stakeholder reporting.

  • Use automation and AI responsibly to streamline evidence collection, control mapping, and recurring reporting while maintaining appropriate human review.


Reporting & continuous improvement

  • Define, build, and maintain recurring GRC metrics and dashboards (monthly/quarterly), and present trends, risks, and remediation status to senior leadership.

  • Draft, maintain, and socialize security policies/standards and System Security Plans (SSPs), including control narratives, implementation details, and evidence references.

  • Communicate clearly with engineering, product, and auditors, and produce high-quality audit deliverables (e.g., narratives, evidence packages, and status reporting).

  • Manage risk register items and PoA&M end-to-end—identify control gaps, partner with stakeholders on remediation plans, and track progress through continuous monitoring.


Program ownership & documentation

  • Own (or serve as backup owner for) key GRC programs by maintaining procedures, SLAs, and artifacts for audits and customer requests (e.g., policy management and security due diligence questionnaires to support RFIs and RFPs).

  • Actively participate in initiatives aimed at enhancing team processes and procedures.

  • Help maintain and curate annual compliance training content and improve training process.

  • Interpret control requirements and regulatory obligations accurately, and translate them into clear, testable expectations for technical teams.

  • Participate in incident response reviews and RCAs by documenting control failures, corrective actions, and follow-up evidence for closure.


Qualifications

Technical Requirements
Senior-level expectation includes independently leading audit workstreams, driving stakeholder follow-through, and owning evidence/control documentation through completion (years of experience are a guideline, but demonstrated scope and impact are key).



  • B.S. degree (Information Security, Computer Science, MIS, or equivalent program preferred) from an accredited college/university.

  • 3+ years supporting audits & compliance work across common frameworks (see framework list above), with demonstrated evidence collection, control testing, & remediation tracking.

  • Minimum 3 years of combined experience with implementing and/or assessing: IT audit, IT risk management, Cloud security & compliance, internal audit function, Information Technology General Controls (ITGC), Information security operations.

  • Experience supporting government-related compliance efforts (e.g., FedRAMP- or DoD-aligned expectations) within cloud environments, including evidence packaging & stakeholder coordination.

  • Hold (or be actively pursuing) relevant certifications such as CISA, CISSP, CCSK/CCAK, or major cloud security certifications (Azure/AWS/GCP), with active status preferred.


Core Competencies

  • Work independently, exercise good judgment & proactively seeks guidance as needed.

  • Manage time effectively across multiple priorities & concurrent projects.

  • Demonstrate strong analytical & critical-thinking skills with business & technical acumen.

  • Communicate clearly in writing, verbally & collaborate effectively with diverse stakeholders.

  • Thrives in a fast-paced, collaborative environment & contribute to shared outcomes.

  • Follow directions from senior staff & supports peers to deliver high-quality, time-bound work.

  • Continuously learn through structured, on-the-job, & self-directed development.


Preferences

  • CCAK/CCSK, CISSP, CISA, or other related information security certification desired.

  • Demonstrable FedRAMP, ISO & SOC Security Framework experience desired.

  • Experience with effective AI usage, data analysis, report preparation, automation, & templating of repeat processes.


Career Interests

Quality Control/Assurance


Position Type

FT


Travel Requirements

10%


Applicant Privacy Notice

Deltek is committed to the protection and promotion of your privacy. In connection with your application for employment with us at Deltek, it is necessary for us to collect, store and use information about you (“Personal Data”) to administer and evaluate your application. We are the “controller” of the Personal Data you provide us and will process any such Personal Data in accordance with applicable law and the statements contained in this
Candidate Privacy Notice
Additionally, we have not sold and do not sell Personal Data you provide to us through the job application process.
Important: Protect Yourself from Recruitment Scams
Bad actors or scammers may try to impersonate Deltek and send fake job offers to people. Messages from Deltek about employment opportunities will be from an @deltek.com account or Enterprise@trm.brassring.com, never from free services like Gmail or Yahoo. Please look carefully at the email address that provides any job offer, as some fake accounts are created to look like a legitimate domain name or email address. We will also never ask you to pay money at any point in the hiring process, whether for training, equipment, background checks, or anything else. If you receive a suspicious offer claiming to be from Deltek, do not share personal or financial information. Report any suspicious communication to Secure@deltek.com and consider reporting it to law enforcement.


Job Expires

05-Oct-2027

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Assoc Consultant
Assoc Consultant

Deltek, Inc. • Herndon (VA)

On-site
USD 53,000 - 71,000
Healthcare benefits
401(k) with company match
Paid vacation and holidays
+4
Sr Consultant
Sr Consultant

Deltek • United States

On-site
USD 72,000 - 127,000
Healthcare benefits
401(k) plan
Paid vacation
Sr Ops Analysts/Sys Admin
Sr Ops Analysts/Sys Admin

Deltek, Inc. • Herndon (VA)

Remote
USD 90,000 - 110,000
LTO Advisory Business Systems Analyst
LTO Advisory Business Systems Analyst

Deltek • United States

Remote
USD 125,000 - 220,000
Healthcare benefits
401(k) plan
Paid vacation
+3
Testing - Associate Support Services Analyst
Testing - Associate Support Services Analyst

Deltek • Chicago (IL)

On-site
USD 22,000 - 23,000
Healthcare benefits
401(k) plan with company match
Paid vacation and holidays
Senior Implementation Consultant
Senior Implementation Consultant

Deltek • United States

Remote
USD 72,000 - 127,000
Healthcare benefits
401(k) plan with company match
Paid vacation and holidays
System Architect I
System Architect I

Deltek, Inc. • United States

Remote
USD 125,000 - 220,000
Sr Consultant
Sr Consultant

Deltek, Inc. • Tampa (FL)

On-site
USD 72,000 - 127,000
Healthcare benefits
401(k) with company match
Paid vacation & holidays
+2
Sr Ops Analysts/Sys Admin
Sr Ops Analysts/Sys Admin

Deltek, Inc • United States

On-site
USD 90,000 - 110,000
Sales Enablement Specialist
Sales Enablement Specialist

Deltek, Inc. • Herndon (VA)

Remote
USD 54,000 - 95,000