Company Summary As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America's Best Midsize Employers by Forbes, a Best Place to Work by Glassdoor, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. www.deltek.com
At Deltek, security isn't a gate at the end of the process - it's in the foundation. Enterprise Security & Technology Services (ESTS) brings together security, infrastructure, and technology operations under one organization, led by our CISO, with a mandate to make sure Deltek builds and operates with integrity at every layer. We're a passionate team of technologists and security professionals who work across the entire company - embedded in how services are built, delivered, and supported. We run agile, we embrace intelligent automation to amplify what our people can do, and we hold ourselves to a high standard because the organizations that depend on Deltek's platform are doing work that can't afford mistakes. If you take your craft seriously, want visibility into how a complex, global technology organization really operates, and believe security should be a first principle - not an afterthought - this is a team that will feel like home.
Business Summary Built on 40 years of industry expertise, Deltek is a leading provider of ERP solutions for Government contractors of all sizes. & whether these firms call them a contract within the government contracting space, an engagement within professional services firms or refer to them as a project within the AEC space, these organizations share the same ultimate goal-to win & deliver successful projects. Deltek offers complete & integrated software solutions that connect & automate every stage of the project lifecycle, enhancing project intelligence, management, & collaboration. With Deltek's industry-focused expertise & end-to-end visibility into project & financial performance, we empower businesses to make data-driven decisions, mitigate risks, & deliver projects on time & within budget.
Position Responsibilities Responsibilities: As a Senior GRC Analyst, you will support assessment, audit readiness, cloud security compliance, risk management, & security tooling across SaaS/cloud environments. You ensure controls are documented, measurable, continuously monitored, & aligned with applicable frameworks, laws, & regulations. This role supports customer trust by delivering clear evidence, accurate reporting, & well-managed remediation across Engineering, Product, & IT.
Priorities: (1) Audit readiness & evidence delivery, (2) Control documentation, continuous monitoring, & (3) Risk/PoA&M reporting, assigned deliverables end-to-end & coordinating inputs from Engineering, Product, & IT.
Audit & frameworks:
- Lead or support audits & assessments for cloud SaaS applications across frameworks such as SOC 1, SOC 2, NIST 800-53, NIST 800-171, CMMC, ISO, FedRAMP, PCI DSS, CIS, CSA CCM, & other security or regulatory standards/frameworks.
- Manage scoping, evidence requests, control testing, issue tracking, remediation follow-up, & final report support.
- Assess & communicate administrative, technical, & security controls across OCI, AWS, Azure, & related cloud services.
- Apply project management practices to plan, track, & deliver assessments, including use of Jira for epics, stories, backlog management, & stakeholder reporting.
- Use automation & AI responsibly to streamline evidence collection, control mapping, & recurring reporting, with appropriate human review.
Reporting & continuous improvement:
- Build & maintain GRC metrics & dashboards for reporting.
- Present trends, risks, remediation status, & control health to leadership.
- Draft & maintain security policies, standards, System Security Plans, control narratives, implementation details, & evidence references.
- Produce high-quality audit deliverables, including narratives, evidence packages, status reports, & remediation updates.
- Manage risk register items & PoA&Ms from identification through closure, including control gap analysis, remediation planning, owner coordination, & progress tracking.
- Translate control requirements & regulatory obligations into clear, testable expectations for technical teams.
Program ownership & documentation:
- Own or backup for key GRC programs by maintaining procedures, SLAs, & artifacts for audits & customer requests (e.g., policy management & security due diligence questionnaires to support RFIs & RFPs).
- Actively participate in initiatives aimed at enhancing team processes & procedures.
- Help maintain & curate annual compliance training content & improve training process.
- Interpret control requirements & regulatory obligations accurately, & translate them into clear, testable expectations for technical teams.
- Participate in incident response reviews & RCAs by documenting control failures, corrective actions, & follow-up evidence for closure.
Qualifications Technical Requirements: Independently lead audit workstreams, driving stakeholder follow-through, & owning evidence/control documentation through completion (years of experience are a guideline, but demonstrated scope & impact are key).
- B.S. degree (Information Security, Computer Science, MIS, or equivalent program preferred) from an accredited college/university.
- 3+ years supporting audits & compliance work across common frameworks (see framework list above), with demonstrated evidence collection, control testing, & remediation tracking.
- Minimum 3 years of combined experience with implementing and/or assessing: IT audit, IT risk management, Cloud security & compliance, internal audit function, Information Technology General Controls (ITGC), Information security operations.
- Experience supporting government-related compliance efforts (e.g., FedRAMP- or DoD-aligned expectations) within cloud environments, including evidence packaging & stakeholder coordination.
- Hold (or be actively pursuing) relevant certifications such as CISA, CISSP, CCSK/CCAK, or major cloud security certifications (Azure/AWS/GCP), with active status preferred.
Core Competencies
- Work independently, exercise good judgment & proactively seeks guidance as needed.
- Manage time effectively across multiple priorities & concurrent projects.
- Demonstrate strong analytical & critical-thinking skills with business & technical acumen.
- Communicate clearly in writing, verbally & collaborate effectively with diverse stakeholders.
- Thrives in a fast-paced, collaborative environment & contribute to shared outcomes.
- Follow directions from senior staff & supports peers to deliver high-quality, time-bound work.
- Continuously learn through structured, on-the-job, & self-directed development.
Preferences
- CCAK/CCSK, CISSP, CISA, or other related information security certification desired.
- Demonstrable FedRAMP, ISO & SOC Security Framework experience desired.
- Experience with effective AI usage, data analysis, report preparation, automation, & templating of repeat processes.
Career Interests Quality Control/Assurance
Compensation Info The U.S. salary range for this position is $76,000.00-$134,000.00. This range is subject to change as Deltek takes a number of factors into consideration when determining individual base pay, such as location, job-related knowledge, skills and experience. Certain roles are eligible for additional rewards, including incentive compensation and equity.
Benefits and perks listed here may vary depending on the nature of employment with Deltek. Employees have access to healthcare benefits, a 401(k) plan and company match, paid vacation time and holidays, well-living programs, short-term and long-term disability coverage, basic life insurance and tuition reimbursement.
Compliance Requirements Certain roles may have additional privacy, security and compliance requirements to the extent they support Costpoint GCCM or similar product offerings.
EEO Statement Deltek, Inc. is an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.
E-Verify Statement Deltek, Inc., utilizes the E-Verify program with every potential new hire. This makes it possible for us to make certain that every employee who works for Deltek is eligible to work in the United States. To learn more about E-Verify you can call 1-800-255-7688 or visit their website by clicking the logo below. E-Verify is a registered trademark of the United States Department of Homeland Security.
Applicant Privacy Notice Deltek is committed to the protection and promotion of your privacy. In connection with your application for employment with us at Deltek, it is necessary for us to collect, store and use information about you ("Personal Data") to administer and evaluate your application. We are the "controller" of the Personal Data you provide us and will process any such Personal Data in accordance with applicable law and the statements contained in this Candidate Privacy Notice Additionally, we have not sold and do not sell Personal Data you provide to us through the job application process.
Important: Protect Yourself from Recruitment Scams Bad actors or scammers may try to impersonate Deltek and send fake job offers to people. Messages from Deltek about employment opportunities will be from an @deltek.com account or Enterprise@trm.brassring.com, never from free services like Gmail or Yahoo. Please look carefully at the email address that provides any job offer, as some fake accounts are created to look like a legitimate domain name or email address. We will also never ask you to pay money at any point in the hiring process, whether for training, equipment, background checks, or anything else. If you receive a suspicious offer claiming to be from Deltek, do not share personal or financial information. Report any suspicious communication to Secure@deltek.com and consider reporting it to law enforcement.
|