> Markdown version of [/jobs/ext/1405762-senior-grc-engineering-analyst](https://www.wearedevelopers.com/jobs/ext/1405762-senior-grc-engineering-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior GRC Engineering Analyst - **Company:** Deltek, Inc - **Location:** Herndon, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $76,000.0 - $134,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Information Systems, System Configuration, Continuous Integration, DevOps, Identity and Access Management, Issue Tracking Systems, Information Technology Audit, Key Management, Network Security, Network Segmentation, PCI Data Security Standards, Systems Development Life Cycle, Cloud Services, Screenshots, Security Information and Event Management, Software Engineering, Systems Architecture, Software Vulnerability Management, Data Logging, Google Cloud, Cloud Platform System, IT General Controls (ITGC), Software Security, Information Technology, RSA Archer Platform, CIS Benchmarks, Oracle Cloud Infrastructure, Plan of Action and Milestones - **Published:** July 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=35742d7c8b753140 ## About the Role * 3+ years of experience in GRC engineering, cloud security or compliance, IT audit/ITGC, Security Operations (SecOps), internal audit, IT risk management, or related fields, with hands-on experience implementing, validating, security tooling and assessing technical controls. * Bachelor's degree in information security, Computer Science, Informatics with Security, MIS, Engineering, or equivalent practical experience. * Experience assessing and validating controls in one or more major cloud platforms, including AWS, Azure, or OCI. Practical OCI experience is preferred. * Working knowledge of cloud security control areas such as IAM, logging and monitoring, encryption/key management, vulnerability management, network security, change management, secure SDLC, CI/CD, and infrastructure-as-code. * Experience partnering with engineering, security, cloud operations, or platform teams to collect evidence, validate control implementation, identify gaps, and support remediation. * Ability to review technical documentation, system configurations, screenshots, logs, tickets, diagrams, and other evidence to determine whether controls are operating effectively. * Familiarity with one or more security and compliance frameworks, such as NIST 800-53, FedRAMP, CMMC, ISO 27001, PCI DSS, SOC 1, or SOC 2. * Possess a security, audit, or cloud certification, such as CISA, CISSP, CCSK/CCAK, AWS, Azure, GCP, or OCI certification, or obtain one within 12 months. Candidates with relevant certification(s) already held are preferred. US Citizenship is required for this position. Core Competencies: * Excellent ability to: + Self-manage time and priorities while working with minimal direction and supervision. + Handle multiple competing priorities and projects. + Resolve business and technical roadblocks independently through structured problem-solving. + Think critically and apply strong analytical, written, verbal, and interpersonal communication skills. * Collaborate effectively in a team environment and take directions from senior-level staff. * Demonstrated initiative to learn through a combination of structured, on-the-job, and self-directed training., * OCI experience. * ITAR and/or Government Cloud assessment experience. * Hands-on experience with FedRAMP and/or NIST 800-171, plus familiarity with CSA CCM and CIS Benchmarks. * Experience supporting or assessing secure software development in cloud environments (e.g., CI/CD, infrastructure as code, containers). ## Description As a Senior GRC Engineering Analyst, you will ensure Deltek's cloud environments and information systems meet security and compliance obligations by testing technical controls, supporting audits, and maturing core GRC services. To support Deltek's flagship GovCon products, you will partner with Cloud Operations, Product Security, Platform Delivery, and Security Operations to translate requirements into test procedures, produce audit-ready artifacts, and drive remediation. * Lead audits and assessments with a key focus on engineering, technical control design, and control implementation aligned to frameworks/programs such as NIST 800-53 Rev. 5, FedRAMP, CMMC, ISO 27001, PCI DSS, SOC 1, and SOC 2. * Test, validate, and document cloud control implementations across AWS, Azure, and OCI, including IAM, network segmentation, encryption/key management, logging/monitoring, vulnerability management, container security, infrastructure-as-code, and CI/CD pipelines. * Partner with Security Engineering, Cloud Engineering, DevOps, IT, and Product teams to translate compliance requirements into scalable, automated, and auditable technical controls. * Own assessment execution end-to-end, including scope definition, technical walkthroughs, control testing, evidence validation, issue tracking, remediation follow-up, and reporting. * Design, maintain, and improve audit-ready artifacts, including control narratives, test procedures, evidence mappings, technical diagrams, implementation documentation, and control validation results. * Facilitate technical walkthroughs with stakeholders and auditors; clearly explain control intent, system architecture, implementation details, evidence sources, and test results. * Identify control gaps, assess technical risk and business impact, and drive remediation to closure with accountable engineering and control owners. * Support continuous compliance through control automation, recurring evidence collection, control health monitoring, and integration with tools such as cloud security platforms, ticketing systems, SIEM, vulnerability management tools, and GRC platforms. * Own or support key GRC services, including policy lifecycle, risk management, FedRAMP continuous monitoring, POA&M management, customer due diligence, security questionnaires, and audit readiness, with a focus on process improvement and automation. * Build compliance metrics and reporting, including dashboards, scorecards, executive summaries, control health indicators, remediation trends, and audit readiness reporting. * Develop or support automation scripts, queries, workflows, or integrations to streamline evidence collection, control testing, compliance monitoring, and reporting. * Evaluate cloud services, system changes, and new technical implementations for compliance impact and advise teams on control requirements early in the design and deployment lifecycle. * Maintain strong working knowledge of cloud security architecture, identity and access management, secure SDLC, infrastructure-as-code, logging/monitoring, vulnerability management, encryption, and change management practices. Success in the first 90 days looks like: You effectively support Cloud Operations, Product Security, Platform Delivery, and Security Operations by partnering with them to implement, validate, and improve the technical controls they own. You ensure control evidence, testing results, technical documentation, and supporting artifacts are complete, accurate, and audit-ready. ## Related Videos - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Let's get visual - Visual testing in your project](https://www.wearedevelopers.com/videos/303-let-s-get-visual-visual-testing-in-your-project) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)