> Markdown version of [/jobs/ext/2736602-sr-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2736602-sr-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr GRC Analyst - **Company:** Deltek, Inc - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $76,000.0 - $134,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Data Analysis, JIRA, Microsoft Azure, Software as a Service, Cloud Computing Security, Cyber Security, Issue Tracking Systems, Information Technology Audit, PCI Data Security Standards, Cloud Services, Cloud Platform System, IT General Controls (ITGC), Information Technology, Oracle Cloud Infrastructure, Plan of Action and Milestones - **Published:** September 5, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18207969?backUrl=%2Fcareer%2F18207969%2FSr-Grc-Analyst ## About the Role Independently lead audit workstreams, driving stakeholder follow-through, & owning evidence/control documentation through completion (years of experience are a guideline, but demonstrated scope & impact are key). * B.S. degree (Information Security, Computer Science, MIS, or equivalent program preferred) from an accredited college/university. * 3+ years supporting audits & compliance work across common frameworks (see framework list above), with demonstrated evidence collection, control testing, & remediation tracking. * Minimum 3 years of combined experience with implementing and/or assessing: IT audit, IT risk management, Cloud security & compliance, internal audit function, Information Technology General Controls (ITGC), Information security operations. * Experience supporting government-related compliance efforts (e.g., FedRAMP- or DoD-aligned expectations) within cloud environments, including evidence packaging & stakeholder coordination. * Hold (or be actively pursuing) relevant certifications such as CISA, CISSP, CCSK/CCAK, or major cloud security certifications (Azure/AWS/GCP), with active status preferred. Core Competencies * Work independently, exercise good judgment & proactively seeks guidance as needed. * Manage time effectively across multiple priorities & concurrent projects. * Demonstrate strong analytical & critical-thinking skills with business & technical acumen. * Communicate clearly in writing, verbally & collaborate effectively with diverse stakeholders. * Thrives in a fast-paced, collaborative environment & contribute to shared outcomes. * Follow directions from senior staff & supports peers to deliver high-quality, time-bound work. * Continuously learn through structured, on-the-job, & self-directed development. Preferences * CCAK/CCSK, CISSP, CISA, or other related information security certification desired. * Demonstrable FedRAMP, ISO & SOC Security Framework experience desired. * Experience with effective AI usage, data analysis, report preparation, automation, & templating of repeat processes. ## Description As a Senior GRC Analyst, you will support assessment, audit readiness, cloud security compliance, risk management, & security tooling across SaaS/cloud environments. You ensure controls are documented, measurable, continuously monitored, & aligned with applicable frameworks, laws, & regulations. This role supports customer trust by delivering clear evidence, accurate reporting, & well-managed remediation across Engineering, Product, & IT. Priorities: (1) Audit readiness & evidence delivery, (2) Control documentation, continuous monitoring, & (3) Risk/PoA&M reporting, assigned deliverables end-to-end & coordinating inputs from Engineering, Product, & IT. Audit & frameworks: * Lead or support audits & assessments for cloud SaaS applications across frameworks such as SOC 1, SOC 2, NIST 800-53, NIST 800-171, CMMC, ISO, FedRAMP, PCI DSS, CIS, CSA CCM, & other security or regulatory standards/frameworks. * Manage scoping, evidence requests, control testing, issue tracking, remediation follow-up, & final report support. * Assess & communicate administrative, technical, & security controls across OCI, AWS, Azure, & related cloud services. * Apply project management practices to plan, track, & deliver assessments, including use of Jira for epics, stories, backlog management, & stakeholder reporting. * Use automation & AI responsibly to streamline evidence collection, control mapping, & recurring reporting, with appropriate human review. Reporting & continuous improvement: * Build & maintain GRC metrics & dashboards for reporting. * Present trends, risks, remediation status, & control health to leadership. * Draft & maintain security policies, standards, System Security Plans, control narratives, implementation details, & evidence references. * Produce high-quality audit deliverables, including narratives, evidence packages, status reports, & remediation updates. * Manage risk register items & PoA&Ms from identification through closure, including control gap analysis, remediation planning, owner coordination, & progress tracking. * Translate control requirements & regulatory obligations into clear, testable expectations for technical teams. Program ownership & documentation: * Own or backup for key GRC programs by maintaining procedures, SLAs, & artifacts for audits & customer requests (e.g., policy management & security due diligence questionnaires to support RFIs & RFPs). * Actively participate in initiatives aimed at enhancing team processes & procedures. * Help maintain & curate annual compliance training content & improve training process. * Interpret control requirements & regulatory obligations accurately, & translate them into clear, testable expectations for technical teams. * Participate in incident response reviews & RCAs by documenting control failures, corrective actions, & follow-up evidence for closure. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)