Pncpl GRC Analyst
Listed on 2026-06-19
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
Responsibilities
Information security risk management and compliance are critical parts of Deltek's business and product strategy. The Principal Governance, Risk, & Compliance (GRC) Analyst is an Individual contributor (IC) role that reports to the Manager of GRC. This role is within the team responsible for implementing and maintaining compliance framework controls and assessing controls within multi-cloud environments. This role supports comprehensive assessments of the management, operational, and technical security controls deployed within Deltek cloud environments.
Determines the effectiveness of the controls – the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements.
- Lead and execute audits and assessments related to NIST 800-53, FedRAMP, CMMC, ISO
27001, PCI DSS, SOC 1, SOC 2, and other information security regulations. - Must have experience leading audit engagements as a principal auditor, understand requirements for completing internal and external audit engagements.
- Lead the gathering, reviewing, assembling, maintaining, and presenting of internal and external audit evidence and related documentation.
- Create and maintain compliance documents such as policies, standards, procedures. Prepare metrics and reporting.
- Effectively communicate with Deltek technical and business stakeholders through written and verbal communication during the process of evidence collection, validation, testing and presentation of results.
- Maintain proficiency with applicable laws, regulations, and standards.
- Identify and communicate risk management, control gaps and process inefficiencies to key stakeholders.
- Actively participate in initiatives aimed at enhancing Cloud Security Compliance team processes and procedures.
- Support internal risk and compliance meetings as a subject matter expert.
- Draft and maintain, and mature GRC services as primary or backup service owner (e.g., Policy Management, Risk Management, Customer Security Due Diligence, Business Continuity Planning, etc.)
- Lead efforts and provide support for any activity that helps maintain Deltek's compliance and security standards.
- US Citizenship is required for this position.
- Minimum 3 years of leading implementing and/or assessing:
Information technology audit, Information Technology General Controls (ITGC), Information security operations, cloud security and compliance, internal audit function, IT risk management, public accounting firm, or a related field. - B.S. degree (Information Security, Computer Science, MIS, or equivalent program preferred) from an accredited college/university.
- Must have experience with ITAR/FedRAMP assessments within technological environments.
- Possess, or working toward, baseline security certifications such as CISA/CompTIA/cloud certification for Microsoft Azure/AWS/Google Cloud Platform.
- Excellent self-management and work with minimal direction.
- Excellent time management skills for handling multiple competing priorities and simultaneous projects.
- Excellent business and technical aptitude and problem-solving skills.
- Excellent critical thinking, analytical, communication (written and verbal) and interpersonal skills.
- Ability to work in a team environment collaboratively and take direction from senior level staff.
- Enthusiasm to learn through a combination of structured, on-the-job, and self-directed training.
- CCAK/CCSK, CISSP, CISA, or other related information security certification desired.
- FedRAMP, NIST 800-171, CSA CCM, CIS Security Framework experience desired.
- Experience with software development in a cloud environment desired.
Employees have access to healthcare benefits, a 401(k) plan and company match, paid vacation time and holidays, well‑living programs, short‑term and long‑term disability coverage, basic life insurance and tuition reimbursement.
Position TypeFT
Travel Requirements10%
Compliance RequirementsCertain roles may have additional privacy, security and compliance requirements to the extent they support Costpoint GCCM or similar product offerings.
EEO StatementDeltek, Inc. is an Equal Opportunity / Affithive Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.
E-Verify StatementDeltek, Inc., utilizes the E-Verify program with every potential new hire. This makes it possible for us to make certain that every employee who works for Deltek is eligible to work in the United States. To learn more about E-Verify you can call or visit their website by clicking the logo below. E-Verify is a registered trademark of the United States Department of Homeland Security.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).