8961BRCompany Summary:As the leading global provider of enterprise software and information solutions for project-based businesses, Deltek helps organizations of all sizes maximize productivity and revenue. Our market leadership stems from the work of our diverse employees who are united by a passion for learning, growing and making a difference. At Deltek, we take immense pride in creating a balanced, values-driven environment, where every employee feels included and empowered to do their best work. Our employees put our core values into action daily, creating a one-of-a-kind culture that has been recognized globally. Thanks to our incredible team, Deltek has been named one of America’s Best Midsize Employers by Forbes, a Top Workplace by The Washington Post and a Best Place to Work in Asia by World HRD Congress. www.deltek.comAuto req ID:8961BRExternal Job Title:Principal GRC Security AnalystPosition Responsibilities: Position Details: Information security risk management and compliance are critical parts of Deltek’s business and product strategy. The Principal Governance, Risk, & Compliance (GRC) Analyst is an Individual contributor (IC) role that reports to the Manager of GRC. This role is within the team responsible for implementing and maintaining compliance framework controls and assessing controls within multi-cloud environments. This role supports comprehensive assessments of the management, operational, and technical security controls deployed within Deltek cloud environments. Determines the effectiveness of the controls - the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements.
Responsibilities:
As a Pri ncipal GRC Analyst you will be part of the team responsible for assurance assessments of cloud environments, information systems, risk management and security tools to ensure adherence to applicable frameworks, laws, and regulations. You will assist with documenting control objectives and procedures in areas such as cloud security, cloud governance and compliance, DevOps, cloud data protection, cloud monitoring, incident response, enterprise security architecture, cyber security, and technology risk management. As part of a team of cloud security experts within GRC team you will drive compliance within Deltek.
Provide subject matter expertise related to NIST 800-171, CIS, CCM, FedRAMP, CMMC, ISO27001, PCI DSS, SOC 1, SOC 2, and other information security regulations.
Must have experience leading engagements as a principal assessor, understand requirements for completing internal assessments and external audit engagements.
Lead the gathering, reviewing, assembling, maintaining, and presenting of internal and external evidence and related documentation. Draft and maintain compliance documents such as policies, standards, procedures. Prepare metrics and reporting.
Effectively communicate with Deltek technical and business stakeholders through written and verbal communication during the process of evidence collection, validation, testing and presentation of results.
Maintain proficiency with applicable laws, regulations, and standards.
Identify and communicate risk management, control gaps and process inefficiencies to key stakeholders.
Actively participate in initiatives aimed at enhancing team processes and procedures.
Support internal risk and compliance meetings as a subject matter expert.
Draft and maintain, and mature GRC services as a primary or backup service owner (e.g., Policy Management, Risk Management, Customer Security Due Diligence, Business Continuity Planning, etc.)
Work Location:Philippines, Makati City Qualifications: Technical Requirements:
Minimum 3 years of combined experience implementing and/or assessing : Information technology audit , Information Technology General Controls (ITGC), Information security operations , cloud security and compliance, internal audit function, IT risk management, public accounting firm , or a related field.
B.S. degree (Information Security, Computer Science, MIS, or equivalent program preferred) from an accredited college/university.
Possess, or working toward, baseline security certifications such as CISA/CompTIA/cloud certification for Microsoft Azure/AWS/Google Cloud Platform or other security certifications.
Travel Requirements:10% Applicant Privacy Notice:Deltek is committed to the protection and promotion of your privacy. In connection with your application for employment with us at Deltek, it is necessary for us to collect, store and use information about you (“Personal Data”) to administer and evaluate your application. We are the “controller” of the Personal Data you provide us and will process any such Personal Data in accordance with applicable law and the statements contained in this Employment Candidate Privacy Notice (https://education.deltek.com/web/du_internal/Recruitment/Applicant Privacy Notice.pdf) . Additionally, we have not sold and do not sell Personal Data you provide to us through the job application process.Business Summary:Deltek's Global Information Security team has a passion for simplifying the delivery of information security in a complex industry. As part of our dynamic team, you will help deliver creative security services to continuously improve the first-rate protection of Deltek’s Information Assets. Join us as we create innovative solutions to further security as a differentiator for Deltek.