Senior GRC Analyst jobs in United States
cer-icon
Apply on Employer Site
company-logo

Delinea · 6 days ago

Senior GRC Analyst

Delinea is a pioneer in securing human and machine identities through intelligent, centralized authorization. The Senior GRC Analyst will play a key role in ensuring the company's alignment with cybersecurity policies and risk management frameworks across various environments, while driving compliance and continuous improvement initiatives.

Cloud SecurityComplianceCyber SecurityIdentity ManagementInformation TechnologyIT ManagementSecuritySoftware
badNo H1BnoteU.S. Citizen Onlynote

Responsibilities

Enforce cybersecurity Process Risk and Control frameworks that are rationalized against applicable laws and standards
Support FedRAMP Moderate and/or High authorization and ongoing compliance
Coordinate with 3PAOs, sponsoring agencies, and internal stakeholders during initial assessment
Assist in developing and maintaining FedRAMP-required documentation
Coordinate evidence collection for RAR, SAR, and continuous monitoring
Track security control implementation with engineering and IT teams
Maintain and update the POA&M and remediation timelines
Help manage ongoing FedRAMP continuous monitoring activities (e.g., monthly scans, annual assessments)
Perform cybersecurity risk assessments and maturity assessments
Conduct control readiness assessments to evaluate design, implementation, and effectiveness
Execute strategy for improving efficiency and ensuring organizational procedure alignment to maintain compliance with industry standards
Lead continuous control monitoring activities using GRC and compliance automation platforms
Function as a trusted advisor for business partners on the design and effective operation of controls

Qualification

FedRAMP requirementsNIST SP 800-53Cybersecurity risk assessmentsSystem Security Plans (SSPs)Cybersecurity certificationsAnalytical skillsPeople skillsGRC toolsJiraConfluenceCommunication skills

Required

Bachelor's degree in computer science, Information Technology, Business Administration, or a related field
7+ years of relevant work experience
Working knowledge of FedRAMP requirements, including: NIST SP 800-53 Rev. 5 or FedRAMP 20x security controls, FedRAMP Moderate or High Baseline, FedRAMP PMO processes (Readiness Assessment, 3PAO interactions, ATO phases)
Understanding of federal cybersecurity frameworks (NIST 800-37 RMF, FIPS 199/200, etc.)
Experience in creating or maintaining System Security Plans (SSPs), Policies, procedures, and SOPs, Control implementation statements, and POA&M (Plan of Action & Milestones)
Experience supporting SOC 1, SOC 2 and PCI-DSS audits for cloud based services
Strong verbal and written communication, analytical and people skills

Preferred

Familiarity with Common Criteria concepts, including Security Targets and evaluation artifacts
Familiarity with Cybersecurity Maturity Model Certification (CMMC)
Cybersecurity certifications (e.g. CISSP, CISA, CRISC, CIPP, etc.)
Familiarity with OneTrust or other GRC tools
Familiarity with Jira and Confluence

Benefits

Healthcare insurance
Pension/retirement matching
Comprehensive life insurance
Employee assistance program
Time off plans
Paid company holidays

Company

Delinea is a provider of privileged access management (PAM) solutions for seamless security

Funding

Current Stage
Late Stage
Total Funding
unknown
2021-03-02Private Equity
2021-03-02Acquired

Leadership Team

leader-logo
Art Gilliland
CEO
linkedin
leader-logo
Shawn Brady
Vice President Sales, Americas
linkedin
Company data provided by crunchbase