SR GRC Consultant I jobs in United States
cer-icon
Apply on Employer Site
company-logo

CDW · 2 hours ago

SR GRC Consultant I

CDW is a leading multi-brand provider of information technology solutions. As a Sr. Government Compliance Analyst, you will support the Global Information Security organization in maintaining compliance with various government security requirements and contribute to audit readiness and risk reduction.

AnalyticsArtificial Intelligence (AI)Cyber SecurityGraphic DesignHardwareInformation TechnologySoftware
badNo H1BnoteU.S. Citizen Onlynote

Responsibilities

Work with control owners to ensure timely execution and effectiveness of controls
Conduct interviews for security controls and collect objective evidence for compliance assessment
Develop and update Operational Plan of Action (OPA) to address gaps and compliance issues
Remediate findings, track progress, and reassess post-remediation
Draft, update, and finalize System Security Plan (SSP) for systems in scope and new systems under evaluation
Use the GRC platform to manage controls effectiveness status, documentation, and evidence
Update or create policies and procedures to support compliance
Develop detailed architecture and data flow diagrams for all in-scope systems
Review and document all connections (APIs, ports, protocols, services) for in-scope systems and physical locations
Identify and document all external and cloud service providers associated with in-scope environments
Review Government contracts and RFPs to identify obligations, assess feasibility, and ensure security requirements are met before commitment
Independently review and revise information security clauses in customer and vendor contractual agreements to ensure compliance with company policies
Perform other work as assigned to support overall Security Risk Management team objectives

Qualification

CMMC Level 2NIST SP 800-171Security Risk ManagementSSP DocumentationArchitecture DocumentationCloud Compliance KnowledgeAnalytical SkillsCompliance CertificationsCritical ThinkingProblem-Solving SkillsAttention to DetailEffective Communication

Required

Bachelor's degree with 5 years of experience in security risk management, audit, or compliance, or related roles, to include 2-year hands on experience with CMMC Level 2, NIST SP 800-171, or similar frameworks, OR
9 years of total Information Technology experience including 5 years of experience in security risk management, audit, compliance or related roles, to include 2-year hands on experience with CMMC Level 2, NIST SP 800-171, or similar frameworks
Experience with SSP, documentation and remediation activities, and compliance evidence gathering
Experience with architecture documentation and data flow diagrams
Understanding of APIs, ports, protocols, and system interconnections
Knowledge of cloud service provider compliance requirements
Strong analytical, documentation, critical thinking, and problem-solving skills
Strong attention to detail and ability to understand legal requirements in contracts
Ability to conduct interviews and communicate effectively with technical and non-technical stakeholders

Preferred

CCMC Certified Professional (CCP), CCA, CISSP, CISA or similar compliance/security certifications, a plus
Master's degree, a plus

Company

At CDW, we know how to make technology work so people can do great things.

Funding

Current Stage
Public Company
Total Funding
$58.74M
2015-08-01Post Ipo Equity· $58.74M
2013-06-27IPO
2008-07-31Series Unknown

Leadership Team

leader-logo
Christine Leahy
President & CEO
linkedin
leader-logo
Sanjay Sood
Chief Technology Officer
linkedin
Company data provided by crunchbase