CDW · 2 hours ago
SR GRC Consultant I
CDW is a leading multi-brand provider of information technology solutions. As a Sr. Government Compliance Analyst, you will support the Global Information Security organization in maintaining compliance with various government security requirements and contribute to audit readiness and risk reduction.
AnalyticsArtificial Intelligence (AI)Cyber SecurityGraphic DesignHardwareInformation TechnologySoftware
Responsibilities
Work with control owners to ensure timely execution and effectiveness of controls
Conduct interviews for security controls and collect objective evidence for compliance assessment
Develop and update Operational Plan of Action (OPA) to address gaps and compliance issues
Remediate findings, track progress, and reassess post-remediation
Draft, update, and finalize System Security Plan (SSP) for systems in scope and new systems under evaluation
Use the GRC platform to manage controls effectiveness status, documentation, and evidence
Update or create policies and procedures to support compliance
Develop detailed architecture and data flow diagrams for all in-scope systems
Review and document all connections (APIs, ports, protocols, services) for in-scope systems and physical locations
Identify and document all external and cloud service providers associated with in-scope environments
Review Government contracts and RFPs to identify obligations, assess feasibility, and ensure security requirements are met before commitment
Independently review and revise information security clauses in customer and vendor contractual agreements to ensure compliance with company policies
Perform other work as assigned to support overall Security Risk Management team objectives
Qualification
Required
Bachelor's degree with 5 years of experience in security risk management, audit, or compliance, or related roles, to include 2-year hands on experience with CMMC Level 2, NIST SP 800-171, or similar frameworks, OR
9 years of total Information Technology experience including 5 years of experience in security risk management, audit, compliance or related roles, to include 2-year hands on experience with CMMC Level 2, NIST SP 800-171, or similar frameworks
Experience with SSP, documentation and remediation activities, and compliance evidence gathering
Experience with architecture documentation and data flow diagrams
Understanding of APIs, ports, protocols, and system interconnections
Knowledge of cloud service provider compliance requirements
Strong analytical, documentation, critical thinking, and problem-solving skills
Strong attention to detail and ability to understand legal requirements in contracts
Ability to conduct interviews and communicate effectively with technical and non-technical stakeholders
Preferred
CCMC Certified Professional (CCP), CCA, CISSP, CISA or similar compliance/security certifications, a plus
Master's degree, a plus
Company
CDW
At CDW, we know how to make technology work so people can do great things.
Funding
Current Stage
Public CompanyTotal Funding
$58.74M2015-08-01Post Ipo Equity· $58.74M
2013-06-27IPO
2008-07-31Series Unknown
Recent News
Government Technology US
2026-01-16
2026-01-05
2025-12-24
Company data provided by crunchbase