CDW Logo

CDW

Sr GRC Consultant I

Posted 2 Hours Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in US
88K-122K Annually
Senior level
Remote or Hybrid
Hiring Remotely in US
88K-122K Annually
Senior level
As a Sr. Government Compliance Analyst, you will support compliance with CMMC and NIST standards, focusing on audits, documentation, and remediation plans while ensuring CDW's security management effectiveness.
The summary above was generated by AI
Description
At CDW, we make it happen, together. Trust, connection, and commitment are at the heart of how we work together to deliver for our customers. It's why we're coworkers, not just employees. Coworkers who genuinely believe in supporting our customers and one another. We collectively forge our path forward with a level of commitment that speaks to who we are and where we're headed. We're proud to share our story and Make Amazing Happen at CDW.
Job Summary
As a Sr. Government Compliance Analyst, you will support CDW's Global Information Security organization in maintaining continuous compliance with Cybersecurity Maturity Model Certification (CMMC), NIST 800-171, and related government security requirements. You will perform detailed technical, documentation, and evidence-gathering activities to support assessments, audits, and system onboarding. This includes developing remediation plans, validating control execution, documenting system architectures and connections, reviewing contractual security requirements, and ensuring accurate compliance records in the GRC platform. Your work directly contributes to audit readiness, risk reduction, and the overall effectiveness of CDW's Security Risk Management program.
What you will do:
* Work with control owners to ensure timely execution and effectiveness of controls.
* Conduct interviews for security controls and collect objective evidence for compliance assessment.
* Develop and update Operational Plan of Action (OPA) to address gaps and compliance issues.
* Remediate findings, track progress, and reassess post-remediation.
* Draft, update, and finalize System Security Plan (SSP) for systems in scope and new systems under evaluation.
* Use the GRC platform to manage controls effectiveness status, documentation, and evidence.
* Update or create policies and procedures to support compliance.
* Develop detailed architecture and data flow diagrams for all in-scope systems.
* Review and document all connections (APIs, ports, protocols, services) for in-scope systems and physical locations.
* Identify and document all external and cloud service providers associated with in-scope environments.
* Review Government contracts and RFPs to identify obligations, assess feasibility, and ensure security requirements are met before commitment.
* Independently review and revise information security clauses in customer and vendor contractual agreements to ensure compliance with company policies.
* Perform other work as assigned to support overall Security Risk Management team objectives.
What we expect of you:
* Bachelor's degree with 5 years of experience in security risk management, audit, or compliance, or related roles, to include 2-year hands on experience with CMMC Level 2, NIST SP 800-171, or similar frameworks, OR
* 9 years of total Information Technology experience including 5 years of experience in security risk management, audit, compliance or related roles, to include 2-year hands on experience with CMMC Level 2, NIST SP 800-171, or similar frameworks.
* Experience with SSP, documentation and remediation activities, and compliance evidence gathering.
* Experience with architecture documentation and data flow diagrams.
* Understanding of APIs, ports, protocols, and system interconnections.
* Knowledge of cloud service provider compliance requirements.
* We value experience, skills, drive, aptitude, and attitude towards university degrees and certifications.
* Strong analytical, documentation, critical thinking, and problem-solving skills.
* Strong attention to detail and ability to understand legal requirements in contracts.
* Ability to conduct interviews and communicate effectively with technical and non-technical stakeholders.
* CCMC Certified Professional (CCP), CCA, CISSP, CISA or similar compliance/security certifications, a plus.
* Master's degree, a plus. This role requires access to Controlled Unclassified Information (CUI), as well as information subject to U.S. export-control laws such as the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). Under these laws and applicable data security requirements in CDW's U.S. government contracts, CDW must assess whether individuals in this role are legally permitted to access export-controlled technical data and certain categories of CUI. After CDW extends a conditional offer of employment, you will be asked to provide information and/or documentation needed to determine whether you are a "U.S. Person" as defined under ITAR (U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee) or otherwise eligible for authorized access under applicable federal regulations, including U.S. government contract requirements for restricted or export-controlled CUI and related personnel-screening obligations. Pay range: $88,000 - $122,400 depending on experience and skill set Annual bonus target of 5% subject to terms and conditions of plan Benefits overview: [https://cdw.benefit-info.com/](https://cdw.benefit-info.com/) Salary ranges may be subject to geographic differentials
* CDW is committed to being an AI-fluent organization
* We're looking for people who bring curiosity, a learner's mindset, and a willingness to engage with ever-evolving technology and tools. We value adopting AI as a partner, openness to experimentation, and a shared interest in learning together on AI. Our goal is to create a culture where AI enhances- not replaces- human creativity and decision-making. You don't need to be an expert today; what matters is your readiness to explore, adapt, and grow with us as we integrate AI responsibly and effectively into our work.Additionally, CDW is committed to fostering an equitable, transparent, and respectful hiring process for all applicants. During our application process, our goal is to understand your experience, strengths, skills, and qualifications. As an AI forward company, we see AI not just as a tool, but as a catalyst for new ways of thinking, creating, and communicating. We encourage candidates to embrace an AI mindset, one that's curious, adaptive, and ready to explore what's possible. We welcome thoughtful use of AI to expand your perspective and elevate how you share your story, while ensuring your application remains rooted in your own background, judgment, and voice.
* About Us
* CDW is a Fortune 500 technology solutions provider that helps businesses, government, education, and healthcare organizations achieve what's possible through technology. What makes CDW different isn't just what we do- it's how we do it. At CDW we act as one- building trust, speaking candidly, and working together to achieve more. We play to win- focusing on what matters most and delivering for our customers. And we think forward- staying curious, moving fast, and continuously learning. We believe meaningful work happens when people feel supported, heard, and empowered to contribute. That's why we think of ourselves as coworkers, not just employees- working together to solve complex challenges and deliver real impact for our customers and communities. As a full-stack, full-lifecycle technology partner, CDW brings deep expertise, strong relationships, and broad industry knowledge to help turn ideas into outcomes. When you join CDW, you become part of a collaborative environment where your work matters, your growth is supported, and your contributions help shape what's next. Together, we deliver the full promise of what technology can do.
* Together, we Make Amazing Happen.
* CDW is an equal opportunity employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status or any other basis prohibited by state and local law.

Top Skills

Cybersecurity Maturity Model Certification (Cmmc)
Grc Platform
Nist 800-171
System Security Plan (Ssp)

Similar Jobs at CDW

2 Hours Ago
Remote or Hybrid
US
121K-170K Annually
Senior level
121K-170K Annually
Senior level
Information Technology
The Digital Velocity ServiceNow Delivery Manager provides leadership for Advisory teams, collaborates with Sales, and drives effective operations for technology solutions delivery, ensuring client satisfaction and strategic alignment.
Top Skills: Ai ToolsServicenow
1K-1K Hourly
Senior level
Information Technology
Deliver technical training as a certified Fortinet Trainer, manage lab environments, and prepare students for certification exams while maintaining up-to-date knowledge of Fortinet solutions.
Top Skills: AWSAzureFortianalyzerForticlientFortigateFortimanagerFortinet Security FabricFortiosGCPSaseSd-WanZtna
2 Hours Ago
Remote or Hybrid
US
125K-193K Annually
Senior level
125K-193K Annually
Senior level
Information Technology
Lead project teams in service design and implementation, ensuring alignment with client needs and platform best practices. Manage relationships, oversee technical solutions, and provide architectural guidance while maintaining quality standards across projects.
Top Skills: Cloud Integration PatternsCsdmCsmItamItomItsmServicenow

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account