Cyber Security Analyst- GRC

Location: Newark, New Jersey US

Apply

Sign up to receive career updates before completing the application

Note: You will complete the application on the next page


Skip & Continue

Job Number: 1286

External Description: Requisition ID: 67417

Job Function/Category: Information Technology

Employment Type: Exempt Full Time

This is an exciting time to be joining PSEG. Our commitments, which include safety, integrity, customer focus, and diversity & inclusion, are the fabric of our culture and help drive the success of our business. We are fortunate to have an outstanding workforce of diverse and highly skilled talent who move us forward in our operational excellence journey. PSEG has more than 12,000 employees who are dedicated to the communities we serve and embody our vision: People providing Safe, Reliable, Economic and Greener Energy.

Job Summary

This position is an experienced level, hands-on technical lead, performing IT security functions and maintaining systems, while providing technical guidance to the team. The GRC analyst will be responsible for leading the day to day cyber compliance, data governance, and cyber risk management functions. The role will include responsibility for defining, creating, and managing cyber and organizational policies and standards in support of legal and regulatory compliance needs as well as general cyber and organizational information security practices.
The analyst will participate in the implementation of GRC software solutions. Collaborate with stakeholders, business analysts, process leaders, and architects in interpreting requirements and configuring them into software platform.

Please note this position is hybrid, comprised of remote and in office work. PSEG reserves the right to amend the hybrid model at any time.

Job Responsibilities

• Execute cybersecurity risk assessment and control attestation processes in GRC
• Participate in the development and implementation of the system-wide risk management function of the information security program to ensure cyber security risks are identified and monitored.
• Participate in the system-wide information security compliance program, ensuring cyber activities, processes, and procedures meet defined requirements, policies and regulations.
• Develop and implement effective and reasonable policies and practices to secure protected and sensitive data and ensure cyber security and compliance with relevant legislation and legal interpretation.
• Work with Internal and External Auditors as appropriate on required security assessments and audits
• Candidate should be able to provide GRC guidance and interpretation of rules, regulations, risks, and best practices.
• Ability to trouble shoot, identify, analyze and mitigate GRC related risks in existing processes, policies and procedures
• Review control effectiveness evidence to assess the quality and effectiveness of the implemented controls
• Work with development teams to provide appropriate and effective remediation guidance for vulnerabilities discovered during various assessments
• Document residual risk
• Prepare and communicate operational metrics and trend analysis for the Cybersecurity Leadership Team

Job Specific Qualifications

Required:
• Bachelor's degree in Computer Science, Information Systems, Cyber Security, Engineering, or related discipline (i.e. STEM) and minimum of 4 years of experience in Information Security.
• In lieu of a degree, minimum of 8 years of experience in information security role.
• Knowledge of information security risk management frameworks and compliance practices.
• Knowledge of securing network technologies, client, and server operating systems.
• Ability to develop security standards and guidelines based on best practices and industry standards
• Excellent oral and written communication skills.
• Excellent technical teamwork, and interpersonal skills.
• Willing to work in strong team environment, constantly teaching and learning from other team members.
• Ability to foster working relationships with the team, IT Management and Client departments.
• Ability to explain technical concepts to the business users in the context of business requirements.
• Technical experience includes: information / data / network / computer security design, administration and/or assessment.
• Broad knowledge of information systems including Windows security, network security, systems development, communication networks, security software/hardware and operating systems.
• Ability to plan and organize, results orientation, technical/professional knowledge.

Desired:
• Experience in Operational Technology (OT) Security is a plus
• ISC2 Certified Information Systems Security Professional (CISSP) or equivalent
• Programming Experience in Python

Minimum Years of Experience

4 years of experience

Disclaimer

Certain positions at the Company may require you to have access to Part 810-Controlled Information. Under the law, the Company is limited in who it can share this information with and in certain circumstances it is necessary to obtain specific authorization before the Company can share this information. Accordingly, if the position does require access to this information, you must complete a 10 CFR Part 810 Export Control Compliance Nationality Request Form, a copy of which will be provided to you by Talent Acquisition if an offer is made. If there is a need for specific authorization, due to the time it takes to obtain authorization from the government, we will likely not be able to further proceed with an offer.

As an employee of PSE&G or PSEG Long Island, you should be aware that during storm restoration efforts, you may be required to perform functions outside of your routine duties and on a schedule that may be different from normal operations.

This site ( http://www.pseg.com ) is strictly for candidates who are not currently PSEG employees. PSEG employees must apply for jobs internally through empower which can be accessed through the mypseg homepage by clicking on the employee center tab, then under the empower header, choose careers.

Business needs may cause PSEG to cancel or delay filling position at any time during the selection process.

Certain positions at the Company may require you to have access to Part 810-Controlled Information. Under the law, the Company is limited in who it can share this information with and in certain circumstances it is necessary to obtain specific authorization before the Company can share this information. Accordingly, if the position does require access to this information, you must complete a 10 CFR Part 810 Export Control Compliance Nationality Request Form, a copy of which will be provided to you by Talent Acquisition if an offer is made. If there is a need for specific authorization, due to the time it takes to obtain authorization from the government, we will likely not be able to further proceed with an offer.

Public Service Enterprise Group (PSEG) is an equal opportunity employer, dedicated to a policy of non-discrimination in employment, including the hiring process, based on any legal protected characteristic. Legally protected characteristics included, race, color, religion, national origin, sex, age, marital status, sexual orientation, disability, or veteran status or any other characteristic protected by federal, state, or local law in locations where PSEG employs individuals.

Need to request an accommodation?

If you have a disability and need assistance submitting your resume, applying for a position or registering for a test, please call 973-430-3845. Any information provided regarding a disability will be kept strictly confidential and will not be shared with anyone involved in making a hiring decision.

Nearest Major Market: Newark
Nearest Secondary Market: New York City
Job Segment: Engineer, Law, Risk Management, Information Systems, Computer Science, Engineering, Legal, Finance, Technology

Job Number: 67417

Community / Marketing Title: Cyber Security Analyst- GRC

Location_formattedLocationLong: Newark, New Jersey US

 

CONNECT WITH US