Information Security GRC Analyst
Poughkeepsie, United States
ā ļø We'll shut down after Aug 1st - try fooš¦ for all jobs in tech ā ļø
Full Time Mid-level / Intermediate USD 71K - 168K
Central Hudson
Resources and information for customers of Central Hudson Gas & ElectricBenefits:
Competitive compensation
Medical, dental, and vision insurance
401(k) retirement savings plan with substantial company match
Life and travel insurance
Tuition assistance
Wellness reimbursement program
Paid holidays and vacation
What is an Information Security GRC Analyst?
An Information Security GRC Analyst is a detail-oriented and proactive individual who supports the management of our information security governance, risk, and compliance programs. This role plays a critical part in maintaining regulatory alignment, reducing operational risk, and maturing our control environment. The ideal candidate is a systems thinker who can translate security frameworks into actionable, trackable work while collaborating across departments to improve organizational resilience.
What does an Information Security GRC Analyst do?
Supports the development, implementation, and maintenance of information security policies, standards, and procedures
Assists in maintaining and operationalizing the enterprise risk register, including control gap identification and remediation tracking
Facilitates risk assessments, control evaluations, and mitigation planning across business and technology functions
Monitors compliance with internal policies and external regulatory frameworks such as NIST 800-53, NIST CSF, ISO 27001, SOX, and NERC CIP
Supports third-party risk management processes, including vendor assessments, documentation collection, and due diligence reviews
Participates in audits, security assessments, and incident response activities as needed
Generates reports and dashboards that communicate risk posture, control effectiveness, and compliance metrics to stakeholders
Collaborates with IT, Legal, and Business teams to ensure alignment of information security practices with enterprise risk tolerance
Tracks change in regulations and assist with mapping compliance requirements to internal controls
Provides support for storm restoration efforts
What does it take to be an Information Security GRC Analyst?
Required:
Bachelorās degree in Cybersecurity, Information Systems, Business, or a related field and experience in cybersecurity, compliance, risk management or audit or an Associates degree in the aforementioned fields and at least 3+ years of cybersecurity, compliance, risk management or audit experience. In lieu of a degree, a high school diploma or equivalency and 5+ years of cybersecurity, compliance, risk management, or audit experience will be considered.
Familiarity with security frameworks and regulatory requirements (e.g., NIST, ISO, SOC 2, SOX, CIS Controls)
Strong analytical skills with the ability to assess complex systems and identify risk
Experience documenting processes, policies, or technical findings clearly and concisely
Ability to manage competing priorities and communicate effectively with technical and non-technical stakeholders
Valid driverās license
Preferred:
Experience with GRC tools (e.g., Archer, ServiceNow GRC, LogicGate, OneTrust)
Experience supporting third-party risk management or vendor security reviews
Industry experience in utilities, energy, or critical infrastructure
Certifications such as Security+, CGRC, CRISC, or GRCP
Applications will be accepted until August 12, 2025.Ā
This position has a career path which allows for advancement opportunities within a job series.Ā The title and level are commensurate with experience.
Pay range: $71,900 ā $168,700
Please go to https://www.cenhud.com/employment. Click the āSearch Career Opportunitiesā button. Follow the directions to submit an application and upload your resume for the desired position.
Applications sent via e-mail and US Mail will not be accepted.Ā No phone calls or agencies, please.Ā All replies will be held in strict confidence.
All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, creed, color, ethnicity, arrest or conviction record, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, citizenship, genetic information, familial status, marital status, pregnancy-related condition, domestic violence victim status, veteran or military status, or any other characteristic protected by federal, state or local laws. Central Hudson Gas & Electric Corporation takes affirmative action in support of its policy to employ and advance employment in individuals who are protected veterans and individuals with disabilities.
VEVRAA FEDERAL CONTRACTOR
Tags: Audits CGRC Compliance CRISC Driverās license Governance Incident response ISO 27001 NERC CIP NIST NIST 800-53 Risk assessment Risk management Security assessment SOC SOC 2 SOX
Perks/benefits: 401(k) matching Career development Competitive pay Gear Health care Insurance Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.