Jobs Companies Duke Energy Cybersecurity Governance & Risk Analyst or Sr. Cybersecurity Governance & Risk Analyst

À propos de ce poste Cybersecurity Governance & Risk Analyst or Sr. Cybersecurity Governance & Risk Analyst chez Duke Energy

Duke Energy · Sur site · Charlotte, NC

Important Application Submission Information

In order to ensure your application is successfully received before the job posting expires, please submit your application by 11:59 PM on Friday, September 18, 2026

More than a career - a chance to make a difference in people's lives.

Build an exciting, rewarding career with us – help us make a difference for millions of people every day. Consider joining the Duke Energy team, where you'll find a friendly work environment, opportunities for growth and development, recognition for your work, and competitive pay and benefits.

The Cybersecurity Governance & Risk Analyst is the second level of the classification hierarchy.  Employees at this level solve problems, in single areas of specialization, with general supervision.  Incumbents are expected to develop skills, and the ability to work with greater independence. They have knowledge of fundamental concepts and procedures. 

The Sr. Cybersecurity Governance & Risk Analyst will be expected to manage work in multiple governance and risk areas with minimal supervision. The individual will be expected to have the ability to plan, design, and implement a cybersecurity risk and governance program and to work independently, with limited guidance. The individual is expected to be fully competent in the use of cyber risk and governance concepts and procedures, and demonstrate critical thinking skills to identify problems, develop solutions, and take actions to resolve or improve. The individual must have the capability to lead efforts with other team members. The individual will have working knowledge of governance and cybersecurity risk.

Responsibilities

  • Demonstrates working knowledge of IT and Cybersecurity policy, standards, processes, controls and functional areas

  • Competent in the use of IT and Cybersecurity tools, procedures, and research capabilities

  • Monitor and evaluate the effectiveness of the enterprise's cybersecurity safeguards to ensure they provide the intended level of protection.

  • Perform or assist in security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in risk mitigation strategy.  

  • Perform or assist in cyber defense trend analysis and reporting

  • Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation

  • Assess or assist in the assessment in the effectiveness of security controls

  • Collaborate with Cybersecurity leadership and architects to make sure security technologies, processes, and people align with Duke’s strategic plan and budget.

  • Continually monitor and support security solutions including architecture and technologies and improve the architecture to meet performance and risk management objectives

  • Carries out individual work assignments of a less complex nature to meet established work schedules.

  • Receives work assignments and works with review and direction by management or senior analyst.

  • Performs or assists in the performance of technical project work as needed to complete project deliverables.

  • Basic knowledge of IT and Cybersecurity policy, standards, processes, resources and controls.

  • Able to apply process and controls knowledge to meet compliance requirements.

  • Provides good customer support to deliver compliance results to internal and external parties

  • Communicates with customers to understand compliance requirements

  • Communicates problems and resolutions to manager and/or customers

Basic/Required Qualifications for Cybersecurity Governance & Risk Analyst:

  • Bachelors degree in Cybersecurity or related degree

  • In addition to bachelor's degree, 2 years related experience

  • In lieu of bachelor's degree AND 2 years minimum of related work experience listed above, high school diploma/GED AND 6 years minimum of related work experience

Basic/Required Qualifications for Sr. Cybersecurity Governance & Risk Analyst:

  • Bachelor’s degree in Cybersecurity or related degree

  • Minimum 5 years Required of Related Work Experience.

  • In lieu of degree(s) listed above, High School/GED AND 9 years related work experience

Desired Qualifications

  • Experience in Cybersecurity, preferably with risk identification and management, audit and compliance, policy development and maintenance, evaluation of control requirements, security and related industry regulatory issues

  • Knowledge in validating the organization against policies/guidelines/procedures/regulations/laws to ensure compliance

  • Knowledge in reviewing service performance reports identifying any significant issues and variances, initiating, where necessary, corrective actions and ensuring that all outstanding issues are followed up

  • Ability to evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) into high quality, fused targeting/intelligence products.

  • Working knowledge of Cybersecurity frameworks such as NIST

  • Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).

  • Able to work effectively with defined direction

  • Demonstrated ability to work independently with supervisory review and direction

  • Excellent listening and communication skills; able to present information in an understandable manner both verbal and written  

  • Demonstrated ability to absorb change and continue with positive results

  • Skill in conducting audits or reviews of technical systems.

  • Skill in performing impact/risk assessments.

  • Skill in processing collected data for follow-on analysis.

  • Recognize a possible security violation and take appropriate action to report the incident as required

  • Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs)

  • Provide ongoing optimization and problem-solving support

  • Demonstrates good listening skills and puts forth the effort to understand others points of view. Has the ability to manage confidential information with a high degree of integrity. 

  • Responds well to supervisors, is easy to challenge and develop, and is easily coachable.  Able to work effectively with defined direction

  • Perform cyber defense trend analysis and reporting.

  • Skill in creating and utilizing mathematical or statistical models.

  • Research current technology to understand capabilities of required system or network.

  • Knowledge of information technology (IT) supply chain security and supply chain risk management policies, requirements, and procedures.

  • ServiceNow or similar asset management database experience

  • Experience creating dashboards in ServiceNow for compliance and cybersecurity monitoring/reporting

  • Knowledge of traditional gas-industry OT devices such as PLCs, RTUs, VFDs, electronic correctors, etc.

  • Direct experience with incident investigation and remediation

  • Demonstrated ability to develop complex processes with multiple stakeholders for isolating/securing OT environments as part of incident response activities

  • Experience tracking and remediating cybersecurity vulnerabilities in operational environments

Working Conditions

  • Hybrid mobility classification – Work will be performed from both remote and onsite locations after the onboarding period. However, hybrid employees must live within a reasonable commute to their designated Duke Energy facility, not greater than 50 miles one way. Employees are expected to report to their assigned Duke Energy facility as required and directed by their manager, on average 3 full workdays per regular work week.

Travel Requirements

5-15%

Relocation Assistance Provided (as applicable)

No

Represented/Union Position

No

Visa Sponsored Position

No. This is not a Visa Sponsored Position. This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future.


Please note that in order to be considered for this position, you must possess all of the basic/required qualifications.

Privacy

Do Not Sell My Personal Information (CA)

Terms of Use

Accessibility

Prêt à postuler chez Duke Energy ?
Postuler chez Duke Energy

À propos de Duke Energy

Terms of Use Brighter opportunities. Brighter futures. Duke Energy values ideas that come from a diverse and inclusive workforce, and we’re dedicated to providing a work environment where all people are valued, respected and able to reach their full potential. Duke Energy is an equal opportunity employer and does not discriminate against any employee or applicant for employment because of race, color, sex, pregnancy, childbirth or related medical conditions, including but not limited to lactation, religion, national origin, ancestry, ethnicity, citizenship, sexual orientation, gender identity, gender expression, age, marital status, physical or mental disability, genetic information, medical

Voir tous les emplois chez Duke Energy →

Emplois similaires

TB
Senior Audit Group Manager - Liquidity Risk
TD Bank
⚡ Postuler tôt New York, New York Sur site $123,880–$201,290
● Nouveau 👁 Vu ✓ Postulé il y a 23 h
Huntington Bank
Commercial Card Segment Risk Manager Sr
Huntington Bank
⚡ Postuler tôt Columbus, OH Sur site $93,000–$189,000
● Nouveau 👁 Vu ✓ Postulé il y a 1 j
Ares Management
Associate/Sr. Associate - Investment Risk Analyst, Ares Insurance Solutions (AIS)
Ares Management
⚡ Postuler tôt New York, NY Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 3 j
U.S. Bank
Business-Line Risk Manager - Corporate Treasury Asset Liability & Interest Rate Risk Management
U.S. Bank
⚡ Postuler tôt Minneapolis, MN Sur site $133,365–$156,900
● Nouveau 👁 Vu ✓ Postulé il y a 3 j
US
Quantitative Risk Analyst (Mid-level) - AML Modeling
USAA
⚡ Postuler tôt San Antonio Home Office I Hybride $93,770–$179,240
● Nouveau 👁 Vu ✓ Postulé il y a 6 j
U.S. Bank
Risk Manager - Digital
U.S. Bank
⚡ Postuler tôt Tempe, AZ Sur site $111,605–$131,300
● Nouveau 👁 Vu ✓ Postulé il y a 6 j
US
Mid-Level Real Estate Credit Risk Analyst
USAA
⚡ Postuler tôt San Antonio Home Office II/III Hybride $93,770–$179,240
● Nouveau 👁 Vu ✓ Postulé il y a 1 sem.
AIG
Risk Analyst ERM
AIG
⚡ Postuler tôt NY-New York Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 1 sem.
FO
Senior Analyst, Cyber Risk Quantification and GRC
Forrester
⚡ Postuler tôt Cambridge, MA Sur site $119,000–$193,000
● Nouveau 👁 Vu ✓ Postulé il y a 2 sem.

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez Duke Energy

Voir tous les emplois chez Duke Energy →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit