Jobs and Careers
NE

Principal Cybersecurity Analyst

NextEra Energy
United Statesfull_timeVerifiedPosted 8 Aug 2024

About the role

Requisition ID:  81697 

Florida Power & Light Company is America’s largest electric company, providing clean, affordable, and reliable electricity to more than 12 million people in Florida. We operate one of the cleanest power generation fleets in the U.S. and our reliability is among the best in the nation. Our goal is to achieve Real Zero carbon emissions from our operations by 2045 by expanding our solar capacity, increasing battery storage and bringing new renewable energy opportunities to Florida, while improving customer affordability and reliability. Are you interested in becoming a game-changer in the energy industry?  Join our world-class team today! 

 

Position Specific Description

The Information Technology Nuclear Governance, Risk, and Compliance (ITN GRC) analyst is responsible for managing and ensuring the alignment of IT activities with the organization’s overall goals, regulatory requirements, and risk management strategies. The ITN GRC role involves a combination of governance, risk management, compliance, and data analytics activities to enhance the effectiveness and security of the organization’s IT systems. 

 

The NextEra Energy ITN GRC team has an important mandate to drive improved awareness and accountability across the nuclear fleet as it pertains to cybersecurity compliance and risk management. One of the methods to fulfill this mandate involves modernizing the way we perform internal control self-assessments. This is an opportunity to innovate at the intersection of cutting-edge disciplines including data analytics/modernization and cybersecurity risk management and established critical disciplines such as operational technology (OT). 

 

Special Considerations

  • Position is located at the Jupiter West facility with occasional travel to other facilities required. 
  • Position is hybrid, with a minimum of 3 days physically in the office required. 
  • Position requires ability to pass nuclear background check and maintain unescorted physical access.

 

Highly Preferred Qualifications

  • Six Sigma Green Belt and one or more cybersecurity certifications (e.g., CISA, CRISC, CISSP)
  • GIAC Critical Infrastructure Protection Certification (GCIP)
  • Global Industrial Cyber Security Professional Certification (GICSP)
  • GIAC Response and Industrial Defense (GRID)
  • Operational Technology (OT)/Industrial Control System (ICS) cybersecurity and/or engineering or similar expertise. 
  • Ability to function as a consultant to other IT groups on cybersecurity matters as a recognized expert and to lead cross-functional teams in making sound risk-based decisions. 
  • Working technical knowledge of cybersecurity, as well as industry trends.
  • Experience in developing cybersecurity policies and standards.
  • Knowledge of industry-standard risk/control frameworks.
     

Job Overview

This job performs ongoing cybersecurity risk reviews for new and existing technologies and services and supports ongoing and new cybersecurity projects.  Individuals develop requirements for and implement technical security projects and tools, as well as define the company’s cybersecurity policies and control framework.  This position collaborates with the company’s IT department and business units to identify the need for, select, and deploy technical controls to meet specific security requirements. Employees in this role build processes and standards to ensure security requirements continue to be met.

Job Duties & Responsibilities

  • Administers, operates and monitors NextEra Energy (NEE) information security sensors, logging, alerting and other detection mechanisms to identify and respond to threats
  • Acts as subject matter expert for one or multiple assigned cybersecurity technology stacks (e.g., identity and access management, network intrusion detection and prevention, host based security tools)
  • Collaborates with security architecture to identify, evaluate and recommend new security technologies for suitability within NEE’s environment and security posture
  • Communicates ongoing cybersecurity activities, priorities and risk measurements or mitigations at multiple organizational levels
  • Provides guidance for security activities and requirements in the system development life cycle (SDLC) and application development efforts. Participates in organizational projects, as required
  • Performs other job-related duties as assigned

Required Qualifications

  • High School Grad / GED

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

NextEra Energy

View company profile →