Jobs and Careers
ES

GRC Security Analyst II

Essential Utilities, Inc.
Bryn Mawr, United Statesfull_timeVerifiedPosted 5 Jun 2026

About the role

Essential Utilities, Inc. delivers safe, clean, reliable services that improve quality of life for individuals, families, and entire communities.


Operating as the Aqua (water and wastewater services) and the Peoples and Delta (natural gas) brands, Essential serves approximately 5.5 million people across 10 states. We are committed to sustainable growth, operational excellence, a superior customer experience, and premier employer status - including a competitive and comprehensive benefits package as well as a commitment to career growth opportunities.


We are advocates for the communities we serve and are dedicated stewards of natural lands, protecting more than 7,600 acres of forests and other habitats throughout our footprint.


Our company is one of the most significant publicly traded water, wastewater service and natural gas providers in the U.S.

The primary responsibilities of the GRC Security Analyst II (Governance & Risk) are to ensure the security and integrity of the organization’s information systems, with a specific focus on risk & vulnerability management as well as security compliance. The Security Analyst will frequently engage with both technical teams and business process owners to analyze risk, communicate risk posture, and develop effective remediation strategies. Ready to take your career to the next level? Let’s talk!

Essential Duties:

  • Manage execution of both enterprise-wide and focused risk, threat, and vulnerability assessments, including but not limited to Security Awareness, Vulnerability, Configuration, and Third-Party Assessments.

  • Analyze and prioritize risk, vulnerability, and compliance findings to define remediation priorities considering all available data sources; partnering with technology and business stakeholders to socialize and implement remediation plans.

    Define and manage qualitative and quantitative metrics and reporting to measure the success of vulnerability, third party, security awareness, security awareness, configuration, and asset management remediations.

  • Ability to lead ongoing vulnerability management processes, including working with IT and business stakeholders to prepare vulnerability remediation plans, track progress, and reduce overall vulnerability exposures.

  • Participate in development, implementation and operation of control/compliance frameworks and security best practices based on ISO 27001/27002, NIST (800-30, Cyber Security Framework/CSF), COBIT, Critical Security Controls, CIS Configuration Benchmarks.

  • Monitor compliance with security configuration standards for servers, endpoints, software, and networking platforms based on CIS Benchmarks.

  • Work closely with IT, development, and operations teams to ensure the integration of security practices into the software development lifecycle (SDLC) and IT operations.

  • Lead or assist with vendor and 3rd party risk assessments.

  • Create/maintain documentation of security solutions, services, configurations, and processes.

  • Work closely with engineers focused on intrusion detection, incident response and security operations to manage risk related to existing and emerging threats. 

  • Collaborate with other security engineers to analyze, process, integrate, communicate, and respond to threat intelligence.

  • Ability to participate in or lead development, improvements and updates to continually improve security controls, policies, guidelines, processes and procedures.

  • Develop and deliver security awareness training programs for employees to enhance their understanding of security best practice to ensure that security and risk management continue to be integrated into the corporate culture. 

  • Lead development and operation of the security awareness program to ensure that security and risk management continue to be integrated into the corporate culture.

  • Implement and maintain controls for compliance and privacy.  Act as liaison to internal and external audit teams as needed.

  • Provide escalation support for the Information Technology Help Desk as required.

  • Ability to work off hours maintenance windows and participate in rotating on call shift periodically.

  • Ability to work alone or function effectively as part of a team.

  • All other duties as assigned by management.

MINIMUM QUALIFICATIONS:

Bachelors in Information

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Essential Utilities, Inc.

View company profile →