Jobs and Careers
CO
Technical Specialist-Information Security Governance, Risk & Compliance
Con EdisonNew York City, United Statesfull_timeVerifiedPosted 18 Feb 2026
About the role
Come join us as a Technical Specialist where you will play a key role in strengthening our Information Security (InfoSec) Governance, Risk & Compliance (GRC) capabilities across the enterprise. In this experienced individual contributor role, you will develop, maintain, and execute the frameworks, policies, standards, and processes used to identify, assess, manage, and report information security risk. You will ensure our security practices align with regulatory requirements, industry standards, and business objectives through hands-on analysis, thorough documentation, and disciplined execution. Success in this role requires a highly self-directed professional who can operate with minimal supervision, demonstrates exceptional organizational skills and attention to detail, and consistently delivers high-quality, actionable outcomes. If you are passionate about driving strong security governance and making a measurable impact on enterprise risk, we strongly encourage you to apply and help shape the future of our security program.
Core Responsibilities
- Contribute to information security policies and governance frameworks aligned with national energy security priorities in compliance with regulatory requirements and industry standards.
- Collaborate with internal stakeholders (IT, OT, Legal, Risk, Operations) and external partners (regulators, government agencies, industry groups).
- Facilitate incident response planning, exercises, and post-incident reviews to strengthen organizational readiness.
- Support incident response planning and champions a culture of cyber accountability and resilience across the organization.
- Support internal and external audits while driving continuous improvement of GRC maturity.
- Provide executive-level reporting on cybersecurity posture, compliance status, and resilience metrics.
- Serve as a key liaison between InfoSec, IT, Audit, Legal, peers in InfoSec Compliance, and business stakeholders to ensure security risks are clearly communicated and appropriately governed.
- Support internal and regulatory compliance efforts, including NERC CIP, TSA, Coast Guard, and other applicable federal and state mandates.
- Facilitate and maintain cyber resilience strategies to ensure continuity of operations during and after cyber incidents.
- Master's Degree and 6 years of work experience in IT or Utility environments with at least four (4) years in GRC or similar or
- Bachelor's Degree and 8 years of work experience in IT or Utility environments with at least four (4) years in GRC or similar
- Master's Degree preferably in Information Technology, Computer Science, Information Security, Math, Engineering or business-related discipline.
- Bachelor's Degree preferably in Information Technology, Computer Science, Information Security, Math, Engineering or business-related discipline.
- Must demonstrate knowledge of project management concepts and ability to support project monitoring, tracking, and facilitation to ensure project deliverance/completion, required.
- Proven experience of process and policy creation and documentation, required.
- Must demonstrate strong analytical skills, required.
- Must demonstrate strong oral and written communication, presentation and interpersonal skills, required.
- Must have used, and have working knowledge of MS Excel, Word and PowerPoint, required.
- Experience and working knowledge of GRC concepts, required.
- Experience developing and delivering well organized analytical presentations, preferred.
- Demonstrates a high commitment to quality
- Assumes personal responsibility for actions
- Strong verbal communication and listening skills
- Possesses flexibility to work in a fast paced, dynamic environment
- Effective interpersonal skills
- Demonstrated analytical skills
- Ability to simultaneously handle multiple priorities
- Must be proficient in Microsoft Office including Word, Excel, Outlook and PowerPoint, etc.
- Effective interpersonal skills
- Driver's License Required
- Ability to push, pull, and lift up to 25 pounds
- Sit or stand to use a keyboard, mouse, and computer for the duration of the workday
- The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.
Mission Statement:
Consolidated Edison Company of New York
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s