Jobs and Careers
TA

Analyst-Cyber GRC, Sr.

Tallgrass
United Statesfull_timeVerifiedPosted 3 Aug 2026
💰 TRY 158,200/yr(TRY 105,400/yrTRY 158,200/yr)

About the role

Primary purpose:

  • The Information Technology Governance, Risk, and Compliance (GRC) team supports Tallgrass’s cybersecurity risk and compliance program across the enterprise. This includes cyber risk management, policy and standards governance, third-party risk management, contractual cybersecurity review, compliance monitoring, control assessments, security awareness, and audit readiness.

  • The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy’s cybersecurity posture by assessing risk, evaluating controls, supporting compliance obligations, and recommending practical safeguards to reduce risk. This role serves as a key advisor to business and technology stakeholders and helps ensure cybersecurity requirements are understood, documented, and implemented effectively.

  • This position also serves as the security function’s primary reviewer of incoming contractual cybersecurity language and works closely with Legal, Supply Chain/Sourcing, IT, Security Operations, Engineering, and business stakeholders on contract reviews, obligation mapping, risk assessments, issue management, and control governance.

Essential Duties & Responsibilities:

 

Governance, Risk, and Compliance:

  • Support the execution and continuous improvement of the cybersecurity GRC program, including governance, risk assessment, compliance monitoring, control evaluation, and issue management activities.
  • Assist with the development, maintenance, communication, and governance of cybersecurity policies, standards, procedures, control requirements, ownership expectations, evidence requirements, and exception processes
  • Clarify control owner accountability by helping define control ownership, evidence expectations, remediation obligations, and reporting requirements.
  • Conduct or support cybersecurity risk assessments, control evaluations, compliance assessments, and audit readiness activities.
  • Track risks, findings, exceptions, remediation plans, risk acceptances, and closure evidence through completion.
  • Develop compliance matrices, control mappings, gap analyses, risk summaries, and management-level reporting/dashboards.

Regulatory Compliance and Audit Support:

  • Support compliance efforts related to applicable cybersecurity and regulatory requirements, including TSA Security Directives, privacy requirements, and NERC CIP, where applicable.
  • Monitor relevant regulatory and industry developments and assist with interpreting, coordinating, and tracking required actions.Support internal and external audits, regulatory reviews, compliance assessments, customer security inquiries, and evidence-gathering activities.
  • Partner with control owners to collect, validate, and maintain evidence of control design and operating effectiveness.
  • Track open compliance and audit findings, prepare status updates, and escalate aging or high-risk items as appropriate.

Contractual Cybersecurity Review:

  • Serve as the security function’s primary reviewer of incoming contractual cybersecurity language, including customer, vendor, supplier, and third-party agreements.

  • Partner with Legal, Supply Chain/Sourcing, business stakeholders, and technology teams to review cybersecurity, privacy, compliance, and risk-related contract provisions.

  • Provide recommended redlines and risk-based guidance for contract requirements related to data protection, access control, incident notification, audit rights, regulatory compliance, business continuity, disaster recovery, subcontractor flow-downs, vulnerability management, and security assessments.

  • Assess proposed contractual requirements against Tallgrass cybersecurity policies, standards, technical capabilities, regulatory obligations, and existing controls.

  • Map contractual obligations to applicable frameworks, regulatory requirements, internal policies, standards, and controls.

  • Identify contractual cybersecurity gaps, operational risks, and potential control deficiencies; recommend mitigation options and track related actions through completion.

Third-Party Risk Management:

  • Support the cybersecurity third-party risk management program for vendors, service providers, contractors, and other third parties that access Tallgrass systems, data, facilities, or networks.

  • Review vendor security questionnaires, SOC reports, certifications, penetration test summaries, policies, and other due diligence documentation.

  • Assess third-party security controls against company policies, standards, regulatory requirements, contractual obligations, and industry best practices.

  • Partner with Legal, Pro

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Tallgrass

View company profile →