Analyst Security GRC 1 (SAP)
CPS EnergyAbout the role
DEADLINE TO APPLY: January 11, 2024 at 11:59 p.m. CDT
We are engineers, high line workers, power plant managers, accountants, electricians, project coordinators, risk analysts, customer service operators, community representatives, safety and security specialists, communicators, human resources partners, information technology technicians and much, much more. We are 3,300 people committed to enhancing the lives of the communities we serve. Together, we are powering the growth and success of our community progress every day!
Pay Grade
GRADE: 11
DEADLINE TO APPLY: August 29, 2023
Position Summary
The position develops and/or maintains security roles for business applications, analytic systems, third-party systems and responsible for managing application risk. The position also develops and/or maintains cybersecurity-related processes, procedures and performs administrative tasks necessary to control several types of organizational risks, govern data security and access authorizations. The position must also monitor and interpret the various regulatory statutes and protocols as well as coordinate and implement new initiatives related to governance, risk and compliance for internal and external audits.
Tasks and Responsibilities
- Internal consultant for governance, risk, and compliance (GRC) activities
- Responsible for understanding, translating and communicating governance, risk, and compliance concepts, requirements and practices to stakeholders
- Assist in the development, implementation and maintenance of programs, processes, and procedures used to support governance, risk, and compliance efforts
- Collaborate with security staff, cross-functional teams and business owners to ensure appropriate role, authorization and access controls are in place that support security governance
- Utilize GRC tools to manage list of external authoritative sources, information technology controls, corporate policies and procedures, vendor management system, and risk management workflows
- Interpret various regulatory standards and requirements impacting CPS Energy and the security organization
- Perform cyber risk and vulnerability assessment to proactively secure the organization
- Perform IT Security Reviews
- Collaborate with various business units to understand, resolve or mitigate constraints impacting their operations and their risks associated with GRC controls
- Prepare internal and external audit evidence
- Maintain proficiency with applicable laws, regulations, and standards
- Performs other duties as assigned
Minimum Skills
Minimum Knowledge and Abilities
Basic knowledge of IT Systems, network protocols, network devices and operating systemsBasic knowledge of data governance and privacyBasic knowledge of compliance related activities (NERC, PCI, HIPAA)Skills with Microsoft Office suite, including word processing, spreadsheets, and presentation softwareAbility to diagnose and troubleshoot basic security issues (ex: security authorizations, account provisioning/deprovisioning, compliance issues)Ability to speak in public as a subject matter expertAbility to comprehend results from security assessment and analyze impacts of those assessmentsAbility to provide after hours and/or on-call system supportEffectively handle or support assignments and projects with limited complexity work is closely managed and occasionally under time constraintsBeginning experience or related experience will be considered as a substitute for degreePreferred Qualifications
-
Experience with SAP ERP to include:
o Security role development and/or maintenance
o User maintenance
o SDLC process experience
· Experience with SAP GRC (10.1 or higher) applications to include:
Understanding SoD principles
-
Experience mitigating organizational SoD risks (analyzing, interpreting, and recommendations)
· Advanced experience with MS Excel (pivot tables, vlookups, etc.)
· General knowledge of Audit and/or GRC practices.
· General knowledge of the Energy Sector (Gas and Electric)
Competencies
Demonstrating InitiativeCommunicates EffectivelyDriving for ResultsUsing Computers and TechnologyDelivering High Quality WorkLearning QuicklyMinimum Education
Bachelor’s Degree in Business Administration, Information Sys, Information Tech, Information Tech Security, Computer Science, Management Information Sys, Information Security; OR related field from an accredited university or equivalent work experience.Required Certifications
Working Environment
Work environment includes extensive indoor work, computer usage, manual dexterity, talking on the phone and in-person, hearing, and performing repetitive motions.Must have the ability to travel to and froApply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s