Jobs and Careers
EN

Security Risk Analyst

Entergy
The Woodlands, United Statesfull_timeVerifiedPosted 14 Jan 2025

About the role

Work Place Flexibility: Hybrid 

Legal Entity: Entergy Services, LLC 

The preferred location is The Woodlands, TX but Jackson, MS, New Orleans, LA and Little Rock. AR may be considered. Relocation assitance and sponsorship is not provided.

JOB SUMMARY/PURPOSE

  • The Security Risk Analyst is responsible for assisting with the implementation and monitoring of Entergy’s vendor security risk management processes within the Chief Security Office (CSO). 
  • The Security Risk Analyst will conduct thorough risk assessments of vendors and third-party service providers to evaluate their security controls, data protection measures, and overall risk posture.
  • In this role, you will develop and implement vendor risk management frameworks, policies, and procedures to enhance the effectiveness of our vendor risk program.
  • The Security Risk Analyst will collaborate with various internal stakeholders, including procurement, legal, and IT teams, to ensure vendor contracts and agreements align with our security standards and requirements.
  • You will monitor and track vendor compliance with security policies, standards, and contractual obligations.
  • Provide regular reports and updates to senior management on the status of vendor risk assessments, identified issues, and remediation efforts.
  • You will create and maintain relevant metrics for the program using PowerBI.
  • Stay current with industry trends, best practices, and regulatory requirements related to vendor risk management.
  • They will also assist the CSO department to raise employee awareness of security risks and methods to protect company critical infrastructure, data, and assets. This role drives security control objectives to mitigate the risk from existing and evolving vulnerabilities and threats for on-site, offshore and cloud solutions.

JOB DUTIES/RESPONSIBILITIES

  • Tracks Vendor Assessment Review Requests and communicates status to requestors.
  • Reviews assessment reports against asset control objectives to determine effectiveness.
  • Assists with vendor risk assessments (vendor assessments, supply chain assessments, etc.) as necessary.
  • Reports out on control testing through Controls Dashboard
  • Administers vendor risk request tracking process.
  • Prepares summary and detailed reports on vendor risk across the enterprise.
  • Conducts control testing and assessment.

MINIMUM REQUIREMENTS

Minimum education required of the position

  • Bachelor’s degree in Business, Computer Science or related field, or equivalent work experience

Minimum experience required of the position

  • 2+ years of experience in internal or external auditing, security testing, or risk management and analysis
  • 1+ years of IT security or IT risk management experience
  • Desired – Vendor Management experience, PowerBI experience

Minimum knowledge, skills and abilities required of the position

  • Excellent problem-solving and decision making ability
  • Excellent written and verbal communication skills
  • Professional demeanor, exceptional interpersonal skills, including teamwork, facilitation and negotiation
  • Team player, highly collaborative, able to work cross-functionally
  • Resourceful and self-motivated, able to work independently when required
  • Excellent planning, organizational and project management skills; detail and process-oriented; able to multi-task a number of different projects
  • Knowledge of generally applicable and accepted audit and risk frameworks (e.g. COBIT, CAG 20 Critical Security Controls, NIST, UCF) and government guidelines and laws (e.g. Sarbanes Oxley Act, NERC/CIP, HIPAA, FCC)
  • Understanding of regulatory requirements impacting the util

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Entergy

View company profile →