Find Jobs
Find Jobs Near You – Available Work in Your Location
Cybersecurity Governance & Risk Analyst or Sr. Cybersecurity Governance & Risk Analyst
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on North Carolina data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$118,018 / year median in North Carolina
+8% projected growth
Job Description
Cybersecurity Governance & Risk Analyst:
Bachelors degree in Cybersecurity or related degree In addition to bachelor's degree, 2 years related experience In lieu of bachelor's degree AND 2 years minimum of related work experience listed above, high school diploma/GED AND 6 years minimum of related work experience Basic/Required Qualifications for Sr.Cybersecurity Governance & Risk Analyst:
Bachelor's degree in Cybersecurity or related degree Minimum 5 years Required of Related Work Experience. In lieu of degree(s) listed above, High School/GED AND 9 years related work experience Desired Qualifications Experience in Cybersecurity, preferably with risk identification and management, audit and compliance, policy development and maintenance, evaluation of control requirements, security and related industry regulatory issues Knowledge in validating the organization against policies/guidelines/procedures/regulations/laws to ensure compliance Knowledge in reviewing service performance reports identifying any significant issues and variances, initiating, where necessary, corrective actions and ensuring that all outstanding issues are followed up Ability to evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) into high quality, fused targeting/intelligence products. Working knowledge of Cybersecurity frameworks such as NIST Knowledge of risk management processes (e.g., methods for assessing and mitigating risk). Able to work effectively with defined direction Demonstrated ability to work independently with supervisory review and direction Excellent listening and communication skills; able to present information in an understandable manner both verbal and written Demonstrated ability to absorb change and continue with positive results Skill in conducting audits or reviews of technical systems. Skill in performing impact/risk assessments. Skill in processing collected data for follow-on analysis. Recognize a possible security violation and take appropriate action to report the incident as required Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs) Provide ongoing optimization and problem-solving support Demonstrates good listening skills and puts forth the effort to understand others points of view. Has the ability to manage confidential information with a high degree of integrity. Responds well to supervisors, is easy to challenge and develop, and is easily coachable. Able to work effectively with defined direction Perform cyber defense trend analysis and reporting. Skill in creating and utilizing mathematical or statistical models. Research current technology to understand capabilities of required system or network. Knowledge of information technology (IT) supply chain security and supply chain risk management policies, requirements, and procedures. ServiceNow or similar asset management database experience Experience creating dashboards in ServiceNow for compliance and cybersecurity monitoring/reporting Knowledge of traditional gas-industry OT devices such as PLCs, RTUs, VFDs, electronic correctors, etc. Direct experience with incident investigation and remediation Demonstrated ability to develop complex processes with multiple stakeholders for isolating/securing OT environments as part of incident response activities Experience tracking and remediating cybersecurity vulnerabilities in operational environments Working Conditions Hybrid mobility classification - Work will be performed from both remote and onsite locations after the onboarding period. However, hybrid employees must live within a reasonable commute to their designated Duke Energy facility, not greater than 50 miles one way. Employees are expected to report to their assigned Duke Energy facility as required and directed by their manager, on average 3 full workdays per regular work week. Travel Requirements 5-15% Relocation Assistance Provided (as applicable) No Represented/Union Position No Visa Sponsored Position No. This is not a Visa Sponsored Position. This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future. Please note that in order to be considered for this position, you must possess all of the basic/required qualifications. Privacy Do Not Sell My Personal Information (CA) Terms of Use AccessibilityBenefits
- Dental Insurance
- Relocation Assistance