Associate Cybersecurity Governance & Risk Analyst

Duke Energy Corporation

Charlotte (NC)

Hybrid

USD 55,000 - 75,000

Full time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Duke Energy Corporation is seeking an entry-level Associate Cybersecurity Gov. & Risk Analyst to support the Cybersecurity Architecture & Consulting team. You will help with foundational cybersecurity governance, risk assessments, documentation, and process improvements while gaining independence over time.

The role covers TASR/SRT reviews, MSB/CMSB maintenance, architecture documentation, and emerging technology research in a hybrid work environment.

Qualifications

  • Associate degree in Cybersecurity or related field is required.
  • High School/GED with 2 years related work experience acceptable.
  • Knowledge of NIST, CIS Benchmarks and risk-management processes.
  • Ability to research current technologies and understand IT and cybersecurity guidance.

Responsibilities

  • Perform intake reviews for TASR and SRT submissions.
  • Validate submissions against cybersecurity standards and architectures.
  • Assist with risk assessments and document findings.
  • Coordinate with requestors to obtain missing information and evidence.
  • Support governance, architecture intake, and reporting activities.

Skills

Cybersecurity frameworks
Risk management
IT policies & controls
Research emerging tech
Communication skills

Education

Associate degree in Cybersecurity or related
High School diploma + 2 years related experience

Job description

Important Application Submission Information

In order to ensure your application is successfully received before the job posting expires, please submit your application by 11:59 PM on Friday, September 25, 2026

Important Application Submission Information

In order to ensure your application is successfully received before the job posting expires, please submit your application by 11:59 PM on Friday, September 25, 2026

More than a career - a chance to make a difference in people's lives.

Build an exciting, rewarding career with us – help us make a difference for millions of people every day. Consider joining the Duke Energy team, where you'll find a friendly work environment, opportunities for growth and development, recognition for your work, and competitive pay and benefits.

Job Summary

This is an entry-level role supporting the Cybersecurity Architecture & Consulting team. The Associate Cybersecurity Gov. & Risk Analyst performs or assists with foundational cybersecurity architecture, governance, risk, and process-driven activities under the direction of management and senior architects. The role supports high-volume architecture services while developing the knowledge and experience needed to work with increasing independence.

The position provides scalable support across Technology Acquisition Sourcing Reviews (TASR), Security Review Tasks (SRT), Cybersecurity Architecture Reviews (CAR), Minimum Security Baselines (MSB/CMSB), architecture intake, metrics, documentation, and emerging technology research. This support enables senior architects to focus on complex risk reviews, strategic initiatives, security design, and stakeholder engagement.

Responsibilities
Technology Acquisition Sourcing Reviews and Security Review Tasks
  • Perform initial intake reviews and completeness checks for TASR and SRT submissions.
  • Validate submissions against established cybersecurity policies, standards, security requirements, and approved architectures.
  • Conduct preliminary risk assessments, identify security gaps, and elevate higher-risk or complex matters to senior architects or subject matter experts.
  • Coordinate with requestors to obtain missing documentation, evidence, or technical information.
  • Support vendor and technology due diligence activities.
  • Track workflow status, review metrics, and reporting requirements.
  • Prepare review summaries, recommendations, and supporting documentation for senior architects and subject matter experts.
  • Document architecture requirements, decisions, risk dispositions, and follow-up actions.
Minimum Security Baselines
  • Research CIS Benchmarks, NIST guidance, vendor hardening recommendations, regulatory requirements, and other recognized security practices.
  • Assist with drafting, updating, and maintaining MSB and CMSB documents.
  • Coordinate stakeholder reviews, validation activities, and approval workflows.
  • Track baseline review cycles, lifecycle activities, and outstanding actions.
  • Collect and organize supporting evidence and implementation documentation.
  • Maintain baseline repositories, templates, and related records.
  • Assist with publishing approved baselines and communicating updates.
  • Document implementation guidance and architecture considerations.
Cybersecurity Architecture Governance and Consulting Support
  • Support Cybersecurity Architecture intake management, workflow coordination, and repository maintenance.
  • Assist with CAR preparation, intake validation, documentation quality reviews, evidence collection, and action-item tracking.
  • Maintain architecture standards, procedures, reference materials, and architecture decision records.
  • Coordinate architecture consultations, stakeholder meetings, and follow-up activities.
  • Prepare clear documentation of architecture recommendations and requirements.
  • Provide professional customer support and communicate issues, requirements, and resolutions to requestors, management, and architecture stakeholders.
Metrics, Reporting, and Continuous Improvement
  • Collect, validate, and analyze architecture performance metrics.
  • Support dashboard reporting, risk-reduction tracking, trend analysis, and operational reporting.
  • Gather evidence supporting architecture outcomes, control implementation, and process performance.
  • Assist with quality assurance reviews of architecture deliverables and identify opportunities for process improvement.
  • Monitor assigned work to meet established schedules and elevate barriers or risks as appropriate.
Emerging Technology and Security Research
  • Research emerging technologies, cloud services, artificial intelligence, agentic AI, and related cybersecurity requirements.
  • Assist with technology evaluations, cybersecurity control mapping, and security framework analysis.
  • Monitor relevant industry trends, vendor capabilities, and changes to security guidance.
  • Develop draft architecture guidance, recommendations, and educational materials for review by senior team members.
General Responsibilities
  • Demonstrate working knowledge of IT and cybersecurity policies, standards, processes, controls, tools, and functional areas.
  • Perform or assist with security reviews, control assessments, risk assessments, and technical project work of a less complex nature.
  • Collaborate with cybersecurity leadership, architects, subject matter experts, business partners, and technology teams.
  • Apply cybersecurity process and control knowledge to support compliance and risk-management objectives.
  • Protect confidential information and perform assigned work with integrity, sound judgment, and appropriate supervisory review.
  • Develop technical, consulting, and architecture skills with the expectation of assuming greater complexity and independence over time.
Basic/Required Qualifications
  • Associate degree in Cybersecurity or Other Related Degree
  • In lieu of Associate degree(s) listed above, High School/GED AND 2 year(s) related work experience
Desired Qualifications
  • Working knowledge of cybersecurity frameworks and guidance, including NIST and CIS Benchmarks.
  • Knowledge of cybersecurity risk-management processes and methods for identifying, assessing, and mitigating risk.
  • Knowledge of IT and cybersecurity policies, standards, procedures, controls, compliance requirements, and security configuration guidance.
  • Ability to research current technologies and understand system, network, cloud, vendor, and emerging technology capabilities.
  • Ability to evaluate, analyze, and synthesize technical and process information into clear, high-quality work products.
  • Experience or interest in conducting technical reviews, control assessments, impact assessments, or risk assessments.
  • Knowledge of IT supply‑chain security and supply‑chain risk‑management practices.
  • Strong written and verbal communication, listening, documentation, organization, and customer‑support skills.
  • Ability to work effectively with defined direction, accept coaching and feedback, and progress toward greater independence.
  • Ability to manage multiple assignments, follow established processes, meet schedules, and elevate issues appropriately.
  • Ability to manage confidential information with a high degree of integrity.
  • Interest in cybersecurity architecture, cloud security, artificial intelligence security, technology governance, metrics, and continuous improvement.
Working Conditions
  • Hybrid Mobility Classification – Work will be performed from both remote and onsite locations after the onboarding period. However, hybrid employees must live within a reasonable commute to their designated Duke Energy facility, not greater than 50 miles one way. Employees are expected to report to their assigned Duke Energy facility as required and directed by their manager, on average 3 full workdays per regular workweek.
  • Office Environment
Specific Requirements
  • 0 - 2 years utility, cybersecurity, auditing, compliance, regulatory or related experience.
Travel Requirements

Not required

Relocation Assistance Provided (as applicable)

No

Represented/Union Position

No

Visa Sponsored Position

No. This is not a Visa Sponsored Position. This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future.

Please note that in order to be considered for this position, you must possess all of the basic/required qualifications.

Privacy

Do Not Sell My Personal Information (CA)

Terms of Use
Accessibility
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Associate Cybersecurity Governance & Risk Analyst
Associate Cybersecurity Governance & Risk Analyst

Duke Energy • Charlotte (NC)

On-site
USD 55,000 - 75,000
Hybrid Junior Cybersecurity Governance & Risk Analyst
Hybrid Junior Cybersecurity Governance & Risk Analyst

Duke Energy Corporation • Charlotte (NC)

Hybrid
USD 55,000 - 75,000
Manager - IT Audit Services
Manager - IT Audit Services

Duke Energy • Charlotte (NC)

Hybrid
USD 140,000 - 180,000
Enterprise Protective Services, Corporate Security Intern - Summer 2027
Enterprise Protective Services, Corporate Security Intern - Summer 2027

Duke Energy Corporation • Charlotte (NC)

On-site
USD 2,066,000 - 3,031,000
Cybersecurity Engineer
Cybersecurity Engineer

Aurora Health Care • Allenton (WI)

Remote
USD 80,000 - 120,000
Director, Security Architecture & Engineering
Director, Security Architecture & Engineering

Apply now! • Morrisville (NC)

On-site
USD 180,000 - 200,000
401k match
Flexible PTO
Parental leave
Cloud and Infrastructure Security Technician
Cloud and Infrastructure Security Technician

Risk & Insurance Education Alliance • Austin (TX)

Hybrid
USD 75,000 - 85,000
Medical, Dental Vision Insurance
401K matching
Paid Holidays
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Technical Security Risk & Governance Analyst
Technical Security Risk & Governance Analyst

Mbi Llc • Harrisburg

On-site
USD 80,000 - 100,000
Hybrid/telework eligibility
Participation in after-hours change windows or incident support
Cybersecurity Audit Analyst
Cybersecurity Audit Analyst

Elevate Ventures, Inc. • Huntsville (AL)

On-site
USD 75,000 - 110,000