Associate Cybersecurity Governance & Risk Analyst

Duke Energy

Charlotte (NC)

Hybrid

USD 55,000 - 75,000

Full time

10 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Duke Energy is seeking an Associate Cybersecurity Governance & Risk Analyst in Charlotte, NC, to support governance, risk, and architecture tasks within a cybersecurity team. This entry-level position offers growth opportunities and exposure to TASR, SRT, CAR, and MSB/CMSB processes.

You will work under supervision to perform intake reviews, assist with risk assessments, and help maintain baselines and architecture documentation, with hybrid on-site/remote work arrangements after onboarding.

Qualifications

  • Associate degree in Cybersecurity or related field required.
  • Alternative: High School/GED plus 2 years related work experience.

Responsibilities

  • Perform intake reviews for TASR/SRT and verify submissions against policies and standards.
  • Assist with risk assessments and identify security gaps for senior architects.
  • Coordinate with requestors to obtain missing documentation and evidence.
  • Support vendor and technology due diligence activities and track workflow status.
  • Document architecture requirements, decisions, risk dispositions, and follow-up actions.
  • Contribute to CAR preparation, intake validation, and documentation quality reviews.
  • Collect and analyze architecture performance metrics and support dashboard reporting.

Skills

Cybersecurity fundamentals
Written communication
Verbal communication
Time management
Analytical thinking
Collaboration

Education

Associate degree in Cybersecurity or related
High School/GED + 2 years related experience

Job description

Associate Cybersecurity Governance & Risk Analyst

United States, North Carolina, Charlotte

Sep 22, 2026

Build an exciting, rewarding career with us - help us make a difference for millions of people every day. Consider joining the Duke Energy team, where you'll find a friendly work environment, opportunities for growth and development, recognition for your work, and competitive pay and benefits.

Job Summary

This is an entry-level role supporting the Cybersecurity Architecture & Consulting team. The Associate Cybersecurity Gov. & Risk Analyst performs or assists with foundational cybersecurity architecture, governance, risk, and process-driven activities under the direction of management and senior architects. The role supports high-volume architecture services while developing the knowledge and experience needed to work with increasing independence.

The position provides scalable support across Technology Acquisition Sourcing Reviews (TASR), Security Review Tasks (SRT), Cybersecurity Architecture Reviews (CAR), Minimum Security Baselines (MSB/CMSB), architecture intake, metrics, documentation, and emerging technology research. This support enables senior architects to focus on complex risk reviews, strategic initiatives, security design, and stakeholder engagement.

Responsibilities
Technology Acquisition Sourcing Reviews and Security Review Tasks
  • Perform initial intake reviews and completeness checks for TASR and SRT submissions.
  • Validate submissions against established cybersecurity policies, standards, security requirements, and approved architectures.
  • Conduct preliminary risk assessments, identify security gaps, and elevate higher-risk or complex matters to senior architects or subject matter experts.
  • Coordinate with requestors to obtain missing documentation, evidence, or technical information.
  • Support vendor and technology due diligence activities.
  • Track workflow status, review metrics, and reporting requirements.
  • Prepare review summaries, recommendations, and supporting documentation for senior architects and subject matter experts.
  • Document architecture requirements, decisions, risk dispositions, and follow-up actions.
Minimum Security Baselines
  • Research CIS Benchmarks, NIST guidance, vendor hardening recommendations, regulatory requirements, and other recognized security practices.
  • Assist with drafting, updating, and maintaining MSB and CMSB documents.
  • Coordinate stakeholder reviews, validation activities, and approval workflows.
  • Track baseline review cycles, lifecycle activities, and outstanding actions.
  • Collect and organize supporting evidence and implementation documentation.
  • Maintain baseline repositories, templates, and related records.
  • Assist with publishing approved baselines and communicating updates.
  • Document implementation guidance and architecture considerations.
Cybersecurity Architecture Governance and Consulting Support
  • Support Cybersecurity Architecture intake management, workflow coordination, and repository maintenance.
  • Assist with CAR preparation, intake validation, documentation quality reviews, evidence collection, and action-item tracking.
  • Maintain architecture standards, procedures, reference materials, and architecture decision records.
  • Coordinate architecture consultations, stakeholder meetings, and follow-up activities.
  • Prepare clear documentation of architecture recommendations and requirements.
  • Provide professional customer support and communicate issues, requirements, and resolutions to requestors, management, and architecture stakeholders.
Metrics, Reporting, and Continuous Improvement
  • Collect, validate, and analyze architecture performance metrics.
  • Support dashboard reporting, risk-reduction tracking, trend analysis, and operational reporting.
  • Gather evidence supporting architecture outcomes, control implementation, and process performance.
  • Assist with quality assurance reviews of architecture deliverables and identify opportunities for process improvement.
  • Monitor assigned work to meet established schedules and escalated barriers or risks as appropriate.
Emerging Technology and Security Research
  • Research emerging technologies, cloud services, artificial intelligence, agentic AI, and related cybersecurity requirements.
  • Assist with technology evaluations, cybersecurity control mapping, and security framework analysis.
  • Monitor relevant industry trends, vendor capabilities, and changes to security guidance.
  • Develop draft architecture guidance, recommendations, and educational materials for review by senior team members.
General Responsibilities
  • Demonstrate working knowledge of IT and cybersecurity policies, standards, processes, controls, tools, and functional areas.
  • Perform or assist with security reviews, control assessments, risk assessments, and technical project work of a less complex nature.
  • Collaborate with cybersecurity leadership, architects, subject matter experts, business partners, and technology teams.
  • Apply cybersecurity process and control knowledge to support compliance and risk-management objectives.
  • Protect confidential information and perform assigned work with integrity, sound judgment, and appropriate supervisory review.
  • Develop technical, consulting, and architecture skills with the expectation of assuming greater complexity and independence over time.
Basic/Required Qualifications
  • Associate degree in Cybersecurity or Other Related Degree
  • In lieu of Associate degree(s) listed above, High School/GED AND 2 year(s) related work experience
Desired Qualifications
  • Working knowledge of cybersecurity frameworks and guidance, including NIST and CIS Benchmarks.
  • Knowledge of cybersecurity risk-management processes and methods for identifying, assessing, and mitigating risk.
  • Knowledge of IT and cybersecurity policies, standards, procedures, controls, compliance requirements, and security configuration guidance.
  • Ability to research current technologies and understand system, network, cloud, vendor, and emerging technology capabilities.
  • Ability to evaluate, analyze, and synthesize technical and process information into clear, high-quality work products.
  • Experience or interest in conducting technical reviews, control assessments, impact assessments, or risk assessments.
  • Knowledge of IT supply-chain security and supply-chain risk-management practices.
  • Strong written and verbal communication, listening, documentation, organization, and customer-support skills.
  • Ability to work effectively with defined direction, accept coaching and feedback, and progress toward greater independence.
  • Ability to manage multiple assignments, follow established processes, meet schedules, and elevate issues appropriately.
  • Ability to manage confidential information with a high degree of integrity.
  • Interest in cybersecurity architecture, cloud security, artificial intelligence security, technology governance, metrics, and continuous improvement.
Working Conditions
  • Hybrid Mobility Classification - Work will be performed from both remote and onsite locations after the onboarding period. However, hybrid employees must live within a reasonable commute to their designated Duke Energy facility, not greater than 50 miles one way. Employees are expected to report to their assigned Duke Energy facility as required and directed by their manager, on average 3 full workdays per regular workweek.
  • Office Environment
Specific Requirements
  • 0 - 2 years utility, cybersecurity, auditing, compliance, regulatory or related experience.
Travel Requirements

Not required

Relocation Assistance Provided (as applicable)

No Represented/Union Position

No Visa Sponsored Position

This is not a Visa Sponsored Position. This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future.

Please note that in order to be considered for this position, you must possess all of the basic/required qualifications.

Privacy

Do Not Sell My Personal Information (CA)

Terms of Use

Accessibility

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Associate Cybersecurity Governance & Risk Analyst
Associate Cybersecurity Governance & Risk Analyst

Duke Energy Corporation • Charlotte (NC)

Hybrid
USD 55,000 - 75,000
Associate Cybersecurity Systems Engineering Analyst - Data Protection
Associate Cybersecurity Systems Engineering Analyst - Data Protection

Duke Energy • Charlotte (NC)

On-site
USD 85,000 - 120,000
Hybrid Junior Cybersecurity Governance & Risk Analyst
Hybrid Junior Cybersecurity Governance & Risk Analyst

Duke Energy Corporation • Charlotte (NC)

Hybrid
USD 55,000 - 75,000
Manager - IT Audit Services
Manager - IT Audit Services

Duke Energy • United States

Hybrid
USD 120,000 - 180,000
Manager - IT Audit Services
Manager - IT Audit Services

Duke Energy • Charlotte (NC)

Hybrid
USD 140,000 - 180,000
Senior Work Management Specialist
Senior Work Management Specialist

Duke Energy • Garner (NC)

Hybrid
USD 52,000 - 70,000
Relocation assistance provided
Technology Development Manager
Technology Development Manager

Duke Energy • Saint Petersburg (FL)

On-site
USD 110,000 - 170,000
Director, Security Architecture & Engineering
Director, Security Architecture & Engineering

Relias Learning, LLC • Morrisville (NC)

On-site
USD 180,000 - 200,000
401k match
Flexible PTO
Parental leave policy
+1
Technology Development Manager
Technology Development Manager

Duke Energy Corporation • Pinehurst (NC)

On-site
USD 115,000 - 140,000
Technology Development Manager
Technology Development Manager

Duke Energy Corporation • Saint Petersburg (FL)

Hybrid
USD 120,000 - 180,000