Cyber Security GRB Analyst - Bethpage, NY

MSCCN

Bethpage (NY)

Hybrid

USD 94,000 - 148,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

PSEG Long Island is seeking a Cybersecurity GRC Analyst to support governance, risk, and compliance within the cybersecurity program. You will work with IT, Internal Audit, Compliance, and Procurement to ensure policies and controls are defined, implemented, and monitored enterprise-wide.

Key tasks include risk and control assessments, policy lifecycle management, audit coordination, remediation tracking, third‑party risk review, and executive reporting.

Qualifications

  • Bachelor's degree in a related discipline.
  • 4+ years of cybersecurity governance, risk, compliance, IT audit, or related field.
  • 8+ years considered with no degree.
  • Proficiency with Cyber GRC technologies (ServiceNow, Archer, RSAM).
  • Experience in policy lifecycle management and standards alignment.
  • Experience in risk and control assessments and documenting findings.

Responsibilities

  • Support governance oversight activities for the cybersecurity program across the enterprise.
  • Maintain and support policy lifecycle management, including review, update, and communication of cybersecurity policies, standards, procedures, and related documentation.
  • Assist with standards alignment to applicable requirements, contractual obligations, and recognized cybersecurity frameworks.
  • Perform and document risk and control assessments for systems, applications, vendors, projects, and business processes.
  • Identify control gaps, document findings, and support risk treatment planning with business and technical stakeholders.
  • Assist with control documentation and control testing to evaluate design and operating effectiveness.
  • Provide audit coordination support for internal audits, external audits, and regulatory assessments, including evidence gathering, response tracking, and issue follow-up.
  • Support compliance validation activities to confirm required controls, processes, and documentation are in place and operating as intended.
  • Support third-party risk review activities, including security questionnaires, documentation review, assessment follow-up, and findings management.
  • Maintain risk registers, issue logs, exception records, remediation plans, and supporting documentation.
  • Perform issue remediation tracking and follow up with stakeholders to support timely closure of findings, gaps, and action items.
  • Prepare executive reporting and documentation related to risk posture, compliance status, audit results, remediation progress, control maturity, and key metrics.
  • Support governance committees, risk discussions, and management reporting through accurate and organized documentation.
  • Contribute to continuous improvement of GRC processes, templates, reporting, and governance practices.

Skills

Governance oversight
Policy lifecycle management
Standards alignment
Risk and control assessments
Audit coordination
Compliance validation
Third‑party risk review
Reporting and documentation
Effective communication
Time management

Education

Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Business, Risk Management or related

Tools

ServiceNow
Archer
RSAM

Job description

ATTENTION MILITARY AFFILIATED JOB SEEKERS - Our organization works with partner companies to source qualified talent for their open roles. The following position is available to Veterans, Transitioning Military, National Guard and Reserve Members, Military Spouses, Wounded Warriors, and their Caregivers. If you have the required skill set, education requirements, and experience, all positions are onsite, unless otherwise stated.

PSEG Company: PSEG Long Island

Salary Range: $ 93,600 - $ 148,200

Work Location Category: Hybrid

PSEG is not offering visa sponsorship for this position.

Job Summary: This position supports the organization’s cybersecurity governance, risk, and compliance program through governance oversight, policy lifecycle management, standards alignment, risk and control assessments, audit coordination, compliance validation, issue remediation tracking, third-party risk review, and executive reporting and documentation.

The Cybersecurity GRC Analyst works closely with IT, Internal Audit, Compliance, Procurement, and business stakeholders to help ensure cybersecurity requirements are defined, documented, assessed, and monitored across the enterprise. This role is responsible for supporting the maintenance of cybersecurity policies and standards, conducting and documenting risk assessments, evaluating control effectiveness, coordinating audit and compliance activities, tracking remediation efforts, and preparing clear reporting for management and leadership.

Job Responsibilities
  • Support governance oversight activities for the cybersecurity program across the enterprise.
  • Maintain and support policy lifecycle management, including the review, update, and communication of cybersecurity policies, standards, procedures, and related documentation.
  • Assist with standards alignment to applicable requirements, contractual obligations, and recognized cybersecurity frameworks.
  • Perform and document risk and control assessments for systems, applications, vendors, projects, and business processes.
  • Identify control gaps, document findings, and support risk treatment planning with business and technical stakeholders.
  • Assist with control documentation and control testing to evaluate design and operating effectiveness.
  • Provide audit coordination support for internal audits, external audits, and regulatory assessments, including evidence gathering, response tracking, and issue follow-up.
  • Support compliance validation activities to confirm required controls, processes, and documentation are in place and operating as intended.
  • Support third-party risk review activities, including security questionnaires, documentation review, assessment follow-up, and findings management.
  • Maintain risk registers, issue logs, exception records, remediation plans, and supporting documentation.
  • Perform issue remediation tracking and follow up with stakeholders to support timely closure of findings, gaps, and action items.
  • Prepare executive reporting and documentation related to risk posture, compliance status, audit results, remediation progress, control maturity, and key metrics.
  • Support governance committees, risk discussions, and management reporting through accurate and organized documentation.
  • Contribute to continuous improvement of GRC processes, templates, reporting, and governance practices.
Required Experience
Job Specific Qualifications
  • Bachelors degree in Cybersecurity, Information Systems, Computer Science, Business, Risk Management or related discipline.
  • With four (4) or more years of experience in cybersecurity governance, risk, compliance, IT audit, internal controls, or related field.
  • Candidates without a degree who have 8 years of experience in cyber security governance risk and compliance will be considered.
  • Proficiency with Cyber GRC technologies (such as ServiceNow, Archer, RSAM, etc.)
  • Background supporting governance oversight, policy lifecycle management, and standards alignment activities.
  • Track record performing risk and control assessments and documenting findings, recommendations, and remediation actions.
  • History of supporting control testing, audit coordination, and compliance validation activities.
  • Direct involvement with third-party risk review, vendor assessment support, or related due diligence functions.
  • Familiarity with issue remediation tracking, exception management, and reporting processes.
  • Advanced analytical, organizational, reporting, and documentation skills.
  • Excellent written and verbal communication skills with the ability to work effectively with technical and non-technical stakeholders.
  • Ability to manage multiple priorities, maintain detailed records, and work independently with limited supervision.
  • Department of Energy’s regulation 10 CFR 810 is required
Please Note the Following

This position falls under the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) and requires NERC CIP background investigation prior to start.

Some positions at PSEG require access to information covered by the Department of Energy’s regulation 10 CFR 810 (Part 810). If applicable, the successful applicant must prove they are: (1) a citizen or national of the USA; OR (2) a lawful permanent resident of the United States (Non-Conditional Permanent I-551 / Green Card / Permanent Resident Card holder); OR (3) a citizen, national, or permanent resident of a “Generally Authorized” destination on the attached list and not also a citizen, national, permanent resident of any country not listed; OR (4) a “Protected Individual” under the Immigration and Naturalization Act (8 U.S.C 1324b(a)(3)).

Preferred Experience
  • Working knowledge of cybersecurity frameworks and control standards such as NIST CSF, NIST SP 800-53, ISO 27001, and CIS Controls.
  • Cybersecurity certification such as Security+, CISSP, CISA
Certificates/Security Clearances/Other
  • Cybersecurity certification such as Security+, CISSP, CISA
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager, Vulnerability Management and Application Security
Manager, Vulnerability Management and Application Security

PSEG • Town of Oyster Bay (NY)

On-site
USD 140,000 - 200,000
Medical benefits
Dental benefits
Vision benefits
+4
Supervisor, Vulnerability Management & Application Cyber Security
Supervisor, Vulnerability Management & Application Cyber Security

PSEG Long Island LLC • Bethpage (NY)

On-site
USD 180,000 - 280,000
Hybrid Cyber GRC Analyst: Risk, Policy & Audit
Hybrid Cyber GRC Analyst: Risk, Policy & Audit

MSCCN • Bethpage (NY)

Hybrid
USD 94,000 - 148,000
IT Auditor
IT Auditor

PSEG • Town of Oyster Bay (NY)

On-site
USD 120,000 - 160,000
9504 Sr IT Mgr
9504 Sr IT Mgr

PSEG.com • The Ironbound (NJ)

On-site
USD 137,000 - 224,000
Medical Insurance
Dental Insurance
Vision Insurance
+5
Cyber Security Analyst PSEG LI - DevSecOps Engineer
Cyber Security Analyst PSEG LI - DevSecOps Engineer

PSEG • Town of Oyster Bay (NY)

Hybrid
USD 110,000 - 160,000
9507 IT Consultant
9507 IT Consultant

PSEG.com • Salem (NJ)

On-site
USD 79,000 - 126,000
Comprehensive benefits from day one
401(k) with company match
Tuition reimbursement
+1
IT Engineer Principal II -Data & Analytics
IT Engineer Principal II -Data & Analytics

PSEG • United States

On-site
USD 121,000 - 199,000
Benefits from day one
Hybrid work environment
Political Affairs & Governance Manager at PSEG Newark, NJ
Political Affairs & Governance Manager at PSEG Newark, NJ

PSEG • Newark (NJ)

On-site
USD 80,000 - 110,000
12063 Sr Project Coordinator - Future of Work and Employee Experience
12063 Sr Project Coordinator - Future of Work and Employee Experience

PSEG • Newark (NJ)

Hybrid
USD 108,000 - 170,000
Medical benefits
Dental benefits
Vision benefits
+6