Principal Cybersecurity Compliance Analyst

GFT

Roseville (CA)

Hybrid

USD 150,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Comprehensive benefits package including wellness programs
Tax-deferred 401(k) savings plan
Incentive compensation for eligible positions

Job summary

GFT is seeking a Principal Cybersecurity Compliance Analyst for its Security and Safety team. This hybrid role in Roseville, CA, requires strong expertise in governance, risk, and compliance programs aligned with regulatory standards.

Key responsibilities include leading GRC program development, conducting compliance assessments, and managing audit documentation. Candidates should have a bachelor's degree and at least 10 years of experience in the power utility sector, particularly focused on NERC CIP standards.

Qualifications

  • Minimum of 10 years of relevant experience in the power utility industry.
  • Deep working knowledge of NERC CIP standards and the FERC regulatory environment.
  • Strong analytical, organizational, and technical writing skills.

Responsibilities

  • Lead the development of governance, risk, and compliance (GRC) programs.
  • Conduct compliance gap assessments and control testing for cybersecurity systems.
  • Prepare and maintain audit-ready documentation.

Skills

Governance, Risk, and Compliance (GRC)
Cybersecurity
Operational Technology
Analytical skills
Communication skills

Education

Bachelor’s degree in cybersecurity, information systems, engineering, business, or related field

Job description

Principal Cybersecurity Compliance Analyst
What You Will Do

GFT is looking for a Principal Cybersecurity Compliance Analyst to join our Security and Safety team in Northern California. This hybrid role requires regular attendance at our client’s office.

Responsibilities
  • Lead and support the development, implementation, and continuous improvement of governance, risk, and compliance (GRC) programs aligned with FERC (D2SI SPHP Section 9) and NERC CIP standards for PG&E’s power generation assets.
  • Develop, maintain, and operationalize policies, procedures, standards, and guidelines to meet regulatory requirements and industry best practices.
  • Conduct compliance gap assessments, risk analyses, and control testing for cybersecurity and OT systems.
  • Prepare and maintain audit‑ready documentation, including compliance narratives, evidence repositories, and records retention practices.
  • Coordinate and support internal and external audits, including NERC Regional Entity audits, spot checks, and self-certifications.
  • Collaborate with cybersecurity, IT, OT, engineering, legal, and enterprise risk teams to align compliance requirements with business operations.
  • Serve as a liaison between technical teams and compliance leadership to translate regulatory requirements into actionable controls.
  • Track compliance metrics, risks, and issues; prepare reports and dashboards for leadership.
  • Monitor regulatory developments, FERC and NERC standards changes, and enforcement trends.
  • Support compliance training and awareness efforts for internal stakeholders.
  • Assist in the integration of compliance controls into operational and cybersecurity processes.
  • Participate in mock audits, tabletop exercises, and incident response planning.
Required Qualifications
  • Bachelor’s degree in cybersecurity, information systems, engineering, business, or a related field.
  • Minimum of 10 years of relevant experience in the power utility industry, with a focus on governance, risk, and compliance (GRC), cybersecurity, or operational technology.
  • Deep working knowledge of NERC CIP standards and the FERC regulatory environment.
  • Direct experience supporting NERC CIP audits (self-certifications, spot checks, or enforcement actions).
  • Experience with compliance documentation, evidence collection, and audit support.
  • Familiarity with electric utility operations, OT environments, or IC/SCADA systems.
  • Strong analytical, organizational, and technical writing skills.
  • Excellent communication and interpersonal skills, with the ability to work independently and collaboratively.
  • Certification from a recognized risk, governance, or cybersecurity organization (e.g., CISSP, CISM, RIMS-CRMP, or equivalent) required.
Preferred Qualifications
  • Experience in the energy sector, particularly power generation or utilities.
  • PMP certification.
  • Familiarity with SCADA/ICS systems and processes.
  • Knowledge of related frameworks (e.g., NIST CSF, NIST SP 800-53, ISO 27001).
  • Experience in project management, including scope, schedule, and budget tracking.
  • Involvement in professional organizations or industry committees.
Compensation

The salary range for this role is $150,000 – $200,000. Salary is dependent upon experience and geographic location.

Benefits
  • Hybrid (in-person and remote) work environment.
  • Comprehensive benefits package including wellness programs, parental leave, pet insurance, medical, dental, vision, disability, and life insurance.
  • Tax‑deferred 401(k) savings plan.
  • Competitive paid‑time‑off (PTO) accrual.
  • Tuition reimbursement for continued education.
  • Commitment to professional development, access to internal and external training programs, and support of active participation in professional organizations.
  • Incentive compensation for eligible positions.
Location

Sacramento, CA; Roseville, CA; Oakland, CA

Equal Opportunity Employer

All qualified candidates will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veterans’ status, or other characteristics protected by law.

Background Check

All advertised positions will require the successful completion of a criminal background check.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Cybersecurity Compliance Analyst
Principal Cybersecurity Compliance Analyst

GFT • Oakland (CA)

Hybrid
USD 150,000 - 200,000
Hybrid work environment
Comprehensive benefits package
401(k) savings plan
+2
Expert Regulatory Analyst - Flexible Location (Electrical Engineer and FERC experience preferred)
Expert Regulatory Analyst - Flexible Location (Electrical Engineer and FERC experience preferred)

Pacific Gas and Electric Company • Oakland (CA)

Hybrid
USD 126,000 - 200,000
Senior Cybersecurity Compliance Lead - GRC & NERC CIP
Senior Cybersecurity Compliance Lead - GRC & NERC CIP

GFT • Roseville (CA)

Hybrid
USD 150,000 - 200,000
Comprehensive benefits package including wellness programs
Tax-deferred 401(k) savings plan
Incentive compensation for eligible positions
Senior Cybersecurity Compliance Lead – GRC & NERC CIP (Hybrid)
Senior Cybersecurity Compliance Lead – GRC & NERC CIP (Hybrid)

GFT • Oakland (CA)

Hybrid
USD 150,000 - 200,000
Hybrid work environment
Comprehensive benefits package
401(k) savings plan
+2
Compliance & Risk Consultant, Senior - Flexible Location
Compliance & Risk Consultant, Senior - Flexible Location

Pacific Gas and Electric Company • Oakland (CA), Northern (KY)

Hybrid
USD 100,000 - 169,000
Compliance Consultant, Senior
Compliance Consultant, Senior

Spectraforce Technologies • Oakland (CA)

Hybrid
USD 90,000 - 120,000
Senior NERC CIP Compliance Analyst
Senior NERC CIP Compliance Analyst

CAMS • New Haven (CT)

On-site
USD 90,000 - 120,000
Medical insurance
401(k) plan
Tuition reimbursement
Regulatory Compliance Advisor
Regulatory Compliance Advisor

Southern California Edison (SCE) • Rosemead (CA)

Hybrid
USD 110,000 - 150,000
Hybrid work model
Travel up to 25%
Enterprise Cybersecurity Senior Advisor - Grid Security
Enterprise Cybersecurity Senior Advisor - Grid Security

Southern California Edison (SCE) • Rosemead (CA)

Hybrid
USD 120,000 - 150,000
Cybersecurity Engineering, Risk & Governance Senior Advisor
Cybersecurity Engineering, Risk & Governance Senior Advisor

Southern California Edison (SCE) • Rosemead (CA)

Hybrid
USD 150,000 - 190,000