Cyber Security GRC Analyst
$93.6k - $148.2kPublic Service Enterprise Group Incorporated
Requisition : 82464 PSEG Company : PSEG Long Island Salary Range : $ 93,600 - $ 148,200 Work Location Category : Hybrid Fixed We're one of the country's largest energy companies, with a vision of powering a future where people use energy more efficiently and it's safer and delivered more reliably than ever. We're also deeply connected to the communities we serve, with more than 13,000 employees working together to support our customers and make a difference every day. Here, you'll have the stability and exciting opportunities that come with being a Fortune 500 company - along with a supportive, friendly work environment where your contributions are valued. We know life isn't one-size-fits-all, and neither is work. That's why we offer flexible work options depending on the role.
In support of this model, roles have been categorized into one of three work location categories:
1. Onsite - roles where employees are expected to be onsite daily.
2. Hybrid fixed - roles that are a mix of remote work and onsite work fixed days each week.
3. Hybrid flexible - roles that are a mix of remote work and onsite work, but the onsite requirements have greater flexibility. (i.e. 5-8 days a month vs. set days each week). As an employee, if you are regularly scheduled to work 20 or more hours per week, you will have access to a wide range of comprehensive benefits designed to support your total well-being: medical, dental, vision, paternal leave and family leave programs, behavioral health programs, 401(k) with company match, life insurance, tuition reimbursement, and generous paid time off. More than 13,000 people already call PSEG their work home, taking pride in providing safe, reliable service to millions of customers. If you're looking for a place where you can build a meaningful career and help power and support our communities, we'd love to welcome you to the team. PSEG is not offering visa sponsorship for this position. Job Summary This position supports the organization's cybersecurity governance, risk, and compliance program through governance oversight, policy lifecycle management, standards alignment, risk and control assessments, audit coordination, compliance validation, issue remediation tracking, third-party risk review, and executive reporting and documentation. The Cybersecurity GRC Analyst works closely with IT, Internal Audit, Compliance, Procurement, and business stakeholders to help ensure cybersecurity requirements are defined, documented, assessed, and monitored across the enterprise. This role is responsible for supporting the maintenance of cybersecurity policies and standards, conducting and documenting risk assessments, evaluating control effectiveness, coordinating audit and compliance activities, tracking remediation efforts, and preparing clear reporting for management and leadership. Job Responsibilities
Some positions at PSEG require access to information covered by the Department of Energy's regulation 10 CFR 810 (Part 810). If applicable, the successful applicant must prove they are: (1) a citizen or national of the USA; OR (2) a lawful permanent resident of the United States (Non-Conditional Permanent I-551 / Green Card / Permanent Resident Card holder); OR (3) a citizen, national, or permanent resident of a "Generally Authorized" destination on the attached list and not also a citizen, national, permanent resident of any country not listed; OR (4) a "Protected Individual" under the Immigration and Naturalization Act (8 U.S.C 1324b(a)(3)). As an employee of PSEG Long Island, you should be aware that during storm/outage restoration efforts, you may be required to perform functions different from normal operations and work extended hours beyond your regular work schedule. You may also be required to work on premise or in an alternate location as directed by the company. For all roles, PSEGLI's drug and alcohol testing program includes pre-employment testing, testing for cause, and post-incident/accident testing.
Employees who are hired or transfer into a federally regulated role (including positions covered by USDOT, PHMSA, or NRC regulations) are subject to random drug and alcohol testing, inclusive of marijuana. Although numerous states throughout the country have legalized marijuana/cannabis products recreationally and medically, the use of these products are prohibited for employees in federally regulated roles. Please note that the use of CBD products may result in a positive drug test for THC/Marijuana and such use is not a legitimate medical explanation for a positive result. If you are a current PSEG employee and offered an opportunity with PSEG Long Island, you will be treated as a new hire. Please note that as a new hire to the Long Island subsidiary, your benefits will change and generally will be consistent with other similarly situated PSEG Long Island new hires. Similarly, for PSEG Long Island employees who accept job opportunities with PSEG or any of its subsidiaries (other than PSEG Long Island), their benefits will change and generally be consistent with other similarly situated new hires of that company.
PSEGLI is an equal opportunity employer, dedicated to a policy of non-discrimination in employment, including the hiring process, based on any legally protected characteristic. Legally protected characteristics include race, color, religion, national origin, sex, age, marital status, sexual orientation, disability or veteran status or any other characteristic protected by federal, state, or local law in locations where PSEG employs individuals.
PSEGLI is committed to providing reasonable accommodations to individuals with disabilities. If you have a disability and need assistance applying for a position, please call View phone number on click.appcast.io or email View email address on click.appcast.io.
If you need to request a reasonable accommodation to perform the essential functions of the job, email View email address on click.appcast.io. Any information provided regarding a disability will be kept strictly confidential and will not be shared with anyone involved in making a hiring decision. ADDITIONAL EEO INFORMATION (Click link below)
Know your Rights: Workplace Discrimination is Illegal
In support of this model, roles have been categorized into one of three work location categories:
1. Onsite - roles where employees are expected to be onsite daily.
2. Hybrid fixed - roles that are a mix of remote work and onsite work fixed days each week.
3. Hybrid flexible - roles that are a mix of remote work and onsite work, but the onsite requirements have greater flexibility. (i.e. 5-8 days a month vs. set days each week). As an employee, if you are regularly scheduled to work 20 or more hours per week, you will have access to a wide range of comprehensive benefits designed to support your total well-being: medical, dental, vision, paternal leave and family leave programs, behavioral health programs, 401(k) with company match, life insurance, tuition reimbursement, and generous paid time off. More than 13,000 people already call PSEG their work home, taking pride in providing safe, reliable service to millions of customers. If you're looking for a place where you can build a meaningful career and help power and support our communities, we'd love to welcome you to the team. PSEG is not offering visa sponsorship for this position. Job Summary This position supports the organization's cybersecurity governance, risk, and compliance program through governance oversight, policy lifecycle management, standards alignment, risk and control assessments, audit coordination, compliance validation, issue remediation tracking, third-party risk review, and executive reporting and documentation. The Cybersecurity GRC Analyst works closely with IT, Internal Audit, Compliance, Procurement, and business stakeholders to help ensure cybersecurity requirements are defined, documented, assessed, and monitored across the enterprise. This role is responsible for supporting the maintenance of cybersecurity policies and standards, conducting and documenting risk assessments, evaluating control effectiveness, coordinating audit and compliance activities, tracking remediation efforts, and preparing clear reporting for management and leadership. Job Responsibilities
- Support governance oversight activities for the cybersecurity program across the enterprise.
- Maintain and support policy lifecycle management, including the review, update, and communication of cybersecurity policies, standards, procedures, and related documentation.
- Assist with standards alignment to applicable requirements, contractual obligations, and recognized cybersecurity frameworks.
- Perform and document risk and control assessments for systems, applications, vendors, projects, and business processes.
- Identify control gaps, document findings, and support risk treatment planning with business and technical stakeholders.
- Assist with control documentation and control testing to evaluate design and operating effectiveness.
- Provide audit coordination support for internal audits, external audits, and regulatory assessments, including evidence gathering, response tracking, and issue follow-up.
- Support compliance validation activities to confirm required controls, processes, and documentation are in place and operating as intended.
- Support third-party risk review activities, including security questionnaires, documentation review, assessment follow-up, and findings management.
- Maintain risk registers, issue logs, exception records, remediation plans, and supporting documentation.
- Perform issue remediation tracking and follow up with stakeholders to support timely closure of findings, gaps, and action items.
- Prepare executive reporting and documentation related to risk posture, compliance status, audit results, remediation progress, control maturity, and key metrics.
- Support governance committees, risk discussions, and management reporting through accurate and organized documentation.
- Contribute to continuous improvement of GRC processes, templates, reporting, and governance practices.
- Bachelors degree in Cybersecurity, Information Systems, Computer Science, Business, Risk Management or related discipline.
- With four (4) or more years of experience in cybersecurity governance, risk, compliance, IT audit, internal controls, or related field.
- Candidates without a degree who have 8 years of experience in cyber security governance risk and compliance will be considered.
- Proficiency with Cyber GRC technologies (such as ServiceNow, Archer, RSAM, etc.)
- Background supporting governance oversight, policy lifecycle management, and standards alignment activities.
- Track record performing risk and control assessments and documenting findings, recommendations, and remediation actions.
- History of supporting control testing, audit coordination, and compliance validation activities.
- Direct involvement with third-party risk review, vendor assessment support, or related due diligence functions.
- Familiarity with issue remediation tracking, exception management, and reporting processes.
- Advanced analytical, organizational, reporting, and documentation skills.
- Excellent written and verbal communication skills with the ability to work effectively with technical and non-technical stakeholders.
- Ability to manage multiple priorities, maintain detailed records, and work independently with limited supervision.
- Department of Energy's regulation 10 CFR 810 is required
- Working knowledge of cybersecurity frameworks and control standards such as NIST CSF, NIST SP 800-53, ISO 27001, and CIS Controls.
- Cybersecurity certification such as Security+, CISSP, CISA
- This position falls under the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) and requires NERC CIP background investigation prior to start.
Some positions at PSEG require access to information covered by the Department of Energy's regulation 10 CFR 810 (Part 810). If applicable, the successful applicant must prove they are: (1) a citizen or national of the USA; OR (2) a lawful permanent resident of the United States (Non-Conditional Permanent I-551 / Green Card / Permanent Resident Card holder); OR (3) a citizen, national, or permanent resident of a "Generally Authorized" destination on the attached list and not also a citizen, national, permanent resident of any country not listed; OR (4) a "Protected Individual" under the Immigration and Naturalization Act (8 U.S.C 1324b(a)(3)). As an employee of PSEG Long Island, you should be aware that during storm/outage restoration efforts, you may be required to perform functions different from normal operations and work extended hours beyond your regular work schedule. You may also be required to work on premise or in an alternate location as directed by the company. For all roles, PSEGLI's drug and alcohol testing program includes pre-employment testing, testing for cause, and post-incident/accident testing.
Employees who are hired or transfer into a federally regulated role (including positions covered by USDOT, PHMSA, or NRC regulations) are subject to random drug and alcohol testing, inclusive of marijuana. Although numerous states throughout the country have legalized marijuana/cannabis products recreationally and medically, the use of these products are prohibited for employees in federally regulated roles. Please note that the use of CBD products may result in a positive drug test for THC/Marijuana and such use is not a legitimate medical explanation for a positive result. If you are a current PSEG employee and offered an opportunity with PSEG Long Island, you will be treated as a new hire. Please note that as a new hire to the Long Island subsidiary, your benefits will change and generally will be consistent with other similarly situated PSEG Long Island new hires. Similarly, for PSEG Long Island employees who accept job opportunities with PSEG or any of its subsidiaries (other than PSEG Long Island), their benefits will change and generally be consistent with other similarly situated new hires of that company.
PSEGLI is an equal opportunity employer, dedicated to a policy of non-discrimination in employment, including the hiring process, based on any legally protected characteristic. Legally protected characteristics include race, color, religion, national origin, sex, age, marital status, sexual orientation, disability or veteran status or any other characteristic protected by federal, state, or local law in locations where PSEG employs individuals.
PSEGLI is committed to providing reasonable accommodations to individuals with disabilities. If you have a disability and need assistance applying for a position, please call View phone number on click.appcast.io or email View email address on click.appcast.io.
If you need to request a reasonable accommodation to perform the essential functions of the job, email View email address on click.appcast.io. Any information provided regarding a disability will be kept strictly confidential and will not be shared with anyone involved in making a hiring decision. ADDITIONAL EEO INFORMATION (Click link below)
Know your Rights: Workplace Discrimination is Illegal
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Cyber Security GRC Analyst in Old Bethpage, NY vacancy
$93.6k - $148.2k
...and documentation. The Cybersecurity GRC Analyst works closely with IT, Internal Audit, Compliance... ...party risk review activities, including security questionnaires, documentation review,... ...who have 8 years of experience in cyber security governance risk and compliance...SuggestedPermanent employmentLocal areaFlexible hours$93.6k - $148.2k
...This position is a hands-on Identity and Access Management (IAM) analyst focused on Privileged Access Management (PAM) responsible for... ...privileged access risks and contribute to the implementation of security controls and PAM best practices. Participate in security...SuggestedPermanent employmentLocal areaFlexible hours$67.2k - $106.4k
...position. Job Summary: Working with the SAP Security team, you will deliver SAP Security... ...ECC, CRM, Business Warehouse, NetWeaver, GRC and other SAP based applications. This includes... ...Management, Legal, Safety and Security, Cyber Security and Law Enforcement agencies to...SuggestedWork experience placementFlexible hours$102.17k
...delivers value and impact to public sector clients across the country. Job Description Join the Trinnex Security Team as a Senior Cyber Security Analyst, where you will operate at the intersection of cybersecurity and DevSecOps to protect critical software systems...SuggestedWork experience placementH1b$129.3k - $193.9k
...to missions. In rapidly changing global security environments, Northrop Grumman brings informed... ...a Senior Principal Computer Systems Analyst to support information system lifecycle activities... ..., project managers, end users, and IT/Cyber management. Analyze and make...SuggestedFull timeRemote workRelocation packageFlexible hoursShift workWeekend work- ...compensation or benefits.Status: Full Time RegularShift: DAY SHIFTDepartment: Information ServicesPosition SummarySummary:The Applications Analyst III, Business Apps is accountable for supporting technology solutions of the hospital’s various financial and related information...Full time
- A leading energy company is seeking an SAP Security support professional to manage security applications across multiple SAP environments. You will ensure compliance with security guidelines, advocate for standard solutions, and maintain user security management. Ideal...Flexible hours
- ...transformation projects Lead in designing, specifying and selecting information system solutions, considering functionality, data, security, integration, infrastructure and performance. Excellent communication skills with ability to explain technical concepts to lay...
$82.6k - $162.8k
Position Summary Join our Deloitte Cyber team to deliver powerful solutions to help our clients navigate the ever-changing threat... ...resilience, grow with confidence, and proactively manage to secure success. Identity security market is undergoing a fundamental transformation...Local areaVisa sponsorship$32 per hour
SGS is the global leader and innovator in inspection, verification, testing and certification services. Founded in 1878, SGS is recognized as the global benchmark in quality and integrity. With over 97,000 employees in 130 countries and operating a network of more than...Hourly payLocal areaImmediate start$65.4k - $116.2k
...Job Summary Working with the SAP Security team, you will deliver SAP Security application... ...ECC, CRM, Business Warehouse, NetWeaver, GRC and other SAP based applications. This... ...Management, Legal, Safety and Security, Cyber Security and Law Enforcement agencies to...Permanent employmentLocal areaFlexible hours$82.6k - $162.8k
...of cybersecurity, data, and artificial intelligence, Deloitte’s Cyber Defense & Resilience team offers the scale, complexity, and... ...In this role, you will support organizations as they modernize security operations through advanced analytics, cyber data engineering,...Local areaVisa sponsorship$105.4k - $207.8k
Position Summary Join Deloitte’s Cyber practice as a Cyber SecOps Senior Consultant... ...landscape through scalable, resilient security operations solutions. In this hands-on role... ...with security operations center analysts and threat detection engineers to prioritize...Local areaVisa sponsorship$97.61k - $188.38k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.... ...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 10/31/2026Work you’ll...Local areaVisa sponsorship- Role, Inc. in Plainview, New York is looking for an Incident Investigator to ensure people supported are free from abuse and neglect by conducting investigations, ensuring compliance with agency policies, and promoting cultural awareness. The ideal candidate will have ...
$134.5k - $265.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.... ...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll...Local areaVisa sponsorship$155.6k - $306.8k
Position Summary As an Engineering Manager in Deloitte Cyber’s Digital Trust & Privacy practice, you will help clients solve complex identity, access, and data protection challenges through AI-enabled engineering solutions. This role sits at the intersection of...Local areaVisa sponsorship- ...Regulatory Affairs Analyst When a group of families came together in 1957 to find services for their children with developmental disabilities, ACLD was born. Today, we are a leading not-for-profit agency employing 1200+ staff and providing over 70 program sites in...Work at officeFlexible hoursWeekend workAfternoon shift
- ...Vulnerability Management process, report SLA adherence status and managing progress throughout the lifecycle. Collaborate with cyber security team to manage risks related to open vulnerabilities. Escalates unresolved vulnerabilities in a timely manner and close any...Permanent employmentWork experience placementFlexible hours
- Company DescriptionSonsoft , Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. Sonsoft Inc. is growing at a steady pace specializing in the fields of Software Development, Software Consultancy and Information Technology Enabled...Permanent employmentFull timeH1b
$141.92k - $212.89k
...Regulatory Authority) is the largest independent regulator of securities firms doing business in the United States. Our mission is to protect... ...the financial sector? As a Senior Principal Risk Specialist, Cyber Engagements, you'll play a pivotal role in strengthening the...Full timeTemporary workFor contractorsFor subcontractorLocal areaImmediate start- Position Summary Deloitte’s Cyber team helps clients address evolving cybersecurity... ...You will design, implement, and optimize secure, outcome-focused solutions while... ...Collaborating with security operations center (SOC) analysts and threat detection engineers to...Local area
$107.71k - $161.56k
...and maintaining market integrity. As a Senior Risk Monitoring Analyst, you'll work at the forefront of financial regulatory oversight... ...as Fraud and Deception, Money Laundering, or Market RiskFINRA Securities Industry Essentials (SIE) certification, or an acceptable...Full timeTemporary workFor contractorsFor subcontractorLocal areaImmediate start- ...focused role, not a pure hands-on engineering position. The consultant will act as a trusted partner, identifying risks, performing security assessments, and delivering actionable recommendations to modernize and secure the County's IT environment. The ideal...Long term contractWork at officeRemote work
$90k - $98k
...Global Cybersecurity IAM Analyst This role is HYBRID 3 days a week on-site at any UL Office in the US or if not near a local UL office... ...identity and access management (IAM) solutions to ensure the security and integrity of our organization's digital assets. Working...Full timeWork at officeLocal areaRemote work3 days per week- ...Application Support Analyst * This is a hybrid role* The Opportunity The KWI Support team is opening a new opportunity within our Application Support division. As an Application Support Analyst, you will be responsible for supporting our clients as they...Work at officeRemote work
$115.8k - $202.7k
...technology deliverables by contributing to and communication of standards and best practices for development, quality assurance, security, and service on-boarding Keep current with industry trends (including solution architecture frameworks and patterns, emerging...Minimum wageLocal areaRemote workNight shift$31.93 - $38.32 per hour
...all begins with two things: hiring incredible people and giving them a great place to work. What You’ll Do The BSA/AML Case Analyst is responsible for conducting and dispositioning mid-risk and continuation case investigations using a risk-based approach within...Hourly payFor contractorsImmediate startRemote workFlexible hours- ...: Full Time Regular Shift: DAY SHIFT Department: Finance / General Acctng Position Summary Summary: The budget analyst assists the budgeting team in the preparation of the annual operating and capital budgets. Produces the census report and admits and...Full timeShift workDay shift
$120k - $140k
...understanding of designing, implementing, managing, and troubleshooting the organization’s network infrastructure. This role ensures secure, reliable, and high-performance connectivity across LAN, WAN, WLAN, cloud, and remote-access environments. Salary: $120,000-$140,00...Temporary workRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Security GRC Analyst. Be the first to apply!
Related searches

