Hiring.Camp

Senior Security and Compliance Analyst

Xcelenergy

·

Yesterday

Salary
$85k – $121k
Location
414 Nicollet Mall, United States of America · Denver, CO, 80205 · Amarillo, TX, 79101
Workplace
Hybrid, Onsite
Type
Full-time
Department
Legal
Seniority
Senior
Experience
4+ years
Education
Bachelor
Closing date
Today
Source
Workday

Description

Xcel Energy (NASDAQ: XEL) is a leading energy provider and Fortune 500 company, dedicated to serving millions of electricity and natural gas customers across eight states: Minnesota, Colorado, Wisconsin, Michigan, North Dakota, South Dakota, New Mexico and Texas. We make energy work better for our customers, helping them thrive every day. That means always raising the bar - delivering better service and providing more reliable, resilient, and sustainable energy. 

Xcel Energy is a place where you’ll have opportunities to grow, expand your skills, and help lead the clean energy transition. We offer meaningful rewards, recognition, and support to help you build your career and make an impact - both on the job and beyond. Most importantly, it means you’ll be joining a company that knows employees are the driving force behind its success and is committed to helping you be your best.

 

Xcel Energy supports a hybrid work model to enable collaboration and flexibility. Many roles are expected to work onsite three days per week (Tuesday–Thursday); however, work location expectations vary based on role, team, and business needs.

 

Position Summary


As a Senior Security Governance and Controls Analyst, you will be responsible for contributing to the develop of and the execution of the security governance and control program focused on security policies and standards, security controls assurance program, training and awareness, and metrics and reporting. Security controls assurance involves the development and evaluation of security controls, self-assessments, and spot-checks. Partners across the security organization, as well as other business units, to facilitate the adoption of security controls. Contributes to the organizational continuous improvement program, driving consistency and quality across the organization.  In addition, designated as a regulation security liaison.  A liaison is the business area point of contact for managing, coordinating or facilitating regulatory compliance operations within the business area.

Essential Responsibilities

  • PROGRAM DEVELOPMENT & MAINTENANCE: Lead the development and implementation of the department's policy and compliance governance program and supporting procedures documentation. Ensure security standard requirements are mapped to key regulations and frameworks.  Establish relationships and partner with industry and business unit subject matter experts to identify and document new requirements and supporting controls. Maintain enterprise security standards in eGRC system to support downstream processes (i.e., Issue Management and Exceptions and Security Assurance (control testing)). Contribute to the development and implementation of the compliance assurance program and supporting procedure documentation. Lead the development and implementation of the CIP compliance management program and supporting procedure documentation.
  • PROGRAM EXECUTION (OPERATIONS): Significant contributor to the execution of security governance program focused on security policies and security standards lifecycle.  Lead in the review and update cycles for security policies and security standards with respective owner and subject matter experts. This includes developing a review schedule, assigning responsibilities within team and service teams. Lead in the development and evaluation of security controls, self-assessments, spot-checks, risk identification, process gaps, and process alignment. Contributes to the organizational continuous improvement program, driving consistency and quality across the organization.  Stay current on relevant industry security threat landscape, changes in security frameworks (i.e., NIST CSF, other NIST as applicable), and in scope regulations (i.e., NERC CIP, DHS TSA, and SOX).
  • PROGRAM METRICS & REPORTING: Compile and review output from security controls assessment program. Work with leads to analyze information and formulate recommendations and reports for management review and decision making. Contribute to the identification and management of security metrics and reporting for leadership and applicable business units.
  • PROGRAM TRAINING AND AWARENESS: Lead the development and implementation of the training and awareness of ESEM Governance program. Develop and deliver training and awareness content to educate applicable business units about the ESEM governance program and security standards.
  • Other duties as assigned.

Minimum Requirements

  • Bachelor's degree or equivalent experience and at least 4 years of experience in security and IT or OT related fields. 
  • Three years of experience with control testing, security standards/policy implementation, security audits, or security risk management. 
  • One year of working in a Governance, Risk & Compliance (GRC) function in a highly regulated environment (e.g. Utilities) may substitute for up to 18 months experience. 
  • Self-starter; adaptable to change. 
  • Ability to set and achieve personal and program goals, and to track performance against those goals. 
  • Ability to work effectively across the organization, establishing positive working relationships, and building trust. 
  • Applies sound judgment and creativity to solve complex problems. Strong verbal and written communication skills. 
  • Demonstrated ability to create documentation for technical and non-technical audiences.

Preferred Requirements

  • Experience in one or more of the following areas: physical access controls, network administration, systems administration, SDLC / secure soft, encryption, asset management, identity and access management, IT or OT operations, security risk management. 
  • Certification in one or more of the following: CISM, CISA, CRISC, CISSP, Security+, CPP or PSP. 
  • Experience using a GRC tool (i.e. Archer).
  • Knowledge of regulatory requirements/frameworks such as PCI, NERC CIP, DHS TSA, SOX, HIPPA, ISO, NIST, COBIT, or Cyber Security Framework (CSF).

 

Our culture is grounded in shared values and employee commitments that guide how we work, support one another, and grow together.


Our Values

Connected, Committed, Trustworthy, Safe


Our Employee Commitments

  • Work that makes a difference
  • A team you can count of
  • Opportunities to grow
  • Rewards that help you thrive

 

Xcel Energy provides job applicants reasonable accommodations for disabilities throughout the application process. If you are in need of an accommodation to complete the application process, now or at any time in the future, please complete the Applicant Accommodation Request Form


Non-Bargaining

 

The anticipated starting base pay for this position is: $84,900.00 to $120,566.00 per year

 

This position is eligible for the following benefits: Annual Incentive Program, Medical/Pharmacy Plan, Dental, Vision, Life Insurance, Dependent Care Reimbursement Account, Health Care Reimbursement Account, Health Savings Account (HSA) (if enrolled in eligible health plan), Limited-Purpose FSA (if enrolled in eligible health plan and HSA), Transportation Reimbursement Account, Short-term disability (STD), Long-term disability (LTD), Employee Assistance Program (EAP), Fitness Center Reimbursement (if enrolled in eligible health plan), Tuition reimbursement, Transit programs, Employee recognition program, Pension, 401(k) plan, Paid time off (PTO), Holidays, Volunteer Paid Time Off (VPTO), Parental Leave

 

Benefit plans are subject to change and Xcel Energy has the right to end, suspend, or amend any of its plans, at any time, in whole or in part.

In any materials you submit, you may redact or remove age-identifying information including but not limited to dates of school attendance and graduation.  You will not be penalized for redacting or removing this information.

 

Deadline to Apply: 10/01/26

 

EEO is the Law (PDF) | Equal Opportunity Statement (PDF) | Employee Rights (PDF)


 

All Xcel Energy employees and contractors share responsibility for protecting the company's information and systems by adhering to cybersecurity policies, standards, and best practices, recognizing that cybersecurity is everyone's responsibility.


 

Accessibility Statement

Xcel Energy endeavors to make https://www.xcelenergy.com and https://jobs.xcelenergy.com accessible to any and all users. If you are in need of an accommodation to complete the application process, now or at any time in the future, please complete the Applicant Accommodation Request Form. For any other application related questions, including application follow-ups or technical issues, please use our Recruiting Assistance, Electra, for assistance. Electra can be found in the lower right-hand corner of our Xcel Energy Careers site.

Skills

CybersecuritySOXRisk ManagementComplianceCISSP

Similar Jobs

30

Sr. Manager, Security Risk, Assurance and Trust

SiTime · Santa Clara, CA

Today

IT Senior Expert Network and Security (m/w/x)

OTTO FUCHS KG · Meinerzhagen, NRW, Germany · Hybrid

Today

Senior Security Engineer, CPU and Platform Security Validation

Sifive · Hsinchu, Taiwan

Yesterday

Senior Infrastructure and Cloud Security Engineer (m/f/d)

ICE · London +1

Yesterday

Senior Consultant Cyber Security – Applied Cryptography and Digital Trust

Business Assurance · Oslo, Norway

Yesterday

Senior Security Engineer (R&D and Secure Systems Engineering)

Nortal · , EE

2 days ago

Senior Information and Cyber Security Officer

Scottish Government Recruitment · Glasgow, United Kingdom, GB · Hybrid

2 days ago

SENIOR MANAGER, SECURITY AND DISBURSEMENT - Montreal, St. Laurent, Laval

Bdc · Montreal, Canada +2 · Hybrid

3 days ago

Senior Field Security Investigator - Volusia, Flagler, Seminole, Lake and Orange County, Florida

Geico · FL Remote Zone 2, United States of America · Remote

4 days ago

Sr. Product Marketing Manager - Tech, Security and Identity PMM

Amazon

5 days ago

Senior Financial Analyst, AWS Search, Security, and Observability

Amazon

5 days ago

Sr. Technical Program Manager - Security Products and Solutions, AWS Infrastructure Security

Amazon

5 days ago

Sr. Technical Program Manager, Safety and Security

Stoneridge Careers · Novi, United States of America

5 days ago

Senior Cyber Security Engineer – Detection and Response

Blackmore_Career_Site_New · Surry Hills, New South Wales, Australia

1 week ago

Senior Information Security Engineer – SIEM and Detection

Esswd · Philadelphia, United States of America +2 · Hybrid

1 week ago

Senior Information Security Analyst, Third-Party Security and Data Breach Expert (T & I) (Telework/Hybrid)

Cbcrc · Montreal - MRC (Papineau) (36.25), Canada +1 · Remote, Hybrid, Onsite

1 week ago

Senior Networking and Security Sales Specialist

Nttlimited · North Carolina, United States of America +1 · Remote

1 week ago

Senior Lead Pre/Post Silicon Validation Engineer - SoC Security and access control Expertise

Qualcomm · Bengaluru, KA,IN, IN

1 week ago

Messaging, Cloud, and Data Security I Senior Analyst I

Vertiv · Mandaluyong City, Philippines

1 week ago

Senior Platform Security Engineer – Device Trust, Attestation and Secure Browser

Nvidia · Santa Clara, CA,US, US

1 week ago

Senior Platform Security Engineer – Device Trust, Attestation and Secure Browser

Nvidia · US, CA, Santa Clara, United States of America

1 week ago

Principal / Senior Information Security Consultant (Risk Management, Security Architecture and Production Security)

Sony · Sony SGP HQ, Perennial Business City, Singapore

1 week ago

Senior Security Engineer, Cloud and Infrastructure Security

Ww · United States - Remote · Remote

1 week ago

Senior Infrastructure Engineer - Infrastructure Security and Core Services

Nvidia · US, CA, Santa Clara, United States of America

1 week ago

Senior Infrastructure Engineer - Infrastructure Security and Core Services

Nvidia · Santa Clara, CA,US, US

1 week ago

Senior Functional Consultant - HCM and Security - Workday Advisory Services

Workday · IND.Pune, India +1

1 week ago

Senior Security Engineer IS - Identity and Access Management, Remote

Providence Health & Services · Renton, WA, United States, US · Remote

2 weeks ago

Sr. Staff Product Designer, Security and Risk Workflow

ServiceNow · Santa Clara, CALIFORNIA, United States · Hybrid

2 weeks ago

Senior Security & Audit Manager (German and English Speaking) (REF5640I)

Deutsche Telekom IT Solutions · Budapest Debrecen Pécs Szeged, Hungary · Hybrid

2 weeks ago

Senior Security Engineer - Detection and Response

MercadoLibre · Medellín, Antioquia,CO, CO

2 weeks ago