Hiring.Camp

Senior Technology Policy and Compliance Consultant

Xcelenergy

·

Yesterday

Salary
$112k – $159k
Location
Denver HQ T3, United States of America · Minneapolis, MN, 55401
Type
Full-time
Department
IT
Seniority
Senior
Experience
8+ years
Education
Bachelor
Closing date
Today
Source
Workday

Description

Are you looking for an exciting job where you can put your skills and talents to work at a company you can feel proud to be a part of? Do you want a workplace that will challenge you and offer you opportunities to learn and grow?  A  position at Xcel Energy could be just what you’re looking for.

Position Summary


This position is responsible for providing project management (e.g., standard implementation plan), direction and leadership to the Technology and Security Services as it relates to Security and Regulatory Compliance and Service Policy. This will include providing policy and compliance guidance on new standards and technologies supporting agencies such as Department of Energy (e.g., Federal Energy Regulatory Commission (FERC), North American Electric Reliability Corporation (NERC)), Department of Homeland Security (e.g., Critical Gas Pipeline), Security and Exchange Commission (e.g., Sarbanes-Oxley), and Department of Commerce (e.g., National Institute of Standards and Technology (NIST)).

This role drives the development of enterprise security policies and standards, oversees governance operations, and ensures alignment with security and regulatory requirements and industry frameworks. Operating as a strategic advisor and subject matter expert, the consultant provides thought leadership across the business, influences decision making, and strengthens the organization’s control environment.


Direction of policy and standards program and coordination of the overall audit process for the regulators for Technology and Security Services. This effort will entail some project direction to establish and implement the updated standards, requirements and Company based policies process across the organization.

Key liaison with the Compliance Governance process for the Technology and Security Services business area as it relates to overall company compliance standard implementation (e.g. Sarbanes Oxley).

Communicate organizational vision, mission, key objectives and individual roles to others. Develop, model and inspire a strong commitment to employee safety, recognition, development and diversity in the workforce. Achieve employee satisfaction by providing a stimulating and rewarding work environment.


Governance Program Development 
Collaborate with cross functional teams to develop and implement new security policies and security standards, ensuring they incorporate applicable regulatory requirements and NIST based frameworks.

Interpret regulatory obligations and industry standards to determine their impact on the organization, translating complex requirements into clear, actionable policy and standard language.

Partner with subject matter experts to address new requirements, emerging risks, and evolving business needs, ensuring governance artifacts remain relevant, comprehensive, and aligned with best practices.

Evaluate the potential impact of new policies and standards across business areas and support stakeholders in understanding and adopting updated governance expectations.

Governance Program Operations

Lead the execution of the security governance program, including the full lifecycle management of security policies and security standards. Responsibilities include coordinating periodic reviews, updates, and approvals, as well as maintaining supporting processes such as mapping standards to applicable frameworks and regulations and ensuring required measures are captured and maintained.

Ensure enterprise security standards are accurately maintained within the eGRC platform to support downstream processes such as Issue Management, Exceptions, and Security Assurance (control testing).


Contribute to organizational continuous improvement efforts, promoting consistency, quality, and operational excellence across security governance and assurance functions. - Stay current on the evolving security landscape, including emerging threats, updates to security frameworks (e.g., NIST CSF and other relevant NIST publications), and changes to applicable regulations (e.g., NERC CIP, DHS TSA, SOX).

Governance Program Metrics and Reporting - Compile, review, and analyze security information to formulate recommendations, metrics, and reports for management review and decision making.

Governance Program Training and Awareness - Oversee the development, implementation, and maintenance of training, training materials, and events related to the ESS Governance Program. Mentor and develop staff in technical and functional subject areas.

Minimum Requirements

  • Bachelor's degree or equivalent experience and at least 8 years of experience in security and IT or OT related fields. 
  • Five years of experience in a GRC discipline. 
  • Five years of work in a Governance, Risk, Compliance (GRC) function in a highly regulated environment (e.g. Utilities) may substitute for up to 18 months experience. 
  • Proven success implementing security policies, standards, and/or controls. 
  • Ability to define strategy and translate it into actionable plans impact organizational change.
  • Ability to work across the organization, building relationships and influencing peers and management through establishing trust and credibility. 
  • Applies sound judgment and creativity to solve complex problems.
  • Ability to excel in a rapidly changing environment. 
  • Strong verbal and written communication skills; ability to drive discussions and influence decision making; strong presentation and reporting skills. 
  • Ability to communicate with and create documentation for technical and non-technical audiences. 


Preferred Requirements

  • Experience in one or more of the following areas: enterprise architecture, access controls, network administration, systems administration, SDLC / secure soft, encryption, asset management, identity and access management, IT or OT operations, security risk management. 
  • Certification in one or more of the following: CISSP, CISM, CISA, CRISC, Security+, CPP or PSP. 
  • Experience using a GRC tool (i.e. Archer). 
  • Knowledge of regulatory requirements and frameworks such as NERC CIP, DHS TSA, SOX, ISO, NIST, COBIT, or Cyber Security Framework (CSF).

As a leading combination electricity and natural gas energy company, Xcel Energy offers a comprehensive portfolio of energy-related products and services to 3.4 million electricity and 1.9 million natural gas customers across eight Western and Midwestern states. At Xcel Energy, we strive to be the preferred and trusted provider of the energy our customers need. If you’re ready to be a part of something big, we invite you to join our team.

All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Individuals with a disability who need an accommodation to apply please contact us at [email protected].

Non-Bargaining

The anticipated starting base pay for this position is: $112,200.00 to $159,400.00 per year

This position is eligible for the following benefits: Annual Incentive Program, Medical/Pharmacy Plan, Dental, Vision, Life Insurance, Dependent Care Reimbursement Account, Health Care Reimbursement Account, Health Savings Account (HSA) (if enrolled in eligible health plan), Limited-Purpose FSA (if enrolled in eligible health plan and HSA), Transportation Reimbursement Account, Short-term disability (STD), Long-term disability (LTD), Employee Assistance Program (EAP), Fitness Center Reimbursement (if enrolled in eligible health plan), Tuition reimbursement, Transit programs, Employee recognition program, Pension, 401(k) plan, Paid time off (PTO), Holidays, Volunteer Paid Time Off (VPTO), Parental Leave

Benefit plans are subject to change and Xcel Energy has the right to end, suspend, or amend any of its plans, at any time, in whole or in part.

In any materials you submit, you may redact or remove age-identifying information including but not limited to dates of school attendance and graduation.  You will not be penalized for redacting or removing this information.

Deadline to Apply: 08/30/26

EEO is the LawEEO is the Law Supplement | Pay Transparency Nondiscrimination | Equal Opportunity Policy (PDF) | Employee Rights (PDF)

All Xcel Energy employees and contractors share responsibility for protecting the company's information and systems by adhering to cybersecurity policies, standards, and best practices, recognizing that cybersecurity is everyone's responsibility.

 

ACCESSIBILITY STATEMENT

Xcel Energy endeavors to make https://www.xcelenergy.com/ accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact Xcel Energy Talent Acquisition at [email protected]. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.

Skills

CybersecuritySOXRisk ManagementComplianceProject ManagementCISSP

Similar Jobs

4

Senior Manager, AI and Technology Policy

National Retail Federation · Washington, DC

3 days ago

Senior Officer, AI Technology Policy

Gatesfoundation · Washington, DC, United States of America

1 month ago

Senior Officer, AI Technology Policy

Gatesfoundation · Washington, DC, United States of America

1 month ago

Senior Director - Government Relations, Emerging Technology & Corporate Policy

Honeywell · Washington, DC, United States, US

4 months ago