Governance, Risk, and Compliance (GRC) Analyst

Nebraska Public Power DistrictColumbus, OH
Onsite

About The Position

The Governance, Risk, & Assurance (GRA) Analyst is responsible for evaluating the security posture of software applications, vendors, and third‑party technologies to support the organization’s cyber risk management program. This role focuses on performing detailed software security assessments, managing third‑party cyber risk reviews, and ensuring that technology solutions entering the environment meet required security and compliance standards. The analyst conducts thorough evaluations of vendor security practices, analyzes application and infrastructure risks, collaborates with internal stakeholders across Enterprise Technolgy (ET) and business units, and provides clear recommendations to reduce cyber exposure. This position requires strong analytical capabilities, high attention to detail, and the ability to interpret complex cybersecurity information to support reliable and secure technology operations.

Requirements

  • Ability to work independently and in cooperation with others on multiple activities with flexibility to manage competing demands and changing priorities.
  • Excellent communication, interpersonal, and organizational skills.
  • Excellent analytical problem-solving skills.
  • Must be customer-service oriented and adaptable to ongoing change.
  • Strong attention to detail and the ability to analyze complex technical information with precision.
  • Foundational understanding of cybersecurity concepts, including vulnerabilities, secure design principles, and common control frameworks.
  • Working knowledge of network architecture and design principles, including segmentation, protocols, and data flow analysis.
  • Experience working in both IT and OT environments, with awareness of unique risks and constraints in operational/industrial systems.
  • Ability to read, interpret, and assess vendor documentation such as SOC 2, penetration test reports, security whitepapers, and architecture diagrams.
  • Familiarity with third‑party cyber risk management practices, vendor security questionnaires, and risk scoring methodologies.
  • Understanding of secure software lifecycle practices and typical application security requirements.
  • Strong written and verbal communication skills to clearly articulate risks, controls, and recommendations to technical and non‑technical audiences.
  • Incumbent may be required to satisfy any existing and future District security clearance or background check requirements for access to key NPPD locations and/or supporting sensitive business applications.
  • Obtain and maintain intermediate to advanced technical certification aligned with key business system platform(s) used at the District (for example, Systems, Applications and Products in Data Processing (SAP), Microsoft certifications, and security related best practices) as applicable.

Responsibilities

  • Perform detailed security assessments for new and existing software, including evaluation of architecture, data handling, authentication, logging, and vulnerability posture.
  • Lead third‑party cyber risk reviews, including analysis of vendor security questionnaires, vulnerability disclosures, and evidence of security controls.
  • Identify and document cybersecurity risks, mitigation steps, and recommendations in alignment with enterprise risk and third party cyber risk management processes.
  • Collaborate with cyber security, network, server, and application teams to validate security requirements and ensure proper integration of software and vendor solutions.
  • Assist in maintaining security artifacts such as risk registers, assessment documentation, and approval workflows for software and vendor evaluations.
  • Monitor changes in cyber threats and emerging risks that may impact software or third‑party environments.
  • Support continuous improvement of risk assessment processes, tools, and communication workflows across the GRA function.
  • Analyze, design, develop, configure, maintain, troubleshoot, and provide direction and support for complex systems, applications and databases in support of the District's computing environment.
  • Provide technical architecture recommendations and apply best practices in system design, development, and testing.
  • Collaborate with/advise/coach other ET/Corporate Security and business unit analysts to ensure understanding of business and technical work processes, tools, and best practices.
  • Evaluate, create, document, and test complex system-related interfaces and integration.
  • Maintains efficient and effective management of vendor contract service relationships pertaining to technical services.
  • Provide 24/7 system support, as needed.
  • Lead special task groups, trouble-shooting efforts, and integration and/or improvement project teams.
  • Lead the development and implementation of training and communications plans/materials.
  • Proven understanding of key NPPD business unit activities and successful application of ET/Corporate Security technical solution design, development, and responsive customer support and service.
  • Work closely with ET/Corporate Security management to oversee and lead resolution of complex technical challenges and new business system initiatives.
  • Accountable for other duties as assigned.

Benefits

  • medical and dental insurance
  • 401K retirement plan
  • paid holidays
  • paid vacation
  • paid medical
  • training opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service