Senior GRC Risk Analyst

Midcontinent Independent System Operator (MISO)Eagan, MN
$105,000 - $130,000Onsite

About The Position

Join MISO as a Senior GRC Risk Analyst, where you will play a key role in safeguarding the power grid by identifying, assessing, and mitigating cybersecurity risks. In this role, you'll be central to MISO’s risk management efforts. You will identify and track risks, support and monitor mitigation activities, and assess third‑party risk. Your work will form the risk‑based foundation for broader cybersecurity functions across the organization. This position is highly cross‑functional and collaborative, giving you the opportunity to work closely with teams across MISO to strengthen and protect critical systems.

Requirements

  • Bachelor's degree in Information Security, Cybersecurity, Risk Management, or a related field.
  • 5+ years experience in cybersecurity risk management, or related fields.
  • Strong background in vendor risk assessments and risk management methodologies.
  • Demonstrated strong strategic thinking and ownership by independently prioritizing work, addressing underlying problems, producing detail‑oriented deliverables, and understanding how daily actions align to broader organizational goals.
  • Strong knowledge of risk management frameworks, such as: NIST Cybersecurity Framework (CSF), NIST 800-37 Control Framework; NIST 800-53

Nice To Haves

  • Advanced degree preferred.
  • Certifications that are a plus: CRISC, CISSP, CISA, CISM

Responsibilities

  • Recommend and support risk mitigation strategies to address identified risks.
  • Work collaboratively across teams to proactively identify, evaluate, and mitigate cybersecurity risks.
  • Ensure risk management activities align with industry best practices, including NIST 800‑37.
  • Serve as a cybersecurity Subject Matter Expert (SME), advising business and technology teams on identifying, prioritizing, and communicating risks.
  • Build, maintain, and continuously improve the organization’s third‑party risk management framework.
  • Evaluate third‑party vendors’ cybersecurity controls, practices, and overall risk posture through detailed assessments.
  • Identify and assess cybersecurity risks associated with vendor and partner relationships.
  • Work closely with procurement, legal, and compliance teams to ensure vendor contracts include appropriate and enforceable security requirements.
  • Provide guidance, consultation, and training to internal stakeholders on effective risk management and mitigation approaches.

Benefits

  • 401k
  • vacation
  • sick and safe time
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service