Summary of Purpose: The Senior IT Security Analyst serves as INPO's primary cybersecurity risk authority, providing oversight and guidance to protect the organization's mission-critical operations in the nuclear power industry. The position, a combination of strategic and hands-on, is responsible for managing and maturing INPO's cybersecurity strategy and program to protect the organization's digital assets and ensure alignment with enterprise risk management objectives, by translating complex technical and regulatory risks into clear actions that reduce risk to INPO. Essential Functions Matures INPO's cybersecurity program, aligning governance, controls, and reporting with NIST Cybersecurity Framework 2.0 and NIST AI Risk Management Framework by setting the standard for security at INPO Refines and maintains IT and security policies, standards, and procedures that operationalize DOE/DOC 810, NRC, and ISO requirements within INPO's compliance environment Maintains the IT risk register and applies assessment and maturity methods to drive consistent identification, analysis, and mitigation tracking across IT Ensures IT integrates risk considerations into technology initiatives, architecture decisions, and change management processes Translates technical risks into executive-level insights that inform prioritization, investment and strategic decisions for the CFO, IT Director, and Senior Leadership Team Produces monthly metrics and quarterly reports on risk posture, trends, maturity, and recommended actions Oversees third-party risk across SaaS, service providers, and supply chain to ensure external relationships meet risk tolerance and contractual/compliance obligations Coordinates IT audits, regulatory examinations, security awareness training, penetration testing, and independent assessments; drives timely remediation and continuous compliance Applies security intelligence from Security Operations Center (SOC)/Managed Detection and Response (MDR) vendors to inform actions, assessments and decision-making Monitors emerging cyber and AI risks, regulatory changes, and industry best practices for nuclear and critical infrastructure, updates strategy accordingly Performs hands-on configuration, monitoring and system administration of enterprise vulnerability management tools (e.g. Qualys) and Governance, Risk and Compliance (GRC) platforms (e.g. ServiceNow GRC, X-Analytics) Performs other duties as assigned
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
High school or GED