Senior Security and Compliance Analyst

Xcel EnergyMinneapolis, MN
Hybrid

About The Position

As a Senior Security Governance and Controls Analyst, you will be responsible for contributing to the development and execution of the security governance and control program focused on security policies and standards, security controls assurance program, training and awareness, and metrics and reporting. Security controls assurance involves the development and evaluation of security controls, self-assessments, and spot-checks. You will partner across the security organization, as well as other business units, to facilitate the adoption of security controls. You will contribute to the organizational continuous improvement program, driving consistency and quality across the organization. In addition, you will be designated as a regulation security liaison, acting as the business area point of contact for managing, coordinating, or facilitating regulatory compliance operations within the business area.

Requirements

  • Bachelor's degree or equivalent experience and at least 4 years of experience in security and IT or OT related fields.
  • Three years of experience with control testing, security standards/policy implementation, security audits, or security risk management.
  • One year of working in a Governance, Risk & Compliance (GRC) function in a highly regulated environment (e.g. Utilities) may substitute for up to 18 months experience.
  • Self-starter; adaptable to change.
  • Ability to set and achieve personal and program goals, and to track performance against those goals.
  • Ability to work effectively across the organization, establishing positive working relationships, and building trust.
  • Applies sound judgment and creativity to solve complex problems.
  • Strong verbal and written communication skills.
  • Demonstrated ability to create documentation for technical and non-technical audiences.

Nice To Haves

  • Experience in one or more of the following areas: physical access controls, network administration, systems administration, SDLC / secure soft, encryption, asset management, identity and access management, IT or OT operations, security risk management.
  • Certification in one or more of the following: CISM, CISA, CRISC, CISSP, Security+, CPP or PSP.
  • Experience using a GRC tool (i.e. Archer).
  • Knowledge of regulatory requirements/frameworks such as PCI, NERC CIP, DHS TSA, SOX, HIPPA, ISO, NIST, COBIT, or Cyber Security Framework (CSF).

Responsibilities

  • Lead the development and implementation of the department's policy and compliance governance program and supporting procedures documentation.
  • Ensure security standard requirements are mapped to key regulations and frameworks.
  • Establish relationships and partner with industry and business unit subject matter experts to identify and document new requirements and supporting controls.
  • Maintain enterprise security standards in eGRC system to support downstream processes (i.e., Issue Management and Exceptions and Security Assurance (control testing)).
  • Contribute to the development and implementation of the compliance assurance program and supporting procedure documentation.
  • Lead the development and implementation of the CIP compliance management program and supporting procedure documentation.
  • Lead in the review and update cycles for security policies and security standards with respective owner and subject matter experts, including developing a review schedule and assigning responsibilities.
  • Lead in the development and evaluation of security controls, self-assessments, spot-checks, risk identification, process gaps, and process alignment.
  • Contribute to the organizational continuous improvement program, driving consistency and quality across the organization.
  • Stay current on relevant industry security threat landscape, changes in security frameworks (i.e., NIST CSF, other NIST as applicable), and in scope regulations (i.e., NERC CIP, DHS TSA, and SOX).
  • Compile and review output from security controls assessment program.
  • Work with leads to analyze information and formulate recommendations and reports for management review and decision making.
  • Contribute to the identification and management of security metrics and reporting for leadership and applicable business units.
  • Lead the development and implementation of the training and awareness of ESEM Governance program.
  • Develop and deliver training and awareness content to educate applicable business units about the ESEM governance program and security standards.
  • Other duties as assigned.

Benefits

  • Annual Incentive Program
  • Medical/Pharmacy Plan
  • Dental
  • Vision
  • Life Insurance
  • Dependent Care Reimbursement Account
  • Health Care Reimbursement Account
  • Health Savings Account (HSA) (if enrolled in eligible health plan)
  • Limited-Purpose FSA (if enrolled in eligible health plan and HSA)
  • Transportation Reimbursement Account
  • Short-term disability (STD)
  • Long-term disability (LTD)
  • Employee Assistance Program (EAP)
  • Fitness Center Reimbursement (if enrolled in eligible health plan)
  • Tuition reimbursement
  • Transit programs
  • Employee recognition program
  • Pension
  • 401(k) plan
  • Paid time off (PTO)
  • Holidays
  • Volunteer Paid Time Off (VPTO)
  • Parental Leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service