{"21441052":{"jobPath":"/jobs/21441052/audit-director-university-staff-professional-3","source":"naylor","job":"21441052","jobTitle":"Audit Director (University Staff Professional 3)"},"21443370":{"jobPath":"/jobs/21443370/risk-manager-of-aviation-capital-portfolio","source":"naylor","job":"21443370","jobTitle":"Risk Manager of Aviation Capital Portfolio"},"21445693":{"jobPath":"/jobs/21445693/it-support-analyst-1","source":"naylor","job":"21445693","jobTitle":"IT Support Analyst 1"},"21445572":{"jobPath":"/jobs/21445572/information-governance-coordinator-hybrid","source":"naylor","job":"21445572","jobTitle":"Information Governance Coordinator - Hybrid"},"21443408":{"jobPath":"/jobs/21443408/risk-manager-of-aviation-capital-portfolio","source":"naylor","job":"21443408","jobTitle":"Risk Manager of Aviation Capital Portfolio"},"21443228":{"jobPath":"/jobs/21443228/director-of-security-safety","source":"naylor","job":"21443228","jobTitle":"Director of Security & Safety"},"21443229":{"jobPath":"/jobs/21443229/director-legislative-government-relations","source":"naylor","job":"21443229","jobTitle":"Director, Legislative & Government Relations"},"21441641":{"jobPath":"/jobs/21441641/merit-soc-analyst","source":"naylor","job":"21441641","jobTitle":"Merit SOC Analyst"},"21442531":{"jobPath":"/jobs/21442531/senior-research-analyst-center-for-security-and-emerging-technology-walsh-school-of-foreign-service-georgetown-university","source":"naylor","job":"21442531","jobTitle":"Senior Research Analyst - Center for Security and Emerging Technology - Walsh School of Foreign Service - Georgetown University"},"21440633":{"jobPath":"/jobs/21440633/administrative-coordinator-student-government-association-assist-vp-office-of-student-affairs","source":"naylor","job":"21440633","jobTitle":"Administrative Coordinator- Student Government Association & Assist. VP Office of Student Affairs"},"21443188":{"jobPath":"/jobs/21443188/chief-audit-executive","source":"naylor","job":"21443188","jobTitle":"Chief Audit Executive "},"21442530":{"jobPath":"/jobs/21442530/senior-research-analyst-center-for-security-and-emerging-technology-walsh-school-of-foreign-service-georgetown-university","source":"naylor","job":"21442530","jobTitle":"Senior Research Analyst - Center for Security and Emerging Technology - Walsh School of Foreign Service - Georgetown University"},"21441045":{"jobPath":"/jobs/21441045/outreach-focused-assistant-professor-in-community-nutrition-and-food-security","source":"naylor","job":"21441045","jobTitle":"Outreach-Focused Assistant Professor in Community Nutrition and Food Security"},"21446199":{"jobPath":"/jobs/21446199/director-of-treasury-risk","source":"naylor","job":"21446199","jobTitle":"Director of Treasury & Risk"},"21443461":{"jobPath":"/jobs/21443461/executive-director-of-enterprise-risk","source":"naylor","job":"21443461","jobTitle":"Executive Director of Enterprise Risk"},"21445580":{"jobPath":"/jobs/21445580/information-governance-coordinator-admin-info-technology-services","source":"naylor","job":"21445580","jobTitle":"Information Governance Coordinator - Admin Info Technology Services"},"21442529":{"jobPath":"/jobs/21442529/senior-data-research-analyst-center-for-security-and-emerging-technology-cset-walsh-school-of-foreign-service-sfs-georgetown-university","source":"naylor","job":"21442529","jobTitle":"Senior Data Research Analyst - Center for Security and Emerging Technology (CSET), Walsh School of Foreign Service (SFS) - Georgetown University"},"21442548":{"jobPath":"/jobs/21442548/information-technology-architect","source":"naylor","job":"21442548","jobTitle":"Information Technology Architect"},"21442604":{"jobPath":"/jobs/21442604/national-security-research-institute-executive-director","source":"naylor","job":"21442604","jobTitle":"National Security Research Institute Executive Director"},"21441673":{"jobPath":"/jobs/21441673/senior-engineer-it-privacy-compliance-program-lead","source":"naylor","job":"21441673","jobTitle":"Senior Engineer, IT Privacy Compliance Program Lead"},"21440822":{"jobPath":"/jobs/21440822/senior-manager-audit-and-business-continuity","source":"naylor","job":"21440822","jobTitle":"Senior Manager, Audit and Business Continuity"},"21442521":{"jobPath":"/jobs/21442521/senior-research-analyst-center-for-security-and-emerging-technology-cset-walsh-school-of-foreign-service-sfs-georgetown-university","source":"naylor","job":"21442521","jobTitle":"Senior Research Analyst, Center for Security and Emerging Technology (CSET), Walsh School of Foreign Service (SFS) - Georgetown University"},"21442522":{"jobPath":"/jobs/21442522/senior-research-analyst-center-for-security-and-emerging-technology-walsh-school-of-foreign-service-georgetown-university","source":"naylor","job":"21442522","jobTitle":"Senior Research Analyst - Center for Security and Emerging Technology - Walsh School of Foreign Service - Georgetown University"},"21446503":{"jobPath":"/jobs/21446503/airport-security-coordinator","source":"naylor","job":"21446503","jobTitle":"AIRPORT SECURITY COORDINATOR"},"21441677":{"jobPath":"/jobs/21441677/senior-engineer-information-security","source":"naylor","job":"21441677","jobTitle":"Senior Engineer, Information Security"}}
About Us Headquartered in Indianapolis, Indiana, Wabash Valley Power is a not-for-profit electric cooperative and wholesale provider of reliable, affordable electricity to our 21 electric distribution member cooperatives. These cooperatives in turn serve more than 280,000 homes, businesses, and farms in Indiana and Illinois.
As a not-for-profit co-op, we do things a bit differently—and that’s the point. Because we aren’t influenced by shareholders, we make our decisions with our members in mind. That means we value things like teamwork, and putting families first. It also means a business model that’s designed for stability and growth. It’s a Deliberately Different approach to the energy industry, and that’s great news for the people who count on us.
What You'll Get We believe what benefits our employees benefits our company. That’s why we put employees first—your health, your family, and your development. These aren’t just slogans: We offer continuing education, flex time, health benefits, a 401(k) match and pension plan, and much more. Here are just a few of the things that make our company culture unique:
• No Sweat - We offer a wellness program that includes a payroll credit for medical insurance, an on-site fitness center for your convenience and extra vacation days for participating. We’ll even throw in a fitness device reimbursement to keep you on track! • Flex Time - Our flexible schedule means you can work in your appointments or family events and maintain a comfortable work-life balance. • Stay in School - We value employees who have a desire to learn, so we provide funds for continuing education. We also offer in-house training and ongoing development through our internal GROW program. • Keep it Casual - When you work for us, you work in comfort. Blue jeans are the norm in our office, and we make them look good! • Work Hard, Play Hard - We reward our employees with generous vacation time, to the tune of up to five weeks off a year. Even our new employees receive credit for prior work experience.
Job Description
The Governance, Risk, and Compliance (GRC) IT Analyst is responsible for ensuring the cooperative's information technology systems adhere to regulatory requirements, industry standards, and internal policies. This role focuses on maintaining compliance with NERC CIP standards, mitigating cybersecurity risks, implementing Zero Trust principles, and supporting governance frameworks to protect critical infrastructure. The GRC IT Analyst collaborates with IT, security, legal, and operational teams to develop policies, perform risk assessments, oversee audits, and strengthen internal controls.
Essential Duties and Responsibilities:
Governance & Compliance
Ensure IT and cybersecurity programs comply with NERC CIP, FERC, and other relevant regulations.
Develop, implement, and maintain IT governance frameworks, policies, and procedures aligned with regulatory requirements.
Serve as a key resource in internal and external audits, coordinating responses, evidence collection, and remediation efforts.
Stay updated on regulatory changes and industry best practices, advising management on necessary adjustments.
Assist in training employees on compliance responsibilities and security awareness.
Risk Management & Internal Control Reviews
Conduct IT risk assessments to identify and evaluate vulnerabilities in IT systems and processes.
Perform internal control reviews to assess the effectiveness of IT security controls, access management, and compliance measures.
Maintain the cooperative’s IT Risk Register and track mitigation strategies.
Work with IT and security teams to implement risk management strategies and security controls.
Support incident response planning and contribute to post-incident investigations.
Zero Trust Implementation & Security Control Assurance
Lead initiatives to design and implement a Zero Trust Architecture (ZTA) for the cooperative’s IT environment.
Establish least privilege access controls, identity verification measures, and micro-segmentation strategies.
Collaborate with IT and networking teams to enforce continuous monitoring and authentication policies.
Ensure Zero Trust principles align with NERC CIP compliance requirements and cybersecurity best practices.
Monitor IT controls and security frameworks (e.g., NIST CSF, CIS Controls).
Evaluate third-party vendors for compliance with cybersecurity and regulatory requirements.
Perform security assessments of IT systems, applications, and network infrastructure.
Participate in business continuity and disaster recovery planning.
Collaboration & Reporting
Generate reports on compliance status, risk assessments, and security metrics for leadership and regulators.
Work closely with IT, operations, and legal teams to ensure alignment between business objectives and compliance requirements.
Serve as a liaison between the cooperative and regulatory bodies during audits and compliance reviews.
Qualifications
Required:
Bachelor’s degree in Information Technology, Cybersecurity, Business, or a related field.
5+ years of experience in IT governance, compliance, or risk management.
Knowledge of NERC CIP standards and regulatory requirements in the electric utility industry.
Experience implementing Zero Trust Security models and least privilege access controls.
Understanding of IT security frameworks (e.g., NIST 800-53, ISO 27001, CIS Controls).
Familiarity with risk assessment methodologies and tools.
Strong analytical and problem-solving skills.
Ability to communicate complex security and compliance topics to non-technical audiences.
Preferred:
Certifications such as CISA, CISSP, CRISC, or CIP Compliance Specialist.
Master’s degree in Information Technology, Cybersecurity, Business, or a related field.
Experience working in an electric cooperative or energy sector.
Hands-on experience with GRC tools, security auditing, or compliance management platforms.
Technical knowledge of network security, endpoint protection, and identity management solutions.
Security Clearance Requirement This position requires the ability to obtain and maintain a U.S. government Secret Security Clearance. While an active clearance is not required to apply, the successful candidate must meet the eligibility criteria for a Secret Clearance, including U.S. citizenship and a background investigation. Our organization will support and facilitate the clearance process for the selected candidate.
About Us
Headquartered in Indianapolis, Indiana, Wabash Valley Power is a not-for-profit electric cooperative and wholesale provider of reliable, affordable electricity to our 23 electric distribution member cooperatives. These cooperatives in turn serve more than 300,000 homes, businesses, and farms in Indiana, Illinois, and Missouri.
As a not-for-profit co-op, we do things a bit differently—and that’s the point. Because we aren’t influenced by shareholders, we make our decisions with our members in mind. That means we value things like teamwork, and putting families first. It also means a business model that’s designed for stability and growth. It’s a Deliberately Different approach to the energy industry, and that’s great news for the people who count on us.
We believe what benefits our employees benefits our company. That’s why we put employees first—your health, your family, and your development. These aren’t just slogans: We offer continuing education, flex time, health benefits, a 401(k) match and pension plan, and much more. Here are just a few of the things that make our company culture unique:
• No Sweat - We offer a wellness program that includes a payroll cr...edit for medical insurance, an on-site fitness center for your convenience and extra vacation days for participating. We’ll even throw in a fitness device reimbursement to keep you on track!
• Flex Time - Our flexible schedule means you can work in your appointments or family events and maintain a comfortable work-life balance.
• Stay in School - We value employees who have a desire to learn, so we provide funds for continuing education. We also offer in-house training and ongoing development through our internal GROW program.
• Keep it Casual - When you work for us, you work in comfort. Blue jeans are the norm in our office and we make them look good!
• Work Hard, Play Hard - We reward our employees with generous vacation time, to the tune of up to five weeks off a year. Even our new employees receive credit for prior work experience.