Invenergy is North America’s largest privately held developer, owner, and operator of power infrastructure. With 25 years of trusted execution, we deliver reliable, affordable energy through a diverse portfolio that includes natural gas, solar, land-based wind, energy storage, transmission, and domestic manufacturing. Headquartered in Chicago, we develop, own, and operate large scale projects that power communities and support the energy future.
This position will be open for application for at least 3 calendar days from the posting date. This position will remain open for application based on business need, which may be before or after the 3-day posting window.
Position Overview:
The Analyst II, Information and Cyber Security supports the execution and continuous improvement of enterprise cybersecurity governance, risk, and compliance (GRC) programs. This role focuses on security controls, policy governance, and regulatory compliance, while also contributing to broader cybersecurity initiatives including risk management, third-party assessments, audit support, and security program operations. This position provides exposure across multiple cybersecurity domains and offers opportunities to contribute to a growing and evolving cybersecurity program aligned with industry and regulatory best practices.
Responsibilities:
- Support the development, maintenance, and enforcement of security policies, standards, and procedures across the enterprise
- Maintain and enhance the security controls catalog, aligning to frameworks such as CIS Controls, NERC CIP, NIST CSF, ISO 27001, and other industry best practice frameworks
- Perform control assessments to evaluate design and operating effectiveness; identify gaps and track remediation efforts
- Develop and maintain dashboards, metrics, and reporting to measure control performance and program maturity
- Support NERC CIP compliance activities, including evidence collection, audit coordination, remediation tracking, and follow-up activities
- Assist in commissioning and compliance validation efforts, including documentation standardization and process improvement initiatives
- Partner with IT and business stakeholders to communicate security requirements and drive compliance across the organization
- Contribute to third-party risk management activities, including vendor security assessments, due diligence reviews, and risk documentation
- Assist in responding to customer security questionnaires, audits, attestations, and evidence requests
- Support contract reviews by identifying cybersecurity requirements and potential risk exposures
- Collaborate with enterprise risk management efforts, including risk identification, documentation, tracking, and remediation coordination
- Track and report on cybersecurity KPIs and program metrics, identifying trends and opportunities for continuous improvement
- Act as a liaison for cybersecurity-related requests, collaborating with teams including Legal, Information Governance, Security Operations, Infrastructure, and Security Architecture
- Participate in cross-functional cybersecurity initiatives and provide operational support across cybersecurity programs as needed
- Support incident response activities and post-incident reviews in a coordination and documentation role, as required
Minimum Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, or a related field (or equivalent experience)
- 2+ years of professional experience in cybersecurity, IT security, or GRC-related roles
- Foundational knowledge of security frameworks (e.g., NIST SP 800-53, ISO 27001, CIS Controls)
- Experience supporting audits, compliance programs, or control assessments
- Strong analytical and problem-solving skills with attention to detail
- Ability to manage multiple priorities and drive tasks to completion
- Effective communication skills, with the ability to engage both technical and non-technical stakeholders
- Self-starter with a proactive mindset and the ability to work independently and collaboratively across teams
Preferred Qualifications
- Experience with regulatory environments such as NERC CIP or other critical infrastructure standards
- Experience with GRC platforms or workflow tools (e.g., ServiceNow, Archer, Smartsheet)
- Background in consulting, advisory, or IT audit with a focus on cybersecurity or compliance
- Experience supporting vendor risk reviews or contract security assessments
- Knowledge of cloud security concepts (e.g., Microsoft 365, Azure environments)
- Relevant certifications (e.g., Security+, CISA, CRISC, CISSP, or similar)
$75,000.00 - $103,000.00 USD Annual
Bonus: 15%
The base pay range reflects the minimum and maximum target salary for the position. Invenergy considers a number of factors when determining base pay offers such as the scope and responsibilities of the position and the candidate's experience, education and skills.
In addition to base pay, the total annual compensation package may also include eligibility to participate in our bonus program(s) which are designed to reward individual and company performance. Your recruiter can share more about bonus eligibility for this position during the hiring process.
Invenergy offers a variety of other benefits including medical, dental and vision insurance, 401k, paid time off, etc.
Invenergy LLC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to, among other things, race, color, religion, sex, sexual orientation, gender identity, national origin, age, status as a protected veteran, or disability.