Analyst II, Information & Cyber Security

Invenergy LLC
Chicago, IL, United States
22 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$75,000.0 - $103,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Microsoft Azure Cloud Computing Security Cyber Security Information Systems Information Technology Audit Workflow Management Systems Smartsheet Information Technology RSA Archer Platform CIS Benchmarks Servicenow

Job description

The Analyst II, Information and Cyber Security supports the execution and continuous improvement of enterprise cybersecurity governance, risk, and compliance (GRC) programs. This role focuses on security controls, policy governance, and regulatory compliance, while also contributing to broader cybersecurity initiatives including risk management, third-party assessments, audit support, and security program operations. This position provides exposure across multiple cybersecurity domains and offers opportunities to contribute to a growing and evolving cybersecurity program aligned with industry and regulatory best practices., * Support the development, maintenance, and enforcement of security policies, standards, and procedures across the enterprise

  • Maintain and enhance the security controls catalog, aligning to frameworks such as CIS Controls, NERC CIP, NIST CSF, ISO 27001, and other industry best practice frameworks
  • Perform control assessments to evaluate design and operating effectiveness; identify gaps and track remediation efforts
  • Develop and maintain dashboards, metrics, and reporting to measure control performance and program maturity
  • Support NERC CIP compliance activities, including evidence collection, audit coordination, remediation tracking, and follow-up activities
  • Assist in commissioning and compliance validation efforts, including documentation standardization and process improvement initiatives
  • Partner with IT and business stakeholders to communicate security requirements and drive compliance across the organization
  • Contribute to third-party risk management activities, including vendor security assessments, due diligence reviews, and risk documentation
  • Assist in responding to customer security questionnaires, audits, attestations, and evidence requests
  • Support contract reviews by identifying cybersecurity requirements and potential risk exposures
  • Collaborate with enterprise risk management efforts, including risk identification, documentation, tracking, and remediation coordination
  • Track and report on cybersecurity KPIs and program metrics, identifying trends and opportunities for continuous improvement
  • Act as a liaison for cybersecurity-related requests, collaborating with teams including Legal, Information Governance, Security Operations, Infrastructure, and Security Architecture
  • Participate in cross-functional cybersecurity initiatives and provide operational support across cybersecurity programs as needed
  • Support incident response activities and post-incident reviews in a coordination and documentation role, as required

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, or a related field (or equivalent experience)
  • 2+ years of professional experience in cybersecurity, IT security, or GRC-related roles
  • Foundational knowledge of security frameworks (e.g., NIST SP 800-53, ISO 27001, CIS Controls)
  • Experience supporting audits, compliance programs, or control assessments
  • Strong analytical and problem-solving skills with attention to detail
  • Ability to manage multiple priorities and drive tasks to completion
  • Effective communication skills, with the ability to engage both technical and non-technical stakeholders
  • Self-starter with a proactive mindset and the ability to work independently and collaboratively across teams, * Experience with regulatory environments such as NERC CIP or other critical infrastructure standards
  • Experience with GRC platforms or workflow tools (e.g., ServiceNow, Archer, Smartsheet)
  • Background in consulting, advisory, or IT audit with a focus on cybersecurity or compliance
  • Experience supporting vendor risk reviews or contract security assessments
  • Knowledge of cloud security concepts (e.g., Microsoft 365, Azure environments)
  • Relevant certifications (e.g., Security+, CISA, CRISC, CISSP, or similar)

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance, $75,000.00 - $103,000.00 USD Annual Bonus: 15%

The base pay range reflects the minimum and maximum target salary for the position. Invenergy considers a number of factors when determining base pay offers such as the scope and responsibilities of the position and the candidate’s experience, education and skills.

In addition to base pay, the total annual compensation package may also include eligibility to participate in our bonus program(s) which are designed to reward individual and company performance. Your recruiter can share more about bonus eligibility for this position during the hiring process.

Invenergy offers a variety of other benefits including medical, dental and vision insurance, 401k, paid time off, etc.

About the company

Invenergy is North America’s largest privately held developer, owner, and operator of power infrastructure. With 25 years of trusted execution, we deliver reliable, affordable energy through a diverse portfolio that includes natural gas, solar, land-based wind, energy storage, transmission, and domestic manufacturing. Headquartered in Chicago, we develop, own, and operate large scale projects that power communities and support the energy future.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all