> Markdown version of [/jobs/ext/1794521-principal-it-governance-and-risk-consultant](https://www.wearedevelopers.com/jobs/ext/1794521-principal-it-governance-and-risk-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal IT Governance and Risk Consultant - **Company:** Pseg Long Island - **Location:** Bethpage, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $107,600.0 - $170,300.0 - **Contract:** Permanent contract - **Skills:** Business Analytics Applications, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Disaster Recovery, IT Management, Software Vulnerability Management, IT General Controls (ITGC), Build Management, Performance Monitor - **Published:** July 18, 2026 - **Apply:** https://dejobs.org/x/x/EF00222286F5456ABC6E6B6A45145CC4/job/ ## About the Role * Bachelor's degree in relevant field of study with at least 8 years of relevant work experience * Demonstrated leadership capabilities through projects or other work planning experiences. * Must have broad knowledge of the IT business area's functions and applications, and of system and technology alternatives. * Deep familiarity with regulatory and assurance frameworks: NIST CSF, NIST 800-53, COBIT, NERC CIP, SOX. * Strong knowledge of IT general controls, application controls, cybersecurity and disaster recovery/business continuity. * Strong understanding of Vulnerability Management process, Risk assessments methodologies, and SLA/KPI management & reporting. * Demonstrated experience in analytic tools to automate performance reporting, and KPI management. * Prior experience in IT governance, risk and/or compliance field. * Strong analytical ability to translate insights into actionable recommendations. * Strong verbal and written communication skills. * Strong facilitation skills. * Strong judgment and escalation management skills. * Ability to foster working relationships with the team, IT Management and vendor teams. * Demonstrated ability to measure process performance and identify constraints, or any other escalation requirements. * Department of Energy's regulation 10 CFR 810 is required. Desired * Ability to automate repetitive tasks. * Ability to handle complex challenges under time constraints. * Project Management Professional Certification (PMP) * Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC). ## Description In support of this model, roles have been categorized into one of three work location categories: 1. Onsite - roles where employees are expected to be onsite daily. 2. Hybrid fixed - roles that are a mix of remote work and onsite work fixed days each week. 3. Hybrid flexible - roles that are a mix of remote work and onsite work, but the onsite requirements have greater flexibility. (i.e. 5-8 days a month vs. set days each week)., This position is a direct report to the Sr IT Manager and has sound knowledge of business processes in the specific area of technology enablement. This position is responsible for managing Vulnerability Management Remediation, IT Risk Management, Reporting & Metrics Management, and Governance & Process Improvement, to meet business outcomes, spanning multiple technologies including associated impact, cost and complexity. This position is part of IT's control assurance program, and part of IT. In that capacity, this position is responsible for the following: Product Consultants are the primary facilitators for the product. Product Consultants are responsible for optimizing the value proposition. They anticipate issues and/or complications, and respond well to time pressures. Leads the effort to work with multiple IT teams to oversee and govern Vulnerability Management Remediation, IT Risk Management, Reporting and Metrics Management, and Governance & Process Improvement. Serves as a subject matter expert for their assigned area. Prioritize actions with IT resources to meet changing business needs. Keeps informed of technical and managerial advances in IT, including leading the introduction of best practice., Leading products teams, in a matrix model, deliver business solutions: * Vulnerability Management and Compliance: * Primary point of contact for vulnerability management remediation. * Works with IT teams to govern and enforce IT Vulnerability Management process, report SLA adherence status and managing progress throughout the lifecycle. * Collaborate with cyber security team to manage risks related to open vulnerabilities. * Escalates unresolved vulnerabilities in a timely manner and close any backlogs. * Governance and Controls Assurance: * Lead the development and maintenance of IT controls aligned with frameworks (NIST, NERC, ISO, SOX etc.). * Map regulatory, audit, and business requirements to control objectives and ensure ongoing compliance. * Prepare management responses, remediation plans, and track closure of findings. * Collaborate with IT Risk Management, Cybersecurity, and Audit teams to ensure controls support company objectives. * Design and build processes for governance of IT vulnerability management, risk management, and compliance. * Identifies process gaps and recommends improvements to enhance efficiency and reduce operational risk. * Reporting and Metrics management: * Define, track, and manage key performance indicators (KPI) for IT business areas and capabilities. * Produce status reports and dashboards for senior leadership team. * Ensures quality using company-approved methodologies. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Answering the Million Dollar Question: Why did I Break Production?](https://www.wearedevelopers.com/videos/1171-answering-the-million-dollar-question-why-did-i-break-production) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [Data Science & more: The Lopez dilemma](https://www.wearedevelopers.com/magazine/10-data-science-more-the-lopez-dilemma) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)