> Markdown version of [/jobs/ext/2695842-cyber-security-analyst-pseg-li-devsecops-engineer](https://www.wearedevelopers.com/jobs/ext/2695842-cyber-security-analyst-pseg-li-devsecops-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Analyst PSEG LI -DevSecOps Engineer - **Company:** CareerCircle - **Location:** Bethpage, NY, United States - **Experience:** Experienced - **Salary:** $93,600.0 - $148,200.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Agile Methodology, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Engineering, CompTIA Security+, Cyber Security, Information Systems, Continuous Delivery, Continuous Integration, DevOps, Github, Information Technology Audit, Information Systems Security Architecture Professional, Python (Programming Language), Open Source Technology, Secure Coding, Software Engineering, Software Vulnerability Management, Sonatype, Software Security, Infrastructure as Code (IaC), Cloudformation, Gitlab-ci, Kubernetes, Information Technology, CIS Benchmarks, Terraform, Prisma Cloud Platform, Devsecops, Docker, Jenkins, Servicenow, Static Application Security Testing, Artifactory, Dynamic Application Security Testing - **Published:** September 3, 2026 - **Apply:** https://www.careercircle.com/jobs/all/all/usa/ny/bethpage/06316851-4607-49fc-94c9-87c5853d4eca ## About the Role ServiceNow Reliability Procurement NIST 800-53 Coordinating Communication Due Diligence Risk Analysis ISO/IEC 27001 Cyber Security Computer Science Cyber Governance Internal Auditing Internal Controls External Auditing CompTIA Security+ Behavioral Health Treatment Planning Information Systems Management Reporting Lifecycle Management Operational Excellence Cyber Security Policies Management By Exception Business Risk Management Permanent Resident Cards Verbal Communication Skills Code Of Federal Regulations Continuous Improvement Process NIST Cybersecurity Framework (CSF) Internal Controls Testing And Monitoring Governance Risk Management And Compliance Certified Information Systems Security Professional, * Bachelors degree in Cybersecurity, Information Systems, Computer Science, Business, Risk Management or related discipline. * With four (4) or more years of experience in cybersecurity governance, risk, compliance, IT audit, internal controls, or related field. * Candidates without a degree who have 8 years of experience in cyber security governance risk and compliance will be considered. * Proficiency with Cyber GRC technologies (such as ServiceNow, Archer, RSAM, etc.) * Background supporting governance oversight, policy lifecycle management, and standards alignment activities. * Track record performing risk and control assessments and documenting findings, recommendations, and remediation actions. * History of supporting control testing, audit coordination, and compliance validation activities. * Direct involvement with third-party risk review, vendor assessment support, or related due diligence functions. * Familiarity with issue remediation tracking, exception management, and reporting processes. * Advanced analytical, organizational, reporting, and documentation skills. * Excellent written and verbal communication skills with the ability to work effectively with technical and non-technical stakeholders. * Ability to manage multiple priorities, maintain detailed records, and work independently with limited supervision. * Department of Energy's regulation 10 CFR 810 is required Desired * Working knowledge of cybersecurity frameworks and control standards such as NIST CSF, NIST SP 800-53, ISO 27001, and CIS Controls. * Cybersecurity certification such as Security+, CISSP, CISA Please Note the Following: * This position falls under the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) and requires NERC CIP background investigation prior to start., ServiceNow Reliability Procurement NIST 800-53 Coordinating Communication Due Diligence Risk Analysis ISO/IEC 27001 Cyber Security Computer Science Cyber Governance Internal Auditing Internal Controls External Auditing CompTIA Security+ Behavioral Health Treatment Planning Information Systems Management Reporting Lifecycle Management Operational Excellence Cyber Security Policies Management By Exception Business Risk Management Permanent Resident Cards Verbal Communication Skills Code Of Federal Regulations Continuous Improvement Process NIST Cybersecurity Framework (CSF) Internal Controls Testing And Monitoring Governance Risk Management And Compliance ## Description This position supports the organization's cybersecurity governance, risk, and compliance program through governance oversight, policy lifecycle management, standards alignment, risk and control assessments, audit coordination, compliance validation, issue remediation tracking, third-party risk review, and executive reporting and documentation., The Cybersecurity GRC Analyst works closely with IT, Internal Audit, Compliance, Procurement, and business stakeholders to help ensure cybersecurity requirements are defined, documented, assessed, and monitored across the enterprise. This role is responsible for supporting the maintenance of cybersecurity policies and standards, conducting and documenting risk assessments, evaluating control effectiveness, coordinating audit and compliance activities, tracking remediation efforts, and preparing clear reporting for management and leadership., * Support governance oversight activities for the cybersecurity program across the enterprise. * Maintain and support policy lifecycle management, including the review, update, and communication of cybersecurity policies, standards, procedures, and related documentation. * Assist with standards alignment to applicable requirements, contractual obligations, and recognized cybersecurity frameworks. * Perform and document risk and control assessments for systems, applications, vendors, projects, and business processes. * Identify control gaps, document findings, and support risk treatment planning with business and technical stakeholders. * Assist with control documentation and control testing to evaluate design and operating effectiveness. * Provide audit coordination support for internal audits, external audits, and regulatory assessments, including evidence gathering, response tracking, and issue follow-up. * Support compliance validation activities to confirm required controls, processes, and documentation are in place and operating as intended. * Support third-party risk review activities, including security questionnaires, documentation review, assessment follow-up, and findings management. * Maintain risk registers, issue logs, exception records, remediation plans, and supporting documentation. * Perform issue remediation tracking and follow up with stakeholders to support timely closure of findings, gaps, and action items. * Prepare executive reporting and documentation related to risk posture, compliance status, audit results, remediation progress, control maturity, and key metrics. * Support governance committees, risk discussions, and management reporting through accurate and organized documentation. * Contribute to continuous improvement of GRC processes, templates, reporting, and governance practices., JFrog DevOps Github Tooling Jenkins Cannabis Sonatype Terraform DevSecOps Pipelines Operations Management Automation Kubernetes Artifactory Public Cloud Azure DevOps Prisma Cloud GitLab CI/CD Team Building Secure Coding Code Analysis Cyber Security Cloud Security Microsoft Azure Security Testing Cloud Governance Security Controls Agile Methodology Security Policies Docker (Software) Behavioral Health AWS CloudFormation Container Security DevOps Engineering Security Solutions Workflow Management Penetration Testing Amazon Web Services Enterprise Security Cloud Infrastructure Application Security Code Access Security Continuous Deployment Operational Excellence Continuous Integration Open Source Technology Infrastructure Security Vulnerability Management Permanent Resident Cards Bash (Scripting Language) Cloud-Native Architecture Code Of Federal Regulations Infrastructure as Code (IaC) Python (Programming Language) Software Composition Analysis Cross-Functional Collaboration Software Development Life Cycle Application Programming Interface (API) Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) +0 ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers)