1

Cyber Security Grc Jobs in Rochester, NY (NOW HIRING)

Senior Manager - Cyber IAM

Rochester, NY ยท On-site

$109K - $148K/yr

... cybersecurity Identity and Access Management (IAM). This position is responsible to design ... Support implementation of GRC automation tools to manage compliance processes and evidence for ...

New

Cyber Security Grc information

See Rochester, NY salary details

$40K

$121.3K

$177.6K

How much do cyber security grc jobs pay per year?

As of Aug 9, 2026, the average yearly pay for cyber security grc in Rochester, NY is $121,252.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,600.00 and $140,100.00 per year, depending on experience, location, and employer.

Is cyber security GRC a good job?

Cyber security GRC (Governance, Risk, and Compliance) is a growing field that offers opportunities in risk management, policy development, and compliance auditing. It typically requires knowledge of security frameworks, regulations, and tools like audit software, and can provide stable employment with potential for career advancement. The role is suitable for those interested in both technical and organizational aspects of cybersecurity.

What are some common challenges faced by Cyber Security GRC professionals, and how do they typically overcome them?

Cyber Security GRC professionals often face the challenge of keeping up with evolving regulations, adapting controls for new technologies, and coordinating between security teams and business units. To overcome these challenges, professionals stay current with industry standards, participate in ongoing training, and actively communicate policy changes and risk assessments to stakeholders across the organization. They also leverage robust GRC tools to streamline compliance processes and documentation. Working collaboratively with IT, legal, and compliance teams allows them to better identify risks and implement effective, practical security controls. This approach ensures a well-integrated and proactive risk management posture for the organization.

What is a Cyber Security GRC?

A Cyber Security GRC (Governance, Risk, and Compliance) job focuses on ensuring an organization's security policies, risk management strategies, and regulatory compliance. Professionals in this role develop and enforce security policies, assess risks, and ensure adherence to industry regulations like GDPR, HIPAA, or ISO 27001. They collaborate with different teams to mitigate cybersecurity threats while aligning security practices with business goals. This role is critical for maintaining an organization's security posture and reducing potential risks.

Is cyber security GRC in high demand?

Cyber security GRC (Governance, Risk, and Compliance) professionals are in high demand due to increasing cybersecurity threats and regulatory requirements. Organizations seek experts with skills in risk management, compliance frameworks, and security policies, often requiring certifications like CISSP or CISA. The role offers strong job growth prospects across various industries.

What are the key skills and qualifications needed to thrive in the Cyber Security GRC position?

To thrive as a Cyber Security GRC professional, a solid understanding of information security frameworks, risk management, and regulatory compliance is essential, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as Archer, ServiceNow, or LogicGate), and certifications like CISSP, CISM, or CRISC, are highly valued. Excellent analytical skills, attention to detail, and the ability to communicate complex risks to non-technical stakeholders are critical soft skills. These capabilities ensure organizations remain secure, compliant, and able to effectively manage evolving cyber risks.

What are the most commonly searched types of Cyber Security Grc jobs in Rochester, NY? The most popular types of Cyber Security Grc jobs in Rochester, NY are:
What are popular job titles related to Cyber Security Grc jobs in Rochester, NY? For Cyber Security Grc jobs in Rochester, NY, the most frequently searched job titles are:
What job categories do people searching Cyber Security Grc jobs in Rochester, NY look for? The top searched job categories for Cyber Security Grc jobs in Rochester, NY are:
What cities near Rochester, NY are hiring for Cyber Security Grc jobs? Cities near Rochester, NY with the most Cyber Security Grc job openings:
Infographic showing various Cyber Security Grc job openings in Rochester, NY as of August 2026, with employment types broken down into 67% Full Time, and 33% Contract. Highlights an 100% In-person job distribution, with an average salary of $121,252 per year, or $58.3 per hour.

Senior Manager - Cyber IAM

Iberdrola

Rochester, NY โ€ข On-site

$109K - $148K/yr

Full-time

Posted 2 days ago

New


Job description

The base salary range for this position is dependent upon experience and location, ranging from:

  • $134,720 to $168,400 in NY
  • $148,160 to $185,200 in CT

Responsibilities

This position provides Leadership and Support across the Avangrid Networks business to support cybersecurity Identity and Access Management (IAM). This position is responsible to design, implement, operate, and evolve IAM solutions and strategies for Avangrid Networks operating companies progress for Grid Digitalization.

  • Drive the shift in philosophy of how critical infrastructure is secured from verify once at the perimeter to continual verification of each user, device, application, and transaction
  • Lead the deployment of IAM services and solutions in support of Avangrid's evolution towards a zero-trust security framework
  • Define, develop, and implement an IAM strategy that reduces risk and provides resiliency, while being designed to rapidly enable business initiatives
  • Engage with, and advise stakeholders within the business on IAM best practices
  • Leverage IAM technology investments to expand core capabilities and develop and integrate high-quality, highly available access management solutions
  • Lead federation of physical and logical access management services in support of global IAM federation objectives
  • Ensure IAM services and solutions are designed and delivered in compliance with industry best practices as well as applicable privacy and legal/regulatory requirements including NIST 800-63, GDPR, SOX, CEII, and NERC
  • Support implementation of GRC automation tools to manage compliance processes and evidence for applicable IAM services
  • Establish an IAM service model that is well defined, highly available, repeatable, and is constantly measured for Key performance, Key risk, and Key operational level metrics
  • Ensure measurements and methods are in place to ensure best in class control quality and assurance for IAM solutions
  • Follow applicable federal agency guidance on IAM technologies relevant to Grid Modernization and assess impact on AVANGRID Networks business model
  • Lead, develop, maintain, and write IAM cybersecurity policies, rules standards, and guidelines
  • Participate in appropriate external industry groups, including the Electricity Sector Coordinating Council (ESCC) in support of the OSG Governance and Risk team
  • Research current IAM industry and government frameworks, vulnerabilities, and risk trends, and assess impact
  • Assess vendors/3rd party's IAM solutions for applicable cyber standards/policies
  • Establish Vendor process and metrics for IAM cyber assurance
  • Analyze current/future IAM vendors, hardware, software, etc. that may be introduced to modernize the electric grid and assess increases and offsets to cyber exposure
  • Respond to audits, participate in cybersecurity-related committees, and explain policy impacts at all levels of the company
  • Educate members and government agencies as required during cyber and physical events.
  • Interact with the Department of Energy (DOE), Department of Homeland Security (DHS), Federal Emergency Management Agency (FEMA), Federal Bureau of Investigation (FBI) and other relevant agencies as needed in response to security and grid modernization-related issues

MAJOR ROLES AND RESPONSIBILITES (Scope of work - range of responsibilities):

  • Lead development and integration of IAM services and solutions in support of Grid Modernization for AVANGRID Networks
  • Define, develop, implement, and operate IAM services and solutions for:
  • Network Automation
  • Smart Metering
  • Resilient Telecommunications
  • Intelligent/automatic centralized operations
  • Digital Asset Management
  • Digital enabled organization
  • Distribution Automation
  • Real Time Systems
  • DER Management

JOB REQUIREMENTS:

Education & Experience Required:

  • Master's Degree in Engineering, Computer Science, or Business Management with a minimum of 8+ years' experience in Cybersecurity; or
  • Bachelor's Degree in Engineering, Computer Science, or Business Management with a minimum of 10+ years' experience in Cybersecurity
  • Experience of 5+ years in Business Decision Support including Cybersecurity Risk Indicators and Performance/Metrics reporting.

Skills/ Abilities:

  • Strong communication and administration skills related to cybersecurity technology
  • Strong system engineering and integration background for complex systems and networking
  • Strong understanding of current and future state of cyberspace

Desired Skills/ Abilities:

  • Security clearance at secret level or above I preferrable.
  • Knowledge of federal government cybersecurity activities and practices
  • Experience in federal or state regulatory environments
  • Experience in federal cybersecurity agencies and environments
  • Experience in a utility environment
  • Certified Information Systems Security Professional (CISSP)
  • Certified Identity and Access Manager (CIAM)

Competencies

  • Growth & Continuous Improvement
  • Initiative & Change
  • Focused on Results
  • Customer Centric (internal and/or external)
  • Communication
  • Collaboration
  • Leadership (people managers/leaders)

#LI-OFFICE
#LI-ER1

Company:

AVANGRID SERVICE COMPANY

Mobility Information

Please note that any applicant who is not a citizen of the country of the vacancy will be subject to compliance with the applicable immigration requirements to legally work in that country.

At Avangrid we provide fair and equal employment and advancement opportunities for all employees and candidates regardless of race, color, religion, national origin, gender, sexual orientation, age, marital status, disability, protected veteran status or any other status protected by federal, state, or local law.
If you are an individual with a disability or a disabled veteran who is unable to use our online tool to search for or to apply for jobs, you may request a reasonable accommodation by contacting our People and Organization department at careers@avangrid.com.

Avangrid employees may be assigned a system emergency role and in the event of a system emergency, may be required to work outside of their regular schedule/job duties. This is applicable to employees that will work in Connecticut, Maine, Massachusetts, and New York within Avangrid Network and Corporate functions. This does not include those that will work for Avangrid Power.

Avangrid employees may also be assigned a NERC Reliability Standards compliance role supporting Critical Infrastructure Protection (CIP) and/or Operations and Planning (O&P) responsibilities. This is applicable to employees that will work in electric transmission, operations, and cyber security business areas in Connecticut, Maine, Massachusetts, and New York within Avangrid Network and Corporate business areas. NERC Reliability Standards compliance roles and responsibilities may include additional access protections, training, audit engagement, and required evidence retention, and will be communicated by the employee's management.

Job Posting End Date:

August-15-2026