Security Risk Analyst
Minneapolis, MN · On-site
Works with the security teams and collaborates with the business to assess IT risks. Tracks risk remediation items. Oversees the risk review process and reporting across the enterprise. Essential ...
Minneapolis, MN · On-site
Works with the security teams and collaborates with the business to assess IT risks. Tracks risk remediation items. Oversees the risk review process and reporting across the enterprise. Essential ...
Minneapolis, MN · On-site
Works with the security teams and collaborates with the business to assess IT risks. Tracks risk remediation items. Oversees the risk review process and reporting across the enterprise. Essential ...
Minneapolis, MN · Hybrid
$85K - $95K/mo
The Information Security Risk Analyst will assess the information security posture of collegiate and administrative units by conducting information security risk assessments, including analyzing ...
Minneapolis, MN · Hybrid
$85K - $95K/mo
The Information Security Risk Analyst will assess the information security posture of collegiate and administrative units by conducting information security risk assessments, including analyzing ...
Minneapolis, MN · On-site
$120K - $130K/yr
Learn IT risk assessment methodologies by staying familiar with industry best practices. Support policy and procedure development to enhance robust security and compliance. Lead special projects in a ...
Minneapolis, MN · On-site
$120K - $130K/yr
Learn IT risk assessment methodologies by staying familiar with industry best practices. Support policy and procedure development to enhance robust security and compliance. Lead special projects in a ...
Learn IT risk assessment methodologies by staying familiar with industry best practices. Support policy and procedure development to enhance robust security and compliance. Lead special projects in a ...
Learn IT risk assessment methodologies by staying familiar with industry best practices. Support policy and procedure development to enhance robust security and compliance. Lead special projects in a ...
Perform riskbased assessments of first line security practices, identifying gaps, weaknesses, thematic concerns, emerging risks, and control deficiencies. * Develop and articulate independent risk ...
Perform riskbased assessments of first line security practices, identifying gaps, weaknesses, thematic concerns, emerging risks, and control deficiencies. * Develop and articulate independent risk ...
Perform risk-based assessments of first line security practices, identifying gaps, weaknesses, thematic concerns, emerging risks, and control deficiencies. * Develop and articulate independent risk ...
Perform risk-based assessments of first line security practices, identifying gaps, weaknesses, thematic concerns, emerging risks, and control deficiencies. * Develop and articulate independent risk ...
Job Title - Information Security Analyst Duration - 3 Months (with a possibility of an extension ... GSEC, CISSP, CISA, CISM, ITIL Preferred exposure in SOC2, ISO 27000, risk assessment methodologies ...
Job Title - Information Security Analyst Duration - 3 Months (with a possibility of an extension ... GSEC, CISSP, CISA, CISM, ITIL Preferred exposure in SOC2, ISO 27000, risk assessment methodologies ...
... vendor security assessments, evaluating control effectiveness, prioritizing remediation, and ... Own enterprise cyber risk management processes, including risk assessments, exception governance ...
... vendor security assessments, evaluating control effectiveness, prioritizing remediation, and ... Own enterprise cyber risk management processes, including risk assessments, exception governance ...
... vendor security assessments, evaluating control effectiveness, prioritizing remediation, and ... Own enterprise cyber risk management processes, including risk assessments, exception governance ...
... vendor security assessments, evaluating control effectiveness, prioritizing remediation, and ... Own enterprise cyber risk management processes, including risk assessments, exception governance ...
Job Title - Information Security Analyst Duration - 3 Months (with a possibility of an extension ... GSEC, CISSP, CISA, CISM, ITIL Preferred exposure in SOC2, ISO 27000, risk assessment methodologies ...
Job Title - Information Security Analyst Duration - 3 Months (with a possibility of an extension ... GSEC, CISSP, CISA, CISM, ITIL Preferred exposure in SOC2, ISO 27000, risk assessment methodologies ...
... security posture improvement, and technology risk reduction. This role serves as a technology ... Drive PCI compliance, assessment, and remediation efforts across multiple technology teams. * Lead ...
... security posture improvement, and technology risk reduction. This role serves as a technology ... Drive PCI compliance, assessment, and remediation efforts across multiple technology teams. * Lead ...
... security posture improvement, and technology risk reduction. This role serves as a technology ... Drive PCI compliance, assessment, and remediation efforts across multiple technology teams. * Lead ...
... security posture improvement, and technology risk reduction. This role serves as a technology ... Drive PCI compliance, assessment, and remediation efforts across multiple technology teams. * Lead ...
... security posture improvement, and technology risk reduction. This role serves as a technology ... Drive PCI compliance, assessment, and remediation efforts across multiple technology teams. * Lead ...
... security posture improvement, and technology risk reduction. This role serves as a technology ... Drive PCI compliance, assessment, and remediation efforts across multiple technology teams. * Lead ...
Lake Elmo, MN · On-site
$199K/yr
Conduct targeted risk assessments of security operations, identity governance, data protection, and vulnerability management programs as needed. Evaluate control design and operating effectiveness ...
Lake Elmo, MN · On-site
$199K/yr
Conduct targeted risk assessments of security operations, identity governance, data protection, and vulnerability management programs as needed. Evaluate control design and operating effectiveness ...
Lake Elmo, MN · On-site
$199K/yr
Conduct targeted risk assessments of security operations, identity governance, data protection, and vulnerability management programs as needed. Evaluate control design and operating effectiveness ...
Lake Elmo, MN · On-site
$199K/yr
Conduct targeted risk assessments of security operations, identity governance, data protection, and vulnerability management programs as needed. Evaluate control design and operating effectiveness ...
Saint Paul, MN · On-site
$60K - $70K/yr
Additionally, the position plays a key role in managing security risk assessments across software products, requiring a strong foundation in cybersecurity best practices. Success in this role demands ...
Quick apply
Saint Paul, MN · On-site
$60K - $70K/yr
Additionally, the position plays a key role in managing security risk assessments across software products, requiring a strong foundation in cybersecurity best practices. Success in this role demands ...
Saint Paul, MN · On-site
$97K - $126K/yr
The Product Security Sr. Analyst will help build and maintain a product security program that offers services such as: product security risk assessment, security testing, security event handling ...
Quick apply
Saint Paul, MN · On-site
$97K - $126K/yr
The Product Security Sr. Analyst will help build and maintain a product security program that offers services such as: product security risk assessment, security testing, security event handling ...
$66K - $114K/yr
Performs security risk assessments of third-party vendors and service providers and tracks remediation activities. * Maintains the vendor risk register and monitors progress toward risk mitigation ...
$66K - $114K/yr
Performs security risk assessments of third-party vendors and service providers and tracks remediation activities. * Maintains the vendor risk register and monitors progress toward risk mitigation ...
Minneapolis, MN · On-site
$66K - $114K/yr
Performs security risk assessments of third-party vendors and service providers and tracks remediation activities. * Maintains the vendor risk register and monitors progress toward risk mitigation ...
Minneapolis, MN · On-site
$66K - $114K/yr
Performs security risk assessments of third-party vendors and service providers and tracks remediation activities. * Maintains the vendor risk register and monitors progress toward risk mitigation ...
Edina, MN · On-site
$66K - $114K/yr
Performs security risk assessments of third-party vendors and service providers and tracks remediation activities. * Maintains the vendor risk register and monitors progress toward risk mitigation ...
Edina, MN · On-site
$66K - $114K/yr
Performs security risk assessments of third-party vendors and service providers and tracks remediation activities. * Maintains the vendor risk register and monitors progress toward risk mitigation ...
| Aspect | Freelance Security Risk Assessment | Security Consultant |
|---|---|---|
| Credentials | Certifications like CISSP, CISA, or CEH often required | Similar certifications, often with additional experience requirements |
| Work Environment | Independent, project-based, often remote or on-site at client locations | Typically employed by firms or consulting agencies, may work on multiple projects |
| Industry Usage | Used by organizations seeking independent risk assessments | Engaged for broader security strategy, policy development, and consulting |
While both roles involve assessing security risks, Freelance Security Risk Assessments focus on independent, project-specific evaluations, whereas Security Consultants often provide ongoing security advice and strategy within organizations or consulting firms.
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 18 days ago
8.3
Based on 89 frontline employees who took The Breakroom Quiz
20th of 53 rated energy and utility
Are you looking for an exciting job where you can put your skills and talents to work at a company you can feel proud to be a part of? Do you want a workplace that will challenge you and offer you opportunities to learn and grow? A position at Xcel Energy could be just what you're looking for.
Position Summary
Executes critical aspects of the Enterprise Security Risk Management function. Partners with the business to document and measure risk inherent to systems, assets, and information. Works with the security teams and collaborates with the business to assess IT risks. Tracks risk remediation items. Oversees the risk review process and reporting across the enterprise.
Essential Responsibilities
Oversees the risk acceptance process across the enterprise to ensure risks are documented and accepted at the correct levels of the organization. Validates remediation plans are in place to reduce risk where possible. Manages cycle to reassess accepted risks, obtain sign-off, and provide reporting.
Assists business partners with completing risk assessments and ensuring the correct documentation is captured to support the risk assessment process. Translates technical language into business terms to facilitate understanding of risk to the business.
Maintains documentation and templates in the GRC toolset and makes recommendations for and implements tool and process improvements.
Collaborates with senior and lead risk analysts on activities related to risk modeling, comprehensive periodic risk assessments, and regulatory reporting standards and expectations, and the development of communication and presentations for internal and external audiences.
Supports on the development of communications and presentations appropriate for senior level audiences and external regulators.
Minimum Requirements
Minimum of 3 years experience working in a security function. (One year of working in a highly regulated environment e.g. Utilities, Financial, may substitute for up to 18 months experience in a security function.)
2 years of experience with risk assessments, audit or control testing.
Knowledge of security and lifecycle management, including auditing methodology or technology risk assessments.
Self-starter; adaptable to change; motivated to set personal and program goals and proactively track performance against goals and initiatives.
Ability to develop strong working relationships with peers and stakeholders across business units.
Experience working with information security policies, standards, industry best practices and/or frameworks (e.g., ISO 27K, NIST 800-53, FISMA, BITS, etc.)
Knowledge of IT Security tools and technologies used in an enterprise environment.
Preferred Requirements: Bachelor's degree or higher with a concentration in computer science, technology, or business, or equivalent combination of education and experience.
Security or Risk-related certifications (CRISC, CISSP, CISA, etc.)
Preferred Qualifications
Risk Assessment Experience:Experience conducting vendor and project-based security risk assessments, including identifying risks, evaluating impact/likelihood, and recommending appropriate controls and treatment strategies.
Security Frameworks & Controls:Working knowledge of security frameworks and standards (e.g., NIST, ISO 27001) and ability to apply control requirements within risk assessments and findings.
GRC Tooling:Familiarity with GRC platforms such as Archer and/or ProcessUnity for documenting assessments, tracking risks, and managing findings lifecycle.
Findings & Risk Management:Experience developing detailed findings, managing remediation tracking, and supporting risk acceptance and exception processes with minimal guidance.
Stakeholder Engagement:Ability to partner with business and technology teams to gather requirements, facilitate discussions, and support risk-based decision-making.
Communication & Documentation:Strong written communication skills with the ability to clearly document risk assessments, findings, and recommendations for both technical and business audiences.
Self-Starter & Adaptability:Demonstrated ability to work independently, manage ambiguity, and prioritize work across multiple assessments and initiatives.
Security & Risk Background:~5+ years of experience in cybersecurity, IT risk, GRC, audit, compliance, or security consulting.
As a leading combination electricity and natural gas energy company, Xcel Energy offers a comprehensive portfolio of energy-related products and services to 3.4 million electricity and 1.9 million natural gas customers across eight Western and Midwestern states. At Xcel Energy, we strive to be the preferred and trusted provider of the energy our customers need. If you're ready to be a part of something big, we invite you to join our team.
All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Individuals with a disability who need an accommodation to apply please contact us at recruiting@xcelenergy.com.
Non-BargainingThe anticipated starting base pay for this position is: $73,700.00 to $104,633.00 per yearThis position is eligible for the following benefits: Annual Incentive Program, Medical/Pharmacy Plan, Dental, Vision, Life Insurance, Dependent Care Reimbursement Account, Health Care Reimbursement Account, Health Savings Account (HSA) (if enrolled in eligible health plan), Limited-Purpose FSA (if enrolled in eligible health plan and HSA), Transportation Reimbursement Account, Short-term disability (STD), Long-term disability (LTD), Employee Assistance Program (EAP), Fitness Center Reimbursement (if enrolled in eligible health plan), Tuition reimbursement, Transit programs, Employee recognition program, Pension, 401(k) plan, Paid time off (PTO), Holidays, Volunteer Paid Time Off (VPTO), Parental LeaveBenefit plans are subject to change and Xcel Energy has the right to end, suspend, or amend any of its plans, at any time, in whole or in part.
In any materials you submit, you may redact or remove age-identifying information including but not limited to dates of school attendance and graduation. You will not be penalized for redacting or removing this information.
Deadline to Apply: 07/21/26EEO is the Law |EEO is the Law Supplement | Pay Transparency Nondiscrimination | Equal Opportunity Policy (PDF) | Employee Rights (PDF)
All Xcel Energy employees and contractors share responsibility for protecting the company's information and systems by adhering to cybersecurity policies, standards, and best practices, recognizing that cybersecurity is everyone's responsibility.
ACCESSIBILITY STATEMENT
Xcel Energy endeavors to make https://www.xcelenergy.com/ accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact Xcel Energy Talent Acquisition at recruiting@xcelenergy.com. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.
Get the full story on Breakroom
Sourced by ZipRecruiter
Xcel Energy is a prominent electricity and natural gas service provider serving multiple states in the United States, including Colorado, Michigan, Minnesota, New Mexico, North Dakota, South Dakota, Texas, and Wisconsin. Our commitment revolves around delivering essential services to our valued customers. As a trailblazer in the industry, we were the first major US electricity provider with a visionary goal to achieve 100% carbon-free electricity by 2050 and an ambitious 80% reduction in carbon emissions by 2030, based on 2005 levels. Through innovative electric vehicle initiatives, we actively contribute to carbon reduction not only in our electricity generation but also in the transportation sector within the states we operate. Simultaneously, we remain devoted to ensuring cost-effectiveness for our customers by implementing advanced electricity rates and energy efficiency programs.
Utilities
10,000+ Employees
Minneapolis, MN, US
1909