Invenergy LLC · Chicago, IL

Analyst II, Information & Cyber Security at Invenergy LLC — Chicago, IL

Full-timeChicago, ILPosted 2026-07-20Apply on Workday

Full job description

Job Description

Position Overview:

The Analyst II, Information and Cyber Security supports the execution and continuous improvement of enterprise cybersecurity governance, risk, and compliance (GRC) programs. This role focuses on security controls, policy governance, and regulatory compliance, while also contributing to broader cybersecurity initiatives including risk management, third-party assessments, audit support, and security program operations. This position provides exposure across multiple cybersecurity domains and offers opportunities to contribute to a growing and evolving cybersecurity program aligned with industry and regulatory best practices.

Responsibilities

  • Support the development, maintenance, and enforcement of security policies, standards, and procedures across the enterprise
  • Maintain and enhance the security controls catalog, aligning to frameworks such as CIS Controls, NERC CIP, NIST CSF, ISO 27001, and other industry best practice frameworks
  • Perform control assessments to evaluate design and operating effectiveness; identify gaps and track remediation efforts
  • Develop and maintain dashboards, metrics, and reporting to measure control performance and program maturity
  • Support NERC CIP compliance activities, including evidence collection, audit coordination, remediation tracking, and follow-up activities
  • Assist in commissioning and compliance validation efforts, including documentation standardization and process improvement initiatives
  • Partner with IT and business stakeholders to communicate security requirements and drive compliance across the organization
  • Contribute to third-party risk management activities, including vendor security assessments, due diligence reviews, and risk documentation
  • Assist in responding to customer security questionnaires, audits, attestations, and evidence requests
  • Support contract reviews by identifying cybersecurity requirements and potential risk exposures
  • Collaborate with enterprise risk management efforts, including risk identification, documentation, tracking, and remediation coordination
  • Track and report on cybersecurity KPIs and program metrics, identifying trends and opportunities for continuous improvement
  • Act as a liaison for cybersecurity-related requests, collaborating with teams including Legal, Information Governance, Security Operations, Infrastructure, and Security Architecture
  • Participate in cross-functional cybersecurity initiatives and provide operational support across cybersecurity programs as needed
  • Support incident response activities and post-incident reviews in a coordination and documentation role, as required

Minimum Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, or a related field (or equivalent experience)
  • 2+ years of professional experience in cybersecurity, IT security, or GRC-related roles
  • Foundational knowledge of security frameworks (e.g., NIST SP 800-53, ISO 27001, CIS Controls)
  • Experience supporting audits, compliance programs, or control assessments
  • Strong analytical and problem-solving skills with attention to detail
  • Ability to manage multiple priorities and drive tasks to completion
  • Effective communication skills, with the ability to engage both technical and non-technical stakeholders
  • Self-starter with a proactive mindset and the ability to work independently and collaboratively across teams

Preferred Qualifications

  • Experience with regulatory environments such as NERC CIP or other critical infrastructure standards
  • Experience with GRC platforms or workflow tools (e.g., ServiceNow, Archer, Smartsheet)
  • Background in consulting, advisory, or IT audit with a focus on cybersecurity or compliance
  • Experience supporting vendor risk reviews or contract security assessments
  • Knowledge of cloud security concepts (e.g., Microsoft 365, Azure environments)
  • Relevant certifications (e.g., Security+, CISA, CRISC, CISSP, or similar)

Base Pay

$75,000.00 - $103,000.00 USD Annual Bonus: 15%