Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Duke Energy Corporation

Associate Cybersecurity Governance, Risk Analyst

Duke Energy Corporation

. Perform initial intake reviews and completeness checks for Technology Acquisition Sourcing Reviews and Security Review Tasks .

Posted 9/22/2026full-timeCharlotte • North Carolina • United StatesJuniorMid-LevelWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in cybersecurity frameworks, risk management processes, and compliance requirements while effectively coordinating architecture reviews and vendor due diligence activities. Proficient in analyzing technical information and producing high-quality documentation to support security initiatives.

Highest-signal resume keywords
Cybersecurity FrameworksRisk Management ProcessesNIST GuidanceCIS BenchmarksTechnical Reviews

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Cybersecurity PoliciesSecurity RequirementsRisk AssessmentsControl AssessmentsDocumentation SkillsArchitecture StandardsSecurity Configuration GuidanceProcess ImprovementVendor Due DiligenceIT Supply-Chain Security
Soft Skills
Strong Communication SkillsListening SkillsOrganizational SkillsCustomer Support SkillsAbility to Accept Feedback
Tools & Technologies
Cloud ServicesEmerging TechnologiesArchitecture Review ToolsDashboard Reporting Tools
Industry Keywords
CybersecurityComplianceAuditingRegulatory RequirementsSecurity Practices

Tech Stack

Tools & technologies
CloudCyber Security

About the role

Key responsibilities & impact
  • Perform initial intake reviews and completeness checks for Technology Acquisition Sourcing Reviews and Security Review Tasks
  • Validate submissions against cybersecurity policies, standards, security requirements, and approved architectures
  • Conduct preliminary risk assessments, identify security gaps, and escalate complex or higher-risk matters
  • Coordinate with requestors to obtain missing documentation, evidence, or technical information
  • Support vendor and technology due diligence activities
  • Track workflow status, review metrics, and reporting requirements
  • Prepare review summaries, recommendations, and supporting documentation
  • Document architecture requirements, decisions, risk dispositions, and follow-up actions
  • Research CIS Benchmarks, NIST guidance, vendor hardening recommendations, regulatory requirements, and recognized security practices
  • Assist with drafting, updating, maintaining, and publishing Minimum Security Baselines and related documentation
  • Support cybersecurity architecture intake management, workflow coordination, repository maintenance, and architecture review preparation
  • Maintain architecture standards, procedures, reference materials, and decision records
  • Coordinate architecture consultations, stakeholder meetings, and follow-up activities
  • Collect, validate, and analyze architecture performance metrics and support dashboard reporting
  • Gather evidence supporting architecture outcomes, control implementation, and process performance
  • Assist with quality assurance reviews and identify process-improvement opportunities
  • Research emerging technologies, cloud services, artificial intelligence, agentic AI, and related cybersecurity requirements
  • Assist with technology evaluations, cybersecurity control mapping, and security framework analysis
  • Collaborate with cybersecurity leadership, architects, subject matter experts, business partners, and technology teams
  • Develop technical, consulting, and architecture skills with increasing complexity and independence

Requirements

What you’ll need
  • Associate degree in Cybersecurity or another related degree
  • Alternatively, High School/GED and 2 years of related work experience in lieu of the associate degree
  • 0–2 years of utility, cybersecurity, auditing, compliance, regulatory, or related experience
  • Working knowledge of cybersecurity frameworks and guidance, including NIST and CIS Benchmarks
  • Knowledge of cybersecurity risk-management processes and methods for identifying, assessing, and mitigating risk
  • Knowledge of IT and cybersecurity policies, standards, procedures, controls, compliance requirements, and security configuration guidance
  • Ability to research current technologies and understand system, network, cloud, vendor, and emerging technology capabilities
  • Ability to evaluate, analyze, and synthesize technical and process information into clear, high-quality work products
  • Experience or interest in technical reviews, control assessments, impact assessments, or risk assessments
  • Knowledge of IT supply-chain security and supply-chain risk-management practices
  • Strong written and verbal communication, listening, documentation, organization, and customer-support skills
  • Ability to work effectively with defined direction, accept coaching and feedback, and progress toward greater independence
  • Ability to manage multiple assignments, follow established processes, meet schedules, and escalate issues appropriately
  • Ability to manage confidential information with a high degree of integrity
  • Ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future

Benefits

Comp & perks
  • Friendly work environment
  • Opportunities for growth and development
  • Recognition for your work
  • Competitive pay and benefits
  • Hybrid work arrangement
  • No travel required
  • Relocation assistance not provided