FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Security and Compliance Analyst
Xcel Energy. Contribute to the development and execution of the security governance and control program .
Posted 9/18/2026full-timeMinneapolis • Colorado • United StatesSenior💰 $84,900 - $120,566 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in security governance, risk management, and compliance, with a strong focus on developing and implementing security policies, standards, and training programs. Proficient in analyzing security controls and metrics to support organizational decision-making and compliance assurance.
Highest-signal resume keywords
Security GovernanceRisk ManagementCompliance AssuranceControl TestingSecurity Policy Implementation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security StandardsControl TestingSecurity AuditsSecurity Risk ManagementDocumentation CreationMetrics ReportingSecurity Controls EvaluationRegulatory ComplianceTraining DevelopmentIssue Management
Soft Skills
AdaptabilityProblem SolvingRelationship BuildingCommunication SkillsJudgment
Tools & Technologies
EGRC SystemGRC ToolArcher
Certifications & Qualifications
CISMCISACRISCCISSPSecurity+CPPPSP
Industry Keywords
PCINERC CIPDHS TSASOXHIPAAISONISTCOBITCyber Security FrameworkGovernance, Risk & Compliance
Tech Stack
Tools & technologiesCyber SecuritySDLC
About the role
Key responsibilities & impact- Contribute to the development and execution of the security governance and control program
- Manage security policies and standards, security controls assurance, training and awareness, and metrics and reporting
- Develop and implement the department's policy and compliance governance program and supporting procedures documentation
- Map security standard requirements to key regulations and frameworks
- Partner with industry and business unit subject matter experts to identify and document new requirements and supporting controls
- Maintain enterprise security standards in the eGRC system for Issue Management, Exceptions, and Security Assurance control testing
- Contribute to the compliance assurance program and supporting procedures
- Lead the development and implementation of the CIP compliance management program
- Lead security policy and standards review and update cycles with owners and subject matter experts
- Develop and evaluate security controls, self-assessments, spot-checks, risk identification, process gaps, and process alignment
- Monitor the security threat landscape, changes in security frameworks, and in-scope regulations
- Compile and review security controls assessment output
- Analyze information and formulate recommendations and reports for management decision-making
- Identify and manage security metrics and reporting for leadership and applicable business units
- Lead development and implementation of ESEM Governance training and awareness
- Develop and deliver training and awareness content to applicable business units
- Serve as a designated regulatory security liaison
- Perform other duties as assigned
Requirements
What you’ll need- Bachelor's degree or equivalent experience
- At least 4 years of experience in security and IT or OT related fields
- Three years of experience with control testing, security standards/policy implementation, security audits, or security risk management
- One year of working in a Governance, Risk & Compliance (GRC) function in a highly regulated environment may substitute for up to 18 months experience
- Self-starter; adaptable to change
- Ability to set and achieve personal and program goals, and to track performance against those goals
- Ability to work effectively across the organization, establishing positive working relationships, and building trust
- Sound judgment and creativity to solve complex problems
- Strong verbal and written communication skills
- Demonstrated ability to create documentation for technical and non-technical audiences
- Preferred: experience with physical access controls, network administration, systems administration, SDLC / secure software, encryption, asset management, identity and access management, IT or OT operations, or security risk management
- Preferred: certification in CISM, CISA, CRISC, CISSP, Security+, CPP or PSP
- Preferred: experience using a GRC tool (i.e. Archer)
- Preferred: knowledge of PCI, NERC CIP, DHS TSA, SOX, HIPPA, ISO, NIST, COBIT, or Cyber Security Framework (CSF)
Benefits
Comp & perks- Annual Incentive Program
- Medical/Pharmacy Plan
- Dental
- Vision
- Life Insurance
- Dependent Care Reimbursement Account
- Health Care Reimbursement Account
- Health Savings Account (HSA) (if enrolled in eligible health plan)
- Limited-Purpose FSA (if enrolled in eligible health plan and HSA)
- Transportation Reimbursement Account
- Short-term disability (STD)
- Long-term disability (LTD)
- Employee Assistance Program (EAP)
- Fitness Center Reimbursement (if enrolled in eligible health plan)
- Tuition reimbursement
- Transit programs
- Employee recognition program
- Pension
- 401(k) plan
- Paid time off (PTO)
- Holidays
- Volunteer Paid Time Off (VPTO)
- Parental Leave
- Hybrid work model supporting collaboration and flexibility