NextEra Energy IT Compliance and Risk Analyst in Juno Beach, Florida

IT Compliance and Risk Analyst

Date:Mar 13, 2018

Primary Location:Juno Beach, FL, US, 33408

Company:NextEra Energy Requisition ID: 22701

Our reliability is one of the best in the nation, and we’re working to make it even better. We live here too. That’s why we’re committed to making Florida a better place. Join our team today

Position Specific Description FPL is seeking an experienced compliance analyst that excels at polished compliance documentation to be part of the team that provides compliance support in the area of cyber security and critical system protection including NERC-CIP compliance. Individual will be responsible for high quality, timely and consistent document creation, update, and re-write as necessary for NERC-CIP compliance documentation across the company. Individual will work cross functionally with other team leaders, team analysts, technology project managers, and business function subject matter experts.

Position requires: • Knowledge and appreciation of compliance regulations and governance and security control principles • Familiarity with regulatory compliance in the context of security, and related regulations, industry standards and guidance • Superior written and solid verbal communication skills • Ability to navigate across obstacles to meet timelines and obtain buy-in from stakeholders • Experience writing policies, procedures and guidance documenting security controls aligned with other regulatory standards and/or security framework(s) may be consider as a substitute for NERC CIP experience •

Your ability to navigate large cross-functional teams; effectively communicate and collaborate with team members and associated business functions across a regulated utility; understanding of agile delivery; remediation and cyber risk management background is key to the success of this role. Understanding of regulatory compliance in utilities, specifically North American Reliability Corporation (NERC), and Critical Infrastructure Protection (CIP) and experience with NERC CIP standards, understanding of controls and measures related to implementation of a CIP program will be highly valued. Equally important is your experience in continuous process improvements and quality measurements and the ability to work with, translate and document complex scenarios into a simplistic manner for non-technical resources (General Counsel, Business, Privacy, etc.). Desired certifications: CISSP, CRISC, CISM, CISA or other industry-relevant cyber-security certifications Lean Six Sigma Belt certification

Job Overview This job supports a focused team facilitating internal solution development across business units, to align Cybersecurity risk, leading technology solutions, and user experience. This position is responsible for various aspects of achieving compliance of cybersecurity including developing, implementing and enforcing IT policies, standards, methodologies and awareness using a risk based approach. Employees in this role develop a deep understanding of NextEra’s technology footprint, technology strategy, threat landscape and risks, to establish a collective Cyberstrategy. Individuals work closely with enterprise architecture, engineering, operations and other technology or business leadership.

Job Duties & Responsibilities

  • Builds processes and tools to provide the business visibility of cybersecurity risks and drive accountability
  • Develops and maintains policies, standards, processes, and procedures to assess, monitor, report, escalate and remediate cyber risk while maintaining corporate compliance with mandated security regulations
  • Assesses and reviews security and controls to ensure sustainable regulatory compliance
  • Develops processes and monitoring to identify, quantify, analyze, and report risk and compliance status
  • Coordinates cyber risk management efforts including identification, assessment, tracking and resolution of risk management activities across all levels of the organization
  • Assists with training, including training material development and deployment to ensure that compliance and risk becomes a sustainable business practice
  • Gathers and prepares documentation to support audits, self-assessments, data requests, etc
  • Performs other job-related duties as assigned Required Qualifications

  • High School Grad / GED

  • Bachelor's or Equivalent Experience
  • Experience: 3+ years Preferred Qualifications

  • Certified Information Systems Aud (CISA)

Employee Group: Exempt Employee Type: Projectbound FT Job Category: Information Technology Organization: Florida Power & Light Company Location: Juno Beach, Florida Other Work Locations: Florida Relocation Provided: No

NextEra Energy is an Equal Opportunity Employer. Qualified applicants are considered for employment without regard to race, color, age, national origin, religion, marital status, sex, sexual orientation, gender identity, gender expression, genetics, disability, protected veteran status or any other basis prohibited by law. We are committed to a diverse and inclusive workplace.

If you require special support or accommodation while seeking employment with NextEra Energy, please send an e-mail to, providing your name, telephone number and the best time for us to reach you. Alternatively, you may call 1-844-694-4748 (Option 1, Press 6) between 8 a.m. and 5 p.m. EST Monday-Friday. Please do not use this line to inquire about your application status.

NextEra Energy will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information.

Nearest Major Market:Palm Beach Nearest Secondary Market:Miami Job Segment:Sustainability, Energy