Cyber GRC Analyst II
Listed on 2025-12-18
-
IT/Tech
Cybersecurity, IT Consultant
At Cleco, we’re not just powering lives—we’re powering a cleaner, smarter future for Louisiana. With bold investments in innovative energy solutions, we’re transforming how we power our communities: smarter, cleaner, and more sustainable. This is a long-term commitment to our people and our communities because our future—and the future of generations to come—depends on it. If you’re ready to make an impact where it matters most, join us at Cleco—where we’re Energizing Your Tomorrow.
The Cyber GRC Analyst II is an experienced professional with some knowledge of and experience with IT General Control (ITGC) principles, practices, concepts, and theories. The role tests adherence to Cleco’s information security policies, standards, and procedures. Ensures Cleco’s IT governance processes are properly designed and functioning effectively, and the organization maintains its compliance with all applicable legal, regulatory, and contractual requirements.
Responsible for ensuring the effectiveness of all IT General Controls (ITGCs). Serve as a direct point of contact between IT and internal / external auditors to provide leadership in managing auditing activities, requests and developing responses to audit findings. Responsible for the completion of assigned processes or activities, requiring interpretation of ITGC practices. Contributes to identifying improvements to ITGC activities and procedures.
Assists in the development and onboarding of entry-level employees with cyber security responsibilities through coaching, mentoring and knowledge sharing.
- Champions a corporate culture that emphasizes transparency, integrity, safety, environmental responsibility, employee development, diversity and inclusion, customer service, and operational excellence.
- Provides technical execution of defined activities to support the delivery of project initiatives required to achieve efficiency, effectiveness, and innovation objectives.
- Achieves results by autonomously owning and executing ITGC activities as defined by manager.
- Supports agile projects through application of defined ITGC approaches.
- Utilizes ITGC standards, procedures, and processes, providing recommendations for process improvements, as necessary.
- Supports the escalation of any risk to delivery for ITGC, to help ensure business objectives are executed and met across responsible project areas.
- Escalate issues to management, as necessary.
- Assess IT compliance with Cleco’s policies and standards and take action to remediate non-compliance.
- Ensure that Cleco’s practices satisfy the requirements of the Sarbanes-Oxley Act.
- Ensure that Cleco is properly evaluating security risks through a risk assessment framework that assesses the potential impact of threats to the business and Cleco’s vulnerability to these threats and recommended controls to reduce risks to levels that align with the organization's risk tolerances and appetite.
- Work collaboratively with all Cleco departments to ensure that local practices are consistent with corporate information security policies and standards.
- Identify compliance objectives and mapped program deliverables to the requirements.
- Participate in Cleco’s business continuity planning and disaster recovery planning programs as well as periodic exercises and tests.
- Collect information for generating and communicating responses to customer due diligence requests and questionnaires.
- Assist in Cleco’s vendor management / third party service provider oversight program and conduct initial vendor due diligence as well as ongoing vendor reviews.
- Conduct and document an annual enterprise risk assessment as well as ad hoc project risk assessments.
- Assist entry-level staff within assigned project teams, leveraging technical experience to help to onboard them and in support of meeting project milestones.
- Provide communication to management to provide status updates on project activities, and identify risks in delivery or resourcing needs.
- Bachelor’s degree in Computer Science, Information Technology, or related field preferred.
- 3‑5+ years of related experience.
- Security Certification required (CISA, CRISC, applicable SANS…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).