Associate Cybersecurity Governance & Risk Analyst
Sign up free to see how well your resume matches this role.
About this role
Important Application Submission Information
In order to ensure your application is successfully received before the job posting expires, please submit your application by 11:59 PM on Friday, September 25, 2026More than a career - a chance to make a difference in people's lives.
Build an exciting, rewarding career with us – help us make a difference for millions of people every day. Consider joining the Duke Energy team, where you'll find a friendly work environment, opportunities for growth and development, recognition for your work, and competitive pay and benefits.
Job Summary
This is an entry-level role supporting the Cybersecurity Architecture & Consulting team. The Associate Cybersecurity Gov. & Risk Analyst performs or assists with foundational cybersecurity architecture, governance, risk, and process-driven activities under the direction of management and senior architects. The role supports high-volume architecture services while developing the knowledge and experience needed to work with increasing independence.
The position provides scalable support across Technology Acquisition Sourcing Reviews (TASR), Security Review Tasks (SRT), Cybersecurity Architecture Reviews (CAR), Minimum Security Baselines (MSB/CMSB), architecture intake, metrics, documentation, and emerging technology research. This support enables senior architects to focus on complex risk reviews, strategic initiatives, security design, and stakeholder engagement.
Responsibilities
Technology Acquisition Sourcing Reviews and Security Review Tasks
- Perform initial intake reviews and completeness checks for TASR and SRT submissions.
- Validate submissions against established cybersecurity policies, standards, security requirements, and approved architectures.
- Conduct preliminary risk assessments, identify security gaps, and escalate higher-risk or complex matters to senior architects or subject matter experts.
- Coordinate with requestors to obtain missing documentation, evidence, or technical information.
- Support vendor and technology due diligence activities.
- Track workflow status, review metrics, and reporting requirements.
- Prepare review summaries, recommendations, and supporting documentation for senior architects and subject matter experts.
- Document architecture requirements, decisions, risk dispositions, and follow-up actions.
Minimum Security Baselines
- Research CIS Benchmarks, NIST guidance, vendor hardening recommendations, regulatory requirements, and other recognized security practices.
- Assist with drafting, updating, and maintaining MSB and CMSB documents.
- Coordinate stakeholder reviews, validation activities, and approval workflows.
- Track baseline review cycles, lifecycle activities, and outstanding actions.
- Collect and organize supporting evidence and implementation documentation.
- Maintain baseline repositories, templates, and related records.
- Assist with publishing approved baselines and communicating updates.
- Document implementation guidance and architecture considerations.
Cybersecurity Architecture Governance and Consulting Support
- Support Cybersecurity Architecture intake management, workflow coordination, and repository maintenance.
- Assist with CAR preparation, intake validation, documentation quality reviews, evidence collection, and action-item tracking.
- Maintain architecture standards, procedures, reference materials, and architecture decision records.
- Coordinate architecture consultations, stakeholder meetings, and follow-up activities.
- Prepare clear documentation of architecture recommendations and requirements.
- Provide professional customer support and communicate issues, requirements, and resolutions to requestors, management, and architecture stakeholders.
Metrics, Reporting, and Continuous Improvement
- Collect, validate, and analyze architecture performance metrics.
- Support dashboard reporting, risk-reduction tracking, trend analysis, and operational reporting.
- Gather evidence supporting architecture outcomes, control implementation, and process performance.
- Assist with quality assurance reviews of architecture deliverables and identify opportunities for process improvement.
- Monitor assigned work to meet established schedules and escalate barriers or risks as appropriate.
Emerging Technology and Security Research
- Research emerging technologies, cloud services, artificial intelligence, agentic AI, and related cybersecurity requirements.
- Assist with technology evaluations, cybersecurity control mapping, and security framework analysis.
- Monitor relevant industry trends, vendor capabilities, and changes to security guidance.
- Develop draft architecture guidance, recommendations, and educational materials for review by senior team members.
General Responsibilities
- Demonstrate working knowledge of IT and cybersecurity policies, standards, processes, controls, tools, and functional areas.
- Perform or assist with security reviews, control assessments, risk assessments, and technical project work of a less complex nature.
- Collaborate with cybersecurity leadership, architects, subject matter experts, business partners, and technology teams.
- Apply cybersecurity process and control knowledge to support compliance and risk-management objectives.
- Protect confidential information and perform assigned work with integrity, sound judgment, and appropriate supervisory review.
- Develop technical, consulting, and architecture skills with the expectation of assuming greater complexity and independence over time.
Basic/Required Qualifications
- Associate degree in Cybersecurity or Other Related Degree
- In lieu of Associate degree(s) listed above, High School/GED AND 2 year(s) related work experience
Desired Qualifications
- Working knowledge of cybersecurity frameworks and guidance, including NIST and CIS Benchmarks.
- Knowledge of cybersecurity risk-management processes and methods for identifying, assessing, and mitigating risk.
- Knowledge of IT and cybersecurity policies, standards, procedures, controls, compliance requirements, and security configuration guidance.
- Ability to research current technologies and understand system, network, cloud, vendor, and emerging technology capabilities.
- Ability to evaluate, analyze, and synthesize technical and process information into clear, high-quality work products.
- Experience or interest in conducting technical reviews, control assessments, impact assessments, or risk assessments.
- Knowledge of IT supply-chain security and supply-chain risk-management practices.
- Strong written and verbal communication, listening, documentation, organization, and customer-support skills.
- Ability to work effectively with defined direction, accept coaching and feedback, and progress toward greater independence.
- Ability to manage multiple assignments, follow established processes, meet schedules, and escalate issues appropriately.
- Ability to manage confidential information with a high degree of integrity.
- Interest in cybersecurity architecture, cloud security, artificial intelligence security, technology governance, metrics, and continuous improvement.
Working Conditions
- Hybrid Mobility Classification – Work will be performed from both remote and onsite locations after the onboarding period. However, hybrid employees must live within a reasonable commute to their designated Duke Energy facility, not greater than 50 miles one way. Employees are expected to report to their assigned Duke Energy facility as required and directed by their manager, on average 3 full workdays per regular workweek.
- Office Environment
Specific Requirements
- 0 - 2 years utility, cybersecurity, auditing, compliance, regulatory or related experience.
Travel Requirements
Not requiredRelocation Assistance Provided (as applicable)
NoRepresented/Union Position
NoVisa Sponsored Position
No. This is not a Visa Sponsored Position. This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future.Please note that in order to be considered for this position, you must possess all of the basic/required qualifications.
Company
Company facts come from this company's own listings. We only show what the postings themselves carry.