Job Details

Governance, Risk, & Compliance Specialist         

Contract to Hire W2 - Profit Sharing Remote
Must Haves:
  • 3+ years of experience in Governance, Risk & Compliance (GRC), cybersecurity compliance, IT audit, information security, or related roles
  • Have GRC, NERC, SOX direct experience with an energy provider
  • Experience with reporting KPI's and intermediate level usage of MS office 360
  • Experience recent experience with documentation writing, audit participation, evidence gathering and defending position
Nice to Haves: 
  • Experience in the renewable energy, utilities, power generation, energy trading, or critical infrastructure industries
  • Familiarity with NERC CIP, FERC, or other energy-sector regulatory requirements
  • Have GRC, NERC, SOX direct experience with an energy provider
  • Experience with reporting KPI's and intermediate level usage of MS office 360
  • Experience recent experience with documentation writing, audit participation, evidence gathering and defending
Day to Day:
  • Support the Information Security team’s governance, risk, and compliance program across corporate IT, cloud services, and operational technology environments
  • Maintain and update security policies, standards, procedures, control narratives, and compliance documentation
  • Coordinate evidence collection for audits, assessments, customer reviews, and internal compliance testing
  • Track audit findings, remediation plans, control deficiencies, policy exceptions, and risk acceptance items
  • Conduct control testing to validate whether security controls are operating effectively
  • Support internal risk assessments, compliance gap assessments, vendor reviews, and security questionnaires
  • Partner with IT, Security Operations, Infrastructure, Engineering, Legal, Procurement, and Operations teams to gather documentation and validate compliance requirements
  • Assist with mapping security controls to frameworks such as NIST, ISO 27001, SOC 2, CIS, and applicable energy-sector requirements
  • Help maintain the company’s risk register, control inventory, compliance calendar, and audit evidence repository
  • Review third-party/vendor security documentation and help assess risk associated with technology providers, OEMs, contractors, and managed service providers
  • Assist in preparing reports, dashboards, and presentations for security leadership and business stakeholders
  • Monitor remediation progress and follow up with control owners to ensure timely closure of audit or compliance items
  • Support continuous improvement of the company’s information security governance program
  • Help ensure new systems, applications, and business initiatives align with security policies and compliance requirements
  • Stay current on cybersecurity regulatory trends, energy-sector security expectations, and industry best practices
Overview 
The Governance & Compliance Specialist will serve as a key member of the Information Security team, helping strengthen the company’s security posture by ensuring policies, controls, audits, risks, and regulatory obligations are effectively managed. In a renewable energy environment, this role is especially important in protecting corporate systems, cloud platforms, and operational assets that support reliable and secure energy generation.
 

Job Overview

Date Posted:
October 6, 2026
Expiration date:
Open Until Filled
Location:
, United States
Job Title:
Governance, Risk, & Compliance Specialist         
PS
Recruiter
Pradyumn Singh
Sr Technical Recruiter at Holistic Partners · Ankit Khanna

Apply for this position

PDF or Word (.doc, .docx) only. Images such as PNG are not accepted.