Primary purpose:
The Information Technology Governance, Risk, and Compliance (GRC) team supports Tallgrass's cybersecurity risk and compliance program across the enterprise. This includes cyber risk management, policy and standards governance, third-party risk management, contractual cybersecurity review, compliance monitoring, control assessments, security awareness, and audit readiness.
The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy's cybersecurity posture by assessing risk, evaluating controls, supporting compliance obligations, and recommending practical safeguards to reduce risk. This role serves as a key advisor to business and technology stakeholders and helps ensure cybersecurity requirements are understood, documented, and implemented effectively.
This position also serves as the security function's primary reviewer of incoming contractual cybersecurity language and works closely with Legal, Supply Chain/Sourcing, IT, Security Operations, Engineering, and business stakeholders on contract reviews, obligation mapping, risk assessments, issue management, and control governance.
Essential Duties & Responsibilities:
Governance, Risk, and Compliance:
Regulatory Compliance and Audit Support:
Contractual Cybersecurity Review:
Serve as the security function's primary reviewer of incoming contractual cybersecurity language, including customer, vendor, supplier, and third-party agreements.
Partner with Legal, Supply Chain/Sourcing, business stakeholders, and technology teams to review cybersecurity, privacy, compliance, and risk-related contract provisions.
Provide recommended redlines and risk-based guidance for contract requirements related to data protection, access control, incident notification, audit rights, regulatory compliance, business continuity, disaster recovery, subcontractor flow-downs, vulnerability management, and security assessments.
Assess proposed contractual requirements against Tallgrass cybersecurity policies, standards, technical capabilities, regulatory obligations, and existing controls.
Map contractual obligations to applicable frameworks, regulatory requirements, internal policies, standards, and controls.
Identify contractual cybersecurity gaps, operational risks, and potential control deficiencies; recommend mitigation options and track related actions through completion.
Third-Party Risk Management:
Support the cybersecurity third-party risk management program for vendors, service providers, contractors, and other third parties that access Tallgrass systems, data, facilities, or networks.
Review vendor security questionnaires, SOC reports, certifications, penetration test summaries, policies, and other due diligence documentation.
Assess third-party security controls against company policies, standards, regulatory requirements, contractual obligations, and industry best practices.
Partner with Legal, Procurement, Privacy, business owners, and Cyber Security to define proportionate contract and security requirements.
Support ongoing monitoring and reassessment of critical third parties.
Threat, Vulnerability, IAM, and Security Awareness Governance:
Provide GRC oversight of threat and vulnerability management activities, including remediation tracking, exception handling, risk reporting, and alignment with policy and regulatory requirements.
Partner with IT Security, infrastructure, application, and operational technology teams to monitor vulnerability findings, remediation plans and overdue items.
Provide GRC oversight of identity and access management controls, including user access reviews, privileged access governance, provisioning and deprovisioning, segregation of duties, and exception management.
Support cybersecurity awareness and training activities, including training coordination, completion tracking, phishing simulation metrics, policy acknowledgments, and employee security communications.
Support records and information governance activities related to cybersecurity, privacy, data handling, information classification, retention, legal hold, evidence management, and compliance requirements.
Maintain awareness of cybersecurity trends, regulatory developments, risk management practices, and industry standards.
Education:
Bachelor's degree from an accredited college or university.
Minimum of five years of experience in cybersecurity, information security, risk management, risk assurance, compliance, third-party risk management, audit, or a related field may be considered as a substitute for a degree
Experience/Specific Knowledge:
Certifications, Licenses & Registrations:
Competencies, Skills & Abilities:
Physical Demands:
Working Conditions:
Supervisory Responsibility:
Preferred Education, Experience, Certifications, Competencies, Skills & Abilities:
Above the minimum requirements, not required but advantageous in this position:
Compensation:
Other Responsibilities:
| Location | Lakewood, CO |
| Salary | $105,400–$158,200 Per Year |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder