About the role: Eagle Creek Renewable Energy is seeking an experienced Information Security Compliance Analyst to join our team and help safeguard our organizations regulatory standing and the security of the critical generation assets across our fleet of hydropower facilities. The ideal candidate will have a strong background in monitoring network security, investigating breaches, and implementing strategies to maintain a secure environment in support of regulatory compliance, with the ability to translate complex requirements into clear, defensible, and well-documented controls. In addition, knowledge and experience with NERC CIP and NIST standards are essential for this role.
What You'll Do:
What Skills and Experience You'll Need:
Education and Experience:
Bachelor's degree in information security, information systems, business, engineering, or a related field, or equivalent experience.
Proven experience in regulatory compliance, audit, GRC, or internal controls, ideally in electric utility, energy, or another regulated or critical-infrastructure environment.
Working knowledge of the NERC CIP compliance lifecycle, including self-certification, self-reporting, mitigation, and audit.
Compliance and Regulatory Knowledge:
In-depth knowledge of security technologies, such as firewalls, intrusion detection systems, antivirus software, encryption methods, and vulnerability scanning tools.
Familiarity with industry security standards and frameworks, including NERC CIP and NIST.
Analytical Skills:
Excellent analytical and problem-solving abilities to translate regulatory requirements into practical, defensible controls.
Ability to assess complex, multi-site environments and identify compliance gaps and risks.
Communication and Collaboration:
Strong written communication and documentation discipline to produce audit-ready evidence and clear compliance reporting.
Ability to collaborate and work cross-functionally with teams such as IT, operational technology, physical security, legal, and management.
Certifications (preferred):
Certified Information Systems Security Professional (CISSP).
Certified Information Systems Auditor (CISA).
Certified in Risk and Information Systems Control (CRISC).
Global Industrial Cyber Security Professional (GICSP) or NERC CIP compliance training.
| Location | Minneapolis, MN |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder