Lead Analyst, Cyber Security Compliance
If you have what it takes to become part of the Vistra family and would like to start a promising career with a global leader, take a look at the exciting employment opportunities that are currently available and apply online.
Job Summary
Lead Analyst will maintain extensive knowledge of Vistra Compliance regulations. Develop, implement and maintain program procedures, processes and tools. Lead the development of interpretations of Standards and guidance documents to produce unambiguous descriptions of compliance obligations for internal stakeholders and summarize impact for company executives. Administer proprietary internal control system. Ensure required documentation to evidence compliance is accurate and effective. Facilitate internal and external audit activities. Investigate variances and escalate when needed. Perform root cause analysis in instances of non-compliance. Design and manage corrective action plans. Exercise critical thinking and problem solving to research and document processes supporting applicable regulations.Job Description
Key Accountabilities
•Perform assigned duties with high degree of accuracy and consistency.
•Accurately interpret regulations and design processes that inherently result in compliance behavior and evidence without adding undue administrative burden to plant staff.
•Maintaining positive relationships with plant teams, vendors, governmental agencies, in order to promote cooperative working relationships.
•Support technology key controls and compliance with regulatory requirements (i.e. ERCOT, NERC-CIP, etc), and corporate technology management and internal audit requirements.
•Identify opportunities for efficiency and automation within compliance controls.
•Support projects such that they are deployed within performance, cost, and schedule targets without disrupting compliance requirements.
•Support metrics processes that track the status of compliance and compliance tool effectiveness and health.
•Participate in a departmental culture that fosters accountability for results while promoting the use of diverse backgrounds and experiences.
Education, Experience, & Skill Requirements
Required:
•Experienced gained through college degree programs and/or certification in business or technology related field, or equivalent experience.
•7-10 years' experience with an understanding in one or more of the following: NERC CIP, ERCOT Protocols, ISO 27001, NIST 800-53, SOX, PCI, NACHA , NRC.
•Demonstrate ability to be trustworthy and dependable
•Exceptional reading comprehension and written communication skills
•Demonstrate ability to learn quickly, be self-motivated to improve knowledge base and tackle new challenges
•Demonstrate ability to facilitate agreement across a wide range of disparate stakeholders
•Demonstrate a working knowledge of application development or a coding technology language such as (VBA, PowerShell, Python, Ruby, C++, etc.)
Preferred:
•Experience with ICS devices, Generation, Transmission assets
•Understand Human Performance Improvement principles
•Working knowledge of agile framework and methodologies
•Experience with Cloud security & compliance best practices
•Professional certification a plus (e.g., CISM, CISA, CISSP, Digital Design)
Key Metrics
Compliance Metrics:
•% of planned work completed on time and on-budget
•% of compliance controls completed on time
•% of control performance effectiveness
•% of control performance automation
Job Family
Information TechnologyCompany
Vistra Corporate Services CompanyLocations
Irving, TexasTexasWe are a company of people committed to: Exceeding Customer Expectations, Great People, Teamwork, Competitive Spirit and Effective Communication. If this describes you, then apply today!
If you currently work for Vistra or its subsidiaries, please apply via the internal career site.
It is the policy of the Company to comply with all employment laws and to afford equal employment opportunity to individuals in all aspects of employment, including in selection for job opportunities, without regard to race, color, religion, sex, sexual orientation, gender identity, pregnancy, national origin, age, disability, genetic information, military service, protected veteran status, or any other consideration protected by federal, state or local laws.