Rejobs

Analytik kybernetické bezpečnosti

Připojte se k NextEra Energy v Saint Paul jako analytik kybernetické bezpečnosti. Podporujte řízení rizik, bezpečnostní hodnocení a nápravná opatření s využitím AI nástrojů. Nabízíme podporu při přestěhování a komplexní benefity.

Na pracovišti Plný úvazek UTC-06:00 Aktualizováno dnes
Plat
88 000–132 000 US$ /rok

Přihláška na jobs.nexteraenergy.com

Zkontrolujte svou schránku.

Na mobilu? K přihlášce se můžete vrátit později z počítače.

NextEra Analytics offers energy consulting services using industry-leading scientific analysis for planning, siting, forecasting and optimizing all forms of energy projects. Our optimization and analytics platforms integrate open-source technologies to leverage massive, diverse sets of utility operating data. This enables rapid development of operational solutions. Applying expertise in advanced mathematics, data and physical sciences, we solve some of the hardest problems facing the energy industry.

We are seeking a cybersecurity professional to support the continued development and execution of NEA's cybersecurity risk management program. This role will coordinate security assessments, third-party risk reviews, application security evaluations, penetration testing activities, and remediation tracking across the organization.

The successful candidate will work closely with engineering teams, application owners, vendors, and business stakeholders to identify cybersecurity risks, document findings, and drive issues through resolution. This individual will also help standardize cybersecurity processes, reporting, and governance while using AI-enabled tools to improve analysis, efficiency, and decision-making.

Key Responsibilities & Expectations

1. Cybersecurity Risk Management

  • Security Assessments: Support cybersecurity assessments and risk reviews across applications, platforms, vendors, and technology solutions.
  • Risk Documentation: Document identified risks, control gaps, findings, compensating controls, and formal risk decisions.
  • Remediation Management: Track cybersecurity findings and remediation activities through validation and closure. Support risk acceptance and exception handling, including documenting formal security decisions when remediation is deferred.

2. Third-Party and Application Security

  • Third-Party Risk Assessments: Support security assessments for vendors, SaaS platforms, development tools, and AI-enabled solutions.
  • Application Security Reviews: Coordinate security reviews for applications and technology tools, including evidence collection, documentation, findings management, and stakeholder follow-up.
  • Stakeholder Coordination: Partner with application owners, engineering teams, vendors, and business stakeholders to obtain required information and resolve identified concerns.

3. Security Testing and Resiliency

  • Penetration Testing Coordination: Support penetration testing activities, including scheduling, scope coordination, results management, remediation tracking, and reporting.
  • Critical Application Resiliency: Assist with resiliency assessments for critical applications by organizing documentation, evaluating risk information, and tracking required actions.
  • Issue Resolution: Work with technical and business teams to identify appropriate remediation plans and ensure cybersecurity risks are addressed in a timely manner.
  • Audit Prep: Assist with audit and evidence requests by organizing support materials, tracking responses, and confirming completeness.

4. Governance, Reporting, and Process Improvement

  • Risk and Assessment Inventories: Maintain accurate inventories of assessed applications, vendors, findings, risk decisions, and remediation status.
  • Standardized Processes: Develop and maintain consistent assessment templates, workflows, procedures, reports, and dashboards.
  • Program Reporting: Provide clear and actionable reporting on cybersecurity risks, assessment activity, remediation progress, and program performance. Analyze recurring findings, remediation patterns, and program trends to help prioritize work and improve the overall cybersecurity program.
  • Continuous Improvement: Identify opportunities to improve the consistency, scalability, and effectiveness of cybersecurity review processes.

5. AI-Enabled Cybersecurity Productivity

  • AI-Assisted Analysis: Use AI assistants and related tools to improve cybersecurity research, risk analysis, documentation, and decision support.
  • Workflow Efficiency: Apply AI-enabled capabilities to streamline evidence review, reporting, remediation tracking, and other repeatable cybersecurity activities.
  • Responsible Adoption: Validate AI-generated outputs, protect sensitive information, and ensure responsible use of AI tools in cybersecurity work.

6. Collaboration and Ownership

  • Cross-Functional Partnership: Collaborate with engineering, application owners, cybersecurity teams, vendors, and business stakeholders to identify security gaps and support remediation.
  • Clear Communication: Translate cybersecurity risks and technical findings into clear, business-relevant language.
  • Ownership and Accountability: Manage assigned assessments and findings from initiation through completion while communicating risks, dependencies, and delays proactively. Apply working knowledge of application security and DevSecOps practices, including vulnerability management concepts and secure delivery workflows.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or equivalent practical experience.
  • Experience supporting cybersecurity risk assessments, security compliance activities, application security reviews, or third-party risk management.
  • Familiarity with cybersecurity controls, risk management concepts, vulnerability management, and remediation practices.
  • Experience coordinating work across technical teams, business stakeholders, and external vendors.
  • Strong organizational skills with the ability to manage documentation, findings, deadlines, and multiple concurrent assessments.
  • Strong written and verbal communication skills, including the ability to explain cybersecurity risks to both technical and nontechnical audiences.
  • Experience using reporting, workflow, ticketing, governance, risk, and compliance tools.
  • Familiarity with GRC, workflow, or case management tools used for risk tracking and remediation.
  • Experience with vulnerability management, security review coordination, or penetration test support.
  • Basic familiarity with application security and DevSecOps concepts such as SAST, SCA, DAST, CI/CD, and secure coding.
  • Ability to use AI assistants and related technologies responsibly to improve analysis, documentation, and workflow efficiency.
  • Ability to validate AI-assisted outputs and handle sensitive information appropriately.

Job Overview

This job performs ongoing cybersecurity risk reviews for new and existing technologies and services and supports ongoing and new cybersecurity projects. Individuals develop requirements for and implement technical security projects and tools, as well as define the company's cybersecurity policies and control framework. This position collaborates with the company's IT department and business units to identify the need for, select, and deploy technical controls to meet specific security requirements. Employees in this role build processes and standards to ensure security requirements continue to be met.

Job Duties & Responsibilities

  • Administers, operates and monitors NextEra Energy (NEE) information security sensors, logging, alerting and other detection mechanisms to identify and respond to threats
  • Develops a subject matter expertise for one or multiple assigned cybersecurity technology stacks (e.g., identity and access management, network intrusion detection and prevention, host based security tools)
  • Collaborates with security architecture to identify, evaluate and recommend new security technologies for suitability within NEE's environment and security posture
  • Communicates ongoing cybersecurity activities, priorities and risk measurements or mitigations at multiple organizational levels
  • Provides guidance for security activities and requirements in the system development life cycle (SDLC) and application development efforts. Participates in organizational projects, as required
  • Performs other job-related duties as assigned

Required Qualifications

  • High School Grad / GED
  • Bachelor's or Equivalent Experience
  • Experience: 2+ years

Preferred Qualifications

  • Certified Information Systems Aud (CISA) certification

The estimated base pay for this position is $88,000.00 to $132,000.00 per year. Starting pay will be based on several factors including, but not limited to, experience, qualifications, job-related and industry knowledge and skills and education/training.

NextEra Energy offers a wide range of benefits to support our employees and their eligible family members. Click here to learn more.

Employee Group: Exempt
Employee Type: Full Time
Job Category: Information Technology
Organization: NextEra Analytics, Inc
Relocation Provided: Yes, if applicable

NextEra Energy is an Equal Opportunity Employer. Qualified applicants are considered for employment without regard to race, color, age, national origin, religion, marital status, sex, sexual orientation, gender identity, gender expression, genetics, disability, protected veteran status or any other basis prohibited by law.

NextEra Energy provides reasonable accommodation in its application and selection process for qualified individuals, including accommodations related to compliance with conditional job offer requirements, consistent with federal, state, and local laws. Supporting medical or religious documentation will be required where applicable and permitted by applicable law. To request a reasonable accommodation, please send an e-mail to [email protected], providing your name, telephone number and the best time for us to reach you.

NextEra Energy will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information.

NextEra Energy does not accept any unsolicited resumes or referrals from any third-party recruiting firms or agencies. Please see our policy for more information.

Plat a benefity

88 000–132 000 US$ /rok
Zdravotní pojištění Penzijní připojištění Placené volno Příspěvek na stěhování

O této pozici

Zveřejněno
7 říj 2026
Aktualizováno
7 říj 2026
Typ úvazku
Plný úvazek
Pracoviště
Na pracovišti
Sektory
Pracovní doba
UTC-06:00
Zkušenosti
2+ years
Zaměstnavatelnexteraenergy.com

O společnosti NextEra Energy

Přehled společnosti

Název

NextEra Energy, Inc.

Ústředí

Juno Beach, Florida, Spojené státy

Založeno

1925

Velikost

Přibližně 16 800 zaměstnanců (zdroj: stockanalysis.com). Příjmy ve výši 24,8 miliardy dolarů v roce 2024 (zdroj: stockanalysis.com).

Co dělají

NextEra Energy se zaměřuje na výrobu obnovitelné energie, především prostřednictvím své dceřiné společnosti NextEra Energy Resources (NEER), která provozuje největší flotilu větrných a solárních zařízení na světě. Společnost se zavázala k pokroku v technologiích čisté energie, včetně skladování energie, zemního plynu, jaderné energie a zařízení na výrobu ropy, s celkovou výrobní kapacitou 73 gigawattů k roku 2024. Jejich produktové nabídky zahrnují výrobu, přenos, distribuci a prodej elektřiny, přičemž mají významnou přítomnost na Floridě prostřednictvím Florida Power & Light (FPL), která obsluhuje miliony zákazníků. Kromě toho se NEER podílí na velkoobchodní výrobě čisté energie po celé Severní Americe, využívajíc velkokapacitní větrné farmy a solární elektrárny, jako je významné DeSoto Next Generation Solar Energy Center, které bylo největší solární elektrárnou v USA při svém vzniku (zdroj: nexteraenergy.com).

Projekty a úspěchy

NextEra Energy má bohatou historii významných projektů, které zdůrazňují její vedení v oblasti obnovitelné energie. Mezi nimi je větrná farma Vansycle Ridge v Oregonu, která byla prvním větrným místem společnosti založeným v roce 1998. Stateline Wind Energy Center, dokončené v roce 2001, bylo v té době uznáno jako největší větrná farma na světě, což ukazuje na rychlý růst společnosti v oblasti větrné energie. V roce 2009 byla uvedena do provozu DeSoto Next Generation Solar Energy Center jako největší zařízení na výrobu solární energie v USA, následovaná Martin Next Generation Solar Energy Center v roce 2011, která byla prvním hybridním zařízením na výrobu solární energie a zemního plynu na světě. Tyto projekty podtrhují závazek NextEra k inovacím a vedení v sektoru obnovitelné energie (zdroj: nexteraenergy.com).

Poslední vývoj

V posledních letech učinila společnost NextEra Energy významné kroky v rozšiřování svých operací a partnerství. V červnu 2024 společnost zajistila prodej akcií v hodnotě 2 miliardy dolarů společnosti BofA Securities a Wells Fargo Securities, čímž posílila svou finanční pozici pro budoucí projekty. Dále bylo 8. prosince 2025 oznámeno významné partnerství s Google Cloud, jehož cílem je poskytnout 15 gigawattů energie pro datová centra do roku 2035. Kromě toho společnost přejmenovala NextEra Energy Partners na XPLR Infrastructure v roce 2025, což odráží její zaměření na správu smluvních projektů čisté energie. Tyto události ilustrují proaktivní přístup NextEra k růstu a inovacím v oblasti obnovitelné energie (zdroj: wikipedia.org).

Práce zde

NextEra Energy nabízí širokou škálu rolí napříč různými odděleními, včetně inženýrství, řízení produktů, prodeje, marketingu, operací, financí a výkonného vedení. Ústředí společnosti v Juno Beach slouží jako hlavní centrum pro tyto pozice, zatímco příležitosti jsou také k dispozici na projektových místech po celé USA a Kanadě. Firemní kultura zdůrazňuje inovace, spolupráci a neustálé učení, podporována moderními zařízeními v ústředí, jako jsou flexibilní pracovní prostory, fitness centra a wellness místnosti. Zaměstnanci těží z komplexních balíčků, které podporují profesní rozvoj a pohodu, ačkoli konkrétní detaily o zdravotních plánech a PTO nejsou podrobně zdokumentovány (zdroj: salestools.io).

Vaše propojení na LinkedIn

Podívejte se na své kontakty ve společnosti NextEra Energy na LinkedIn a využijte svou síť při podávání přihlášky.

Zobrazit spojení

Další podobné pozice chytré sítě

Analytik kybernetické bezpečnosti
NextEra Energy · 88 000–132 000 US$/rok