Quick Overview
Salary
$105.4k - $158.2k/yr
Work Type
Hybrid
Level
Mid Senior
Job Description
Job Description
Primary purpose:
Responsibilities
Essential Duties & Responsibilities:
Governance, Risk, and Compliance:
Regulatory Compliance and Audit Support:
Contractual Cybersecurity Review:
Third-Party Risk Management:
Threat, Vulnerability, IAM, and Security Awareness Governance:
Qualifications
Education:
Experience/Specific Knowledge:
Certifications, Licenses & Registrations:
Competencies, Skills & Abilities:
Physical Demands:
Working Conditions:
Supervisory Responsibility:
Preferred Education, Experience, Certifications, Competencies, Skills & Abilities:
Above the minimum requirements, not required but advantageous in this position:
Compensation:
Other Responsibilities:
About Us
Tallgrass was named one of the Top Workplaces USA and highlighted in Colorado's Top Workplaces for the past seven consecutive years. Tallgrass is a leading energy infrastructure company focused on safely, reliably, and sustainably delivering the energy and services that power our nation and enable our quality of life.
At Tallgrass, we value our teams and strive to create an environment where employees feel respected, and their contributions are valued. We aim to support employees' physical, mental, and financial well-being through a comprehensive Total Rewards Program.
Application Deadline: Recruiting timelines vary by position; however, all Tallgrass positions accept applications for at least five business days from the posting date. This position is open and still accepting applications.
Compensation: Compensation ranges are provided in good faith based on what we anticipate when researching wages for this position at the state and national levels. We may ultimately pay more or less than the posted range. This salary range may also be modified in the future.
Notice to External Search Firms: Tallgrass does not accept unsolicited resumes from search firms or employment agencies. Unsolicited referrals and resumes are considered Tallgrass property; therefore, Tallgrass will not pay a fee for any placement resulting from the receipt of an unsolicited referral. Approved vendors may be invited to refer talent for specific positions at Tallgrass's request only. A fully executed agreement with Tallgrass must be in place and current in these cases.
EEO Statement: Tallgrass complies with all Equal Employment Opportunity (EEO) affirmative action laws and regulations. Tallgrass does not discriminate on the basis of age, race, religion, color, sex, national origin, marital status, genetic information, sexual orientation, gender Identity and expression, disability, veteran status, pregnancy status, or other status protected by law.
Primary purpose:
- The Information Technology Governance, Risk, and Compliance (GRC) team supports Tallgrass's cybersecurity risk and compliance program across the enterprise. This includes cyber risk management, policy and standards governance, third-party risk management, contractual cybersecurity review, compliance monitoring, control assessments, security awareness, and audit readiness.
- The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy's cybersecurity posture by assessing risk, evaluating controls, supporting compliance obligations, and recommending practical safeguards to reduce risk. This role serves as a key advisor to business and technology stakeholders and helps ensure cybersecurity requirements are understood, documented, and implemented effectively.
- This position also serves as the security function's primary reviewer of incoming contractual cybersecurity language and works closely with Legal, Supply Chain/Sourcing, IT, Security Operations, Engineering, and business stakeholders on contract reviews, obligation mapping, risk assessments, issue management, and control governance.
Responsibilities
Essential Duties & Responsibilities:
Governance, Risk, and Compliance:
- Support the execution and continuous improvement of the cybersecurity GRC program, including governance, risk assessment, compliance monitoring, control evaluation, and issue management activities.
- Assist with the development, maintenance, communication, and governance of cybersecurity policies, standards, procedures, control requirements, ownership expectations, evidence requirements, and exception processes
- Clarify control owner accountability by helping define control ownership, evidence expectations, remediation obligations, and reporting requirements.
- Conduct or support cybersecurity risk assessments, control evaluations, compliance assessments, and audit readiness activities.
- Track risks, findings, exceptions, remediation plans, risk acceptances, and closure evidence through completion.
- Develop compliance matrices, control mappings, gap analyses, risk summaries, and management-level reporting/dashboards.
Regulatory Compliance and Audit Support:
- Support compliance efforts related to applicable cybersecurity and regulatory requirements, including TSA Security Directives, privacy requirements, and NERC CIP, where applicable.
- Monitor relevant regulatory and industry developments and assist with interpreting, coordinating, and tracking required actions.Support internal and external audits, regulatory reviews, compliance assessments, customer security inquiries, and evidence-gathering activities.
- Partner with control owners to collect, validate, and maintain evidence of control design and operating effectiveness.
- Track open compliance and audit findings, prepare status updates, and escalate aging or high-risk items as appropriate.
Contractual Cybersecurity Review:
- Serve as the security function's primary reviewer of incoming contractual cybersecurity language, including customer, vendor, supplier, and third-party agreements.
- Partner with Legal, Supply Chain/Sourcing, business stakeholders, and technology teams to review cybersecurity, privacy, compliance, and risk-related contract provisions.
- Provide recommended redlines and risk-based guidance for contract requirements related to data protection, access control, incident notification, audit rights, regulatory compliance, business continuity, disaster recovery, subcontractor flow-downs, vulnerability management, and security assessments.
- Assess proposed contractual requirements against Tallgrass cybersecurity policies, standards, technical capabilities, regulatory obligations, and existing controls.
- Map contractual obligations to applicable frameworks, regulatory requirements, internal policies, standards, and controls.
- Identify contractual cybersecurity gaps, operational risks, and potential control deficiencies; recommend mitigation options and track related actions through completion.
Third-Party Risk Management:
- Support the cybersecurity third-party risk management program for vendors, service providers, contractors, and other third parties that access Tallgrass systems, data, facilities, or networks.
- Review vendor security questionnaires, SOC reports, certifications, penetration test summaries, policies, and other due diligence documentation.
- Assess third-party security controls against company policies, standards, regulatory requirements, contractual obligations, and industry best practices.
- Partner with Legal, Procurement, Privacy, business owners, and Cyber Security to define proportionate contract and security requirements.
- Support ongoing monitoring and reassessment of critical third parties.
Threat, Vulnerability, IAM, and Security Awareness Governance:
- Provide GRC oversight of threat and vulnerability management activities, including remediation tracking, exception handling, risk reporting, and alignment with policy and regulatory requirements.
- Partner with IT Security, infrastructure, application, and operational technology teams to monitor vulnerability findings, remediation plans and overdue items.
- Provide GRC oversight of identity and access management controls, including user access reviews, privileged access governance, provisioning and deprovisioning, segregation of duties, and exception management.
- Support cybersecurity awareness and training activities, including training coordination, completion tracking, phishing simulation metrics, policy acknowledgments, and employee security communications.
- Support records and information governance activities related to cybersecurity, privacy, data handling, information classification, retention, legal hold, evidence management, and compliance requirements.
- Maintain awareness of cybersecurity trends, regulatory developments, risk management practices, and industry standards.
Qualifications
Education:
- Bachelor's degree from an accredited college or university.
- Minimum of five years of experience in cybersecurity, information security, risk management, risk assurance, compliance, third-party risk management, audit, or a related field may be considered as a substitute for a degree
Experience/Specific Knowledge:
- Experience conducting or supporting risk assessments, control evaluations, compliance assessments, vulnerability assessments, and audit readiness activities.
- Experience reviewing cybersecurity, privacy, compliance, or risk-related contract language.
- Experience mapping contractual, regulatory, customer, or internal requirements to cybersecurity frameworks, policies, standards, controls, and evidence.
- Experience supporting third-party/vendor risk management, including vendor due diligence, security assessments, remediation tracking, and ongoing monitoring.
- Experience reviewing vendor security documentation, such as SOC 1/SOC 2 reports, ISO certifications, security questionnaires, policies, control attestations, or penetration test summaries.
- Proficiency with risk assessment methodologies, tools, and techniques.
- Strong understanding of cybersecurity controls, risk management, business continuity, disaster recovery, control ownership, and exception governance.
- Familiarity with GRC tools, third-party risk management platforms, or similar systems.
- Understanding of cybersecurity frameworks, standards, and best practices, such as NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, SOC 2 Trust Services Criteria, TSA Security Directives, and applicable privacy requirements.
- Ability to communicate governance, risk, compliance, and audit concepts effectively to technical teams, business stakeholders, and executives.
Certifications, Licenses & Registrations:
- Must possess and maintain a valid driver's license and a driving record satisfactory to the company and its insurers (for travel).
Competencies, Skills & Abilities:
- Strong written and verbal communication skills, including the ability to explain technical or control requirements to non-technical stakeholders.
- Ability to organize competing priorities, meet deadlines, and maintain accurate documentation.
- Sound judgment, accountability, and professionalism when handling sensitive company information.
- Ability to work collaboratively across functional boundaries and influence outcomes without relying solely on reporting authority.
- Strong analytical, research, interviewing, negotiation, and evidence-management skills.
- Ability to apply a risk-based approach to determine the appropriate depth of review.
Physical Demands:
- All the physical requirements listed below are those that may be necessary for an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made for individuals with disabilities to perform the essential functions.
- Must be able to sit for prolonged periods of time.
- The employee is regularly required to use hands to type, touch, handle, or feel; talk and hear; and frequently stand and reach with hands and arms.
- The employee is occasionally required to walk, climb, balance, bend, stoop, squat, crouch, kneel, push, or pull.
- The employee must regularly lift or move up to 10 pounds and occasionally lift or move up to 25 pounds.
Working Conditions:
- Will work non-traditional hours as needed.
- Required to carry a cell phone and be available to respond during working and non-working hours when assigned.
- Candidates will be required to clear a drug screen and complete a background check, including a credit report for certain positions after an offer has been extended and prior to being employed.
Supervisory Responsibility:
- No direct supervisory responsibility. Coordinates vendor, business-owner, and control-owner actions through the assessment lifecycle.
Preferred Education, Experience, Certifications, Competencies, Skills & Abilities:
Above the minimum requirements, not required but advantageous in this position:
- CRISC, CISA, CISM, CISSP, enterprise-risk, audit, or comparable certification,
- Experience with governance, risk, compliance, workflow, or analytics platforms.
- Experience assessing technology vendors in energy, infrastructure, or another regulated industry.
Compensation:
- The annual salary range for this position will be $105,400-$158,200/yr.
Other Responsibilities:
- The above statements describe the general nature and level of work being performed. This position may perform other duties as assigned.
About Us
Tallgrass was named one of the Top Workplaces USA and highlighted in Colorado's Top Workplaces for the past seven consecutive years. Tallgrass is a leading energy infrastructure company focused on safely, reliably, and sustainably delivering the energy and services that power our nation and enable our quality of life.
At Tallgrass, we value our teams and strive to create an environment where employees feel respected, and their contributions are valued. We aim to support employees' physical, mental, and financial well-being through a comprehensive Total Rewards Program.
- Industry competitive pay
- Health insurance package options that include Flexible Spending & Health Savings Accounts
- Infertility Coverage
- Parental Leave
- 401(k) with up to a 6% match that vests immediately plus an employer discretionary contribution of up to 4%
- Wellness Programs and Mental Health Resources
- Employer-paid life insurance, short-term disability, and long-term disability coverage
- Critical Illness & Accident Insurance
- Vacation, sick days, paid caregiver leave, volunteer and bereavement paid time off
- Identity theft protection
- Annual discretionary bonus
- Generous Tuition Reimbursement Program
- Company-paid holidays and floating holidays
- Company vehicle (if applicable)
- Employee discounts; vehicles, tires, cellular plans, and more
- Networking and employee engagement events
- Personal development to grow your career with us based on your strengths and interests
Application Deadline: Recruiting timelines vary by position; however, all Tallgrass positions accept applications for at least five business days from the posting date. This position is open and still accepting applications.
Compensation: Compensation ranges are provided in good faith based on what we anticipate when researching wages for this position at the state and national levels. We may ultimately pay more or less than the posted range. This salary range may also be modified in the future.
Notice to External Search Firms: Tallgrass does not accept unsolicited resumes from search firms or employment agencies. Unsolicited referrals and resumes are considered Tallgrass property; therefore, Tallgrass will not pay a fee for any placement resulting from the receipt of an unsolicited referral. Approved vendors may be invited to refer talent for specific positions at Tallgrass's request only. A fully executed agreement with Tallgrass must be in place and current in these cases.
EEO Statement: Tallgrass complies with all Equal Employment Opportunity (EEO) affirmative action laws and regulations. Tallgrass does not discriminate on the basis of age, race, religion, color, sex, national origin, marital status, genetic information, sexual orientation, gender Identity and expression, disability, veteran status, pregnancy status, or other status protected by law.
Skills
SOC 2
Compliance
Continuous Improvement
Due Diligence
Employee Engagement
LESS
Mental Health
Procurement
Recruiting
Regulatory Compliance
Risk Assessment
Risk Management
Sourcing
Similar jobs
Bank Platform Transformation - Integration Architect-Engineer - Sr Associate
PricewaterhouseCoopers LLP · Atlanta, United States
5 minutes ago$77k - $202k/yrVMWare SME
Avtech Solutions · United States
5 minutes agoEvent Manager
Talent Software Services, Inc · Cambridge, United States
5 minutes agoApplication Architect III- #26-19111
U.S. Tech Solutions Inc. · Fredericton, United States
7 minutes agoInterim Executive Director over Network Infrastructure-W-2 ONLY
United Global Technologies · Columbia, United States
7 minutes agoInstructional Designer / Graphic Designer
Aptara, Inc. · United States
7 minutes ago€45/hr