Associate Cybersecurity Governance & Risk Analyst
Job Description
This entry-level position supports the Cybersecurity Architecture & Consulting team at Duke Energy by assisting with cybersecurity architecture, governance, risk, and process-driven activities. The role emphasizes intake, documentation quality, baseline support, and research aligned to recognized security guidance.
Location and Work Setup
- Location: Charlotte, NC
- Work model: Hybrid (remote and onsite after onboarding)
- Commute requirement: Hybrid employees must live within a reasonable commute to a designated Duke Energy facility, not greater than 50 miles one way
- Onsite expectation: Employees are expected to report to their assigned facility as required and directed by their manager, on average 3 full workdays per regular workweek
- Work environment: Office environment
Education
- Required: Associate degree in Cybersecurity or other related degree
- Alternative: High School/GED + 2 years related work experience (in lieu of the associate degree)
Responsibilities
- Perform initial intake reviews and completeness checks for TASR and SRT submissions
- Validate submissions against established cybersecurity policies, standards, security requirements, and approved architectures
- Conduct preliminary risk assessments, identify security gaps, and escalate higher-risk or complex matters to senior architects or subject matter experts
- Coordinate with requestors to obtain missing documentation, evidence, or technical information
- Support vendor and technology due diligence activities
- Track workflow status, review metrics, and reporting requirements
- Prepare review summaries, recommendations, and supporting documentation for senior architects and subject matter experts
- Document architecture requirements, decisions, risk dispositions, and follow-up actions
- Research CIS Benchmarks, NIST guidance, vendor hardening recommendations, regulatory requirements, and other recognized security practices
- Assist with drafting, updating, and maintaining MSB and CMSB documents
- Coordinate stakeholder reviews, validation activities, and approval workflows
- Track baseline review cycles, lifecycle activities, and outstanding actions
- Collect and organize supporting evidence and implementation documentation
- Maintain baseline repositories, templates, and related records
- Assist with publishing approved baselines and communicating updates
- Document implementation guidance and architecture considerations
- Support Cybersecurity Architecture intake management, workflow coordination, and repository maintenance
- Assist with CAR preparation, including intake validation, documentation quality reviews, evidence collection, and action-item tracking
- Maintain architecture standards, procedures, reference materials, and architecture decision records
- Coordinate architecture consultations, stakeholder meetings, and follow-up activities
- Prepare clear documentation of architecture recommendations and requirements
- Provide customer support by communicating issues, requirements, and resolutions to requestors, management, and architecture stakeholders
- Collect, validate, and analyze architecture performance metrics
- Support dashboard reporting, risk-reduction tracking, trend analysis, and operational reporting
- Gather evidence supporting architecture outcomes, control implementation, and process performance
- Assist with quality assurance reviews of architecture deliverables and identify opportunities for process improvement
- Monitor assigned work to meet established schedules and escalate barriers or risks as appropriate
- Research emerging technologies, cloud services, artificial intelligence, agentic AI, and related cybersecurity requirements
- Assist with technology evaluations, cybersecurity control mapping, and security framework analysis
- Monitor relevant industry trends, vendor capabilities, and changes to security guidance
- Develop draft architecture guidance, recommendations, and educational materials for review by senior team members
- Demonstrate working knowledge of IT and cybersecurity policies, standards, processes, controls, tools, and functional areas
- Perform or assist with security reviews, control assessments, risk assessments, and technical project work of a less complex nature
- Collaborate with cybersecurity leadership, architects, subject matter experts, business partners, and technology teams
- Apply cybersecurity process and control knowledge to support compliance and risk-management objectives
- Protect confidential information and perform assigned work with integrity, sound judgment, and appropriate supervisory review
- Develop technical, consulting, and architecture skills with progression toward greater complexity and independence over time
Required Qualifications
- Associate degree in Cybersecurity or other related degree
- In lieu of associate degree(s): High School/GED + 2 years related work experience
- Experience: 0 to 2 years of utility, cybersecurity, auditing, compliance, regulatory, or related experience
- Working knowledge of cybersecurity frameworks and guidance, including NIST and CIS Benchmarks
- Knowledge of cybersecurity risk-management processes and methods for identifying, assessing, and mitigating risk
- Knowledge of IT and cybersecurity policies, standards, procedures, controls, compliance requirements, and security configuration guidance
- Ability to research current technologies and understand system, network, cloud, vendor, and emerging technology capabilities
- Ability to evaluate, analyze, and synthesize technical and process information into clear, high-quality work products
- Experience or interest in conducting technical reviews, control assessments, impact assessments, or risk assessments
- Knowledge of IT supply-chain security and supply-chain risk-management practices
- Strong written and verbal communication, listening, documentation, organization, and customer-support skills
- Ability to work effectively with defined direction, accept coaching and feedback, and progress toward greater independence
- Ability to manage multiple assignments, follow established processes, meet schedules, and escalate issues appropriately
- Ability to manage confidential information with a high degree of integrity
- Interest in cybersecurity architecture, cloud security, artificial intelligence security, technology governance, metrics, and continuous improvement
Technologies and Security Guidance
- CIS Benchmarks
- NIST guidance
- Cloud services
- Artificial intelligence
- Agentic AI
Travel and Sponsorship
- Travel: Not required
- Relocation: Not provided
- Union/represented position: No
- Visa sponsored position: No. This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future
Application Deadline
Please submit your application by 11:59 PM on Friday, September 25, 2026.