Senior Technology Policy and Compliance Consultant
This position is responsible for providing project management, direction, and leadership to Technology and Security Services as it relates to Security and Regulatory Compliance and Service Policy. This includes providing policy and compliance guidance on new standards and technologies supporting agencies such as the Department of Energy (e.g., Federal Energy Regulatory Commission (FERC), North American Electric Reliability Corporation (NERC)), Department of Homeland Security (e.g., Critical Gas Pipeline), Security and Exchange Commission (e.g., Sarbanes-Oxley), and Department of Commerce (e.g., National Institute of Standards and Technology (NIST)).
Responsibilities
- Drive the development of enterprise security policies and standards, oversee governance operations, and ensure alignment with security and regulatory requirements and industry frameworks.
- Operate as a strategic advisor and subject matter expert, providing thought leadership across the business, influencing decision making, and strengthening the organization’s control environment.
- Direct policy and standards program and coordinate the overall audit process for regulators for Technology and Security Services.
- Communicate organizational vision, mission, key objectives, and individual roles to others.
- Develop, model, and inspire a strong commitment to employee safety, recognition, development, and diversity in the workforce.
- Achieve employee satisfaction by providing a stimulating and rewarding work environment.
- Governance Program Development:
- Collaborate with cross-functional teams to develop and implement new security policies and standards, ensuring they incorporate applicable regulatory requirements and NIST-based frameworks.
- Interpret regulatory obligations and industry standards to determine their impact on the organization, translating complex requirements into clear, actionable policy and standard language.
- Partner with subject matter experts to address new requirements, emerging risks, and evolving business needs, ensuring governance artifacts remain relevant, comprehensive, and aligned with best practices.
- Evaluate the potential impact of new policies and standards across business areas and support stakeholders in understanding and adopting updated governance expectations.
- Governance Program Operations:
- Lead the execution of the security governance program, including the full lifecycle management of security policies and standards.
- Coordinate periodic reviews, updates, and approvals, as well as maintain supporting processes such as mapping standards to applicable frameworks and regulations.
- Ensure enterprise security standards are accurately maintained within the eGRC platform to support downstream processes such as Issue Management, Exceptions, and Security Assurance (control testing).
- Contribute to organizational continuous improvement efforts, promoting consistency, quality, and operational excellence across security governance and assurance functions.
- Stay current on the evolving security landscape, including emerging threats, updates to security frameworks (e.g., NIST CSF and other relevant NIST publications), and changes to applicable regulations (e.g., NERC CIP, DHS TSA, SOX).
- Governance Program Metrics and Reporting:
- Compile, review, and analyze security information to formulate recommendations, metrics, and reports for management review and decision-making.
- Governance Program Training and Awareness:
- Oversee the development, implementation, and maintenance of training, training materials, and events related to the ESS Governance Program.
- Mentor and develop staff in technical and functional subject areas.
Requirements
- Bachelor's degree or equivalent experience and at least 8 years of experience in security and IT or OT-related fields.
- Five years of experience in a GRC discipline.
- Five years of work in a Governance, Risk, Compliance (GRC) function in a highly regulated environment (e.g., Utilities) may substitute for up to 18 months of experience.
- Proven success implementing security policies, standards, and/or controls.
- Ability to define strategy and translate it into actionable plans that impact organizational change.
- Ability to work across the organization, building relationships and influencing peers and management through establishing trust and credibility.
- Applies sound judgment and creativity to solve complex problems.
- Ability to excel in a rapidly changing environment.
- Strong verbal and written communication skills; ability to drive discussions and influence decision-making; strong presentation and reporting skills.
- Ability to communicate with and create documentation for technical and non-technical audiences.
Preferred Qualifications
- Experience in one or more of the following areas: enterprise architecture, access controls, network administration, systems administration, SDLC/secure software development, encryption, asset management, identity and access management, IT or OT operations, security risk management.
- Certification in one or more of the following: CISSP, CISM, CISA, CRISC, Security+, CPP, or PSP.
- Experience using a GRC tool (e.g., Archer).
- Knowledge of regulatory requirements and frameworks such as NERC CIP, DHS TSA, SOX, ISO, NIST, COBIT, or Cyber Security Framework (CSF).
Pay
The anticipated starting base pay for this position is $112,200.00 to $159,400.00 per year.
Benefits
- Annual Incentive Program
- Medical/Pharmacy Plan
- Dental
- Vision
- Life Insurance
- Dependent Care Reimbursement Account
- Health Care Reimbursement Account
- Health Savings Account (HSA) (if enrolled in eligible health plan)
- Limited-Purpose FSA (if enrolled in eligible health plan and HSA)
- Transportation Reimbursement Account
- Short-term disability (STD)
- Long-term disability (LTD)
- Employee Assistance Program (EAP)
- Fitness Center Reimbursement (if enrolled in eligible health plan)
- Tuition reimbursement
- Transit programs
- Employee recognition program
- Pension
- 401(k) plan
- Paid time off (PTO)
- Holidays
- Volunteer Paid Time Off (VPTO)
- Parental Leave
Benefit plans are subject to change, and Xcel Energy has the right to end, suspend, or amend any of its plans at any time, in whole or in part.