Job Title: Senior Security Risk Coordinator
Work Place Flexibility: Hybrid
Legal Entity: Entergy Services, LLC
***This position can be located in The Woodlands, TX; New Orleans, LA; Little Rock, AR or Jackson, MS – Other locations within Entergy’s service territory may be considered. ***
Job Summary/Purpose
The Risk Coordinator Senior serves as a security and risk subject matter expert to help manage security risk and enable alignment to the Enterprise Security Program’s security risk agenda via coordinating and facilitating cyber and physical risk management processes and data to be presented to executive management.
The Risk Coordinator Sr. assesses the appropriateness of security, reliability, privacy, and data protection exceptions for business units from inputs provided and recommends where business units can enhance security protocol or execution to meet risk appetite.
Job Duties/Responsibilities
Risk Identification and Assessment
Lead and enhance programs for risk assessment /advisement on new technologies, critical infrastructure protection, logical cyber and physical security controls, and data protection measures
Identify, evaluate, and prioritize risk treatment
Conduct security reviews of corporate and operational technology infrastructure
Risk Management Program
Develop and acquire expertise in the areas of technology and regulations to ensure Entergy’s security posture and reliability standards are appropriately aligned to target risk thresholds
Provide security risk expertise and guidance to a diverse set of Entergy enterprise and operational technology stakeholders
Execute and create security risk management program practices and execution of security policies and requirements
Lead and drive the creation, maintenance and implementation of enterprise, operational, and critical infrastructure protection risk activities
Apply cybersecurity & risk management framework knowledge to drive risk identification across the enterprise
Compliance, Reporting, and Risk Metrics
Design and communicate risk details to team members during risk ranking sessions and ensure risk trends are identified
Track and manage risks identified through the security exception process or the cyber or physical risk review process
Develop key risk indicator (KRI) metrics and reporting processes associated with Entergy’s security risk to be utilized in executive reporting and dashboards including the use of technology including GRC platforms and artificial intelligence risk methods
Coordination
Coordinate with peer CSO functions to address security gaps within the three lines of defense as they arise through the risk exception process including identifying root causes and trends
Liaise with Lines of Business on security and reliability risks identified through the exception process or as new technologies and related projects are initiated
Guide business unit stakeholders on the mitigation strategies for requested exceptions
Facilitate line of business understanding of the impact of all mission critical business processes
Apply cybersecurity & risk management framework knowledge to drive risk identification across the enterprise
Procedure Development
Develop and assist in data and risk management process and procedure development
Data Protection & Privacy
Assist in data protection and privacy program governance and oversight activities
Minimum Requirements
Minimum education required of the position
Bachelor’s Degree in Information Systems, Information Assurance, Risk Management or related degree
Minimum experience required of the position
5+ years of information security, critical information protection, information technology, risk management, data analysis, or project management experience
Minimum knowledge, skills and abilities for the position
Planning, organizational and project management skills; detail and process-oriented; able to juggle multiple priorities in a fast-paced environment
Problem-solving/decision making ability
Written and verbal communication skills, able to explain complex issues in clear and concise terms
Interpersonal skills, including teamwork, facilitation and negotiation
Highly collaborative, able to work cross-functionally; possessing the ability to forge relationships and partner effectively
Preferred knowledge, skills and abilities for the position
Understanding of risk management frameworks (NIST 800-39 " Managing Information Security Risk “, NISTIR 8286 "Integrating Cybersecurity and Enterprise Risk Management (ERM) “, The Open FAIR (Factor Analysis of Information Risk), COSO Enterprise Risk Management, etc.)
Understanding of logical and physical security technologies and controls (NIST CSF, NIST 800-53, etc.)
Understanding of privacy protection best practices and technical requirements
Technology (Archer GRC/ServiceNow GRC or GRC platforms, Microsoft Power BI or other Data Analytics, Quantitative Risk, other risk management platforms)
Any certificates, licenses, etc. required for the position
The following certifications are desired but not required for this position;
Certified Information Systems Manager (CISM)
Certified Information Systems Security Professional (CISSP)
Certified in Risk and Information Systems Control (CRISC)
Certified in the Governance of Enterprise IT (CGEIT)
Certified Information Systems Auditor (CISA)
Certified Protection Profession (CPP)
#LI-HYBRID
#LI-DH1
Primary Location: Texas-The Woodlands Louisiana : New Orleans
Arkansas : Little Rock
Mississippi : Jackson
Texas : The Woodlands
Job Function: All Other Jobs
FLSA Status: Professional
Relocation Option:
Union description/code: NON BARGAINING UNIT
Number of Openings: 1
Req ID: 119394
Travel Percentage:Up to 25%
An Equal Opportunity Employer, Minority/Female/Disability/Vets. Please click here to view the EEO page, or see statements below.
EEO Statement: The Entergy System of Companies provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a protected veteran in accordance with applicable federal, state and local laws. The Entergy System of Companies complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment including, but not limited to, recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
The Entergy System of Companies expressly prohibits any form of unlawful employee harassment based on race, color, religion, sex, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status. Improper interference with the ability of the Entergy System of Company employees to perform their expected job duties is absolutely not tolerated.
Accessibility: Entergy provides reasonable accommodations for online applicants. Requests for a reasonable accommodation may be made orally or in writing by an applicant, employee, or third party on his or her behalf. If you are an individual with a disability and you are in need of an accommodation for the recruiting process please click here and provide your name, contact number, the accommodation requested and the requisition number that you are requesting the accommodation for. Employee Services will contact you regarding your request.
Additional Responsibilities: As a provider of essential services, Entergy expects its employees to be available to work additional hours, to work in alternate locations, and/or to perform additional duties in connection with storms, outages, emergencies, or other situations as deemed necessary by the company. Exempt employees may not be paid overtime associated with such duties.
Equal Opportunity
The non-confidential portions of the affirmative action program for individuals with disabilities and protected veterans shall be available for inspection upon request by any employee or applicant for employment. Please contact to schedule a time to review the affirmative action plan during regular office hours.
EEI Testing:
One way that Entergy has found to identify and assess the abilities and skills needed for certain jobs is through pre-employment testing. If this position does require an EEI test, the type of test will be located under the qualifications section of the job posting. If you are invited to a test session, we strongly recommend you review and complete the practice test as well as review the testing brochure for your respective test. The test brochure will give you critical information on the test such as time allocated and number of questions. Also, keep in mind that the actual test is timed; you should practice timing yourself while doing the practice tests. The practice test information and test brochures can be located by going to the EEI website, Logon ID: entergy, password: practice test (2 words). Travel expenses incurred in connection with EEI testing are non-reimbursable.
In addition to EEI testing there is also Fit-for-Duty testing which will identify and assess the abilities and skills needed for certain jobs. If this position does require Fit-for-Duty testing, the type of test will be located under the qualifications section of the job posting.
WORKING CONDITIONS:
As a provider of essential services, Entergy expects its employees to be available to work additional hours, to work in alternate locations, and/or to perform additional duties in connection with storms, outages, emergencies, or other situations as deemed necessary by the company. Exempt employees may not be paid overtime associated with such duties.
Please note: Authorization to work in the United States is a precondition to employment in this position. Entergy will not sponsor candidates for work visas for this position.