Cybersecurity Risk Analyst job at NRG Energy in Houston, TX

NRG Energy
Washington, US
Hybrid

Job Description

Title: Cybersecurity Risk Analyst

Location:

Houston, TX, US, 77010

Company: NRG

As an NRG employee, we encourage you to take charge of your career and development journey. We invite you to explore exciting opportunities across our businesses. You’ll find that our dynamic work environment provides variety and challenge. Your growth is key to our ongoing success—take the lead in shaping your career development, goals and future!

JOB SUMMARY:

The Cybersecurity Risk Analyst supports the organization's cyber risk management program by identifying, assessing, documenting, and communicating cyber risk across systems, applications, technologies, and business initiatives. This role partners with Technology, Business, Enterprise Risk and other stakeholders to enable risk-informed decisions and practical risk treatment outcomes.

The role is focused on internal cybersecurity risk assessments evaluating threats, vulnerabilities, control gaps, and business impact while helping stakeholders align on risk acceptance decisions consistent with organizational risk tolerance. Work is guided by the NIST CSF 2.0, with expected familiarity with FAIR and professional AI tools, as well as awareness of emerging technology risks and evolving cyber threats. This role is distinct from team responsibilities centered on third-party risk, vendor contracts, security surveys, or regulatory compliance.

Essential Duties and Responsibilities:

Cybersecurity Risk Assessment

Conduct cybersecurity risk assessments for systems, applications, infrastructure, technologies, projects, and business initiatives.

Identify, assess, analyze, and document cybersecurity threats, vulnerabilities, control gaps, exploitability considerations, and potential business impacts.

Evaluate inherent and residual cyber risk and develop clear, supportable risk statements, ratings, and recommendations.

Apply established cybersecurity risk assessment methodologies, frameworks, and reference materials, including FAIR and other relevant cyber risk analysis approaches.

Support practical and well-informed cyber risk treatment recommendations, including mitigation, remediation, transfer, avoidance, and acceptance.

Assist in identifying and documenting reasonable cyber risk acceptance positions aligned with business objectives, governance expectations, and organizational risk tolerance.

Stakeholder Engagement and Risk Facilitation

Partner with stakeholders across Technology, Cybersecurity, Business, and Enterprise Risk to gather information and support effective cyber risk assessments.

Facilitate meetings, workshops, and working sessions to bring the right stakeholders together for risk identification, analysis, treatment, and acceptance discussions.

Build alignment across teams and help translate technical cybersecurity issues into clear business risk implications and decision points.

Coordinate with team members responsible for adjacent activities, including third-party risk management, compliance support, contract review, security surveys, and regulatory matters, while maintaining primary focus on internal cyber risk assessment and analysis.

Vulnerability and Threat-Informed Risk Analysis

Work closely with vulnerability management and other cybersecurity teams to understand vulnerability exposure, remediation priorities, compensating controls, and the impact of technical findings on cyber risk.

Analyze vulnerability data, remediation status, exploitability, and exposure trends to inform cyber risk assessments and recommendations.

Maintain awareness of emerging cyber threats, attack techniques, threat actor activity, and technology developments that may affect the organization’s risk posture.

Metrics, Reporting, and Program Support

Collect, organize, analyze, and report cybersecurity risk metrics, trends, and themes to support leadership reporting and program oversight.

Prepare clear and concise risk assessment documentation, reports, summaries, and presentations for technical and non-technical stakeholders.

Support the continuous improvement of cybersecurity risk assessment processes, templates, standards, and reporting practices.

Use approved AI-enabled tools responsibly to support cyber risk research, analysis, documentation, and operational efficiency in accordance with company requirements.

Incorporate considerations related to artificial intelligence, generative AI, and other emerging technology risks into cybersecurity risk assessments, as applicable.

Working Conditions:

Hybrid.

Travel minimally.

Minimum Requirements:

A bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Risk Management, Business, or a related field is preferred but not required.

A minimum of five years of experience in cybersecurity, information security, cyber risk, technology risk, vulnerability management, IT audit, or a related discipline is essential.

Demonstrated experience performing cybersecurity or technology risk assessments is required.

Familia

Skills & Requirements

Technical Skills

Nist csf 2.0FairProfessional ai toolsCybersecurity risk assessment methodologiesCyber risk treatment recommendationsVulnerability managementCyber risk analysis approachesStakeholder engagementRisk facilitationTeamworkCommunicationCybersecurityRisk management

Employment Type

FULL TIME

Level

senior

Posted

4/30/2026

Apply Now

You will be redirected to NRG Energy's application portal.

Sign in and we'll score your resume against this role.