Systems Manager-Governance, Risk, & Compliance (GRC)

Consolidated Edison Company of New York, Inc. (CECONY)New York City, New YorkOn-siteFull-timeStaff, 8–12 yearsListed 1 hour ago

Apply now

About this role

The System Manager, Information Security (InfoSec) Governance, Risk & Compliance (GRC), is a leadership role responsible for overseeing information security governance, risk management, compliance, and related strategic programs across the enterprise. Responsibilities include establishing and maintaining frameworks, processes, and capabilities used to identify, assess, manage, communicate, and monitor cybersecurity risk while ensuring alignment with regulatory requirements, industry standards, and business objectives. The successful candidate must be self-motivated, able to work with minimal guidance, possess extensive organizational skills and attention to detail, and drive results.

Required Education/Experience
- Master's Degree and 6 years of work experience in IT or Utility environments with at least four (4) years in GRC or similar or
- Bachelor's Degree and 8 years of work experience in IT or Utility environments with at least four (4) years in GRC or similar.

Preferred Education/Experience
- Master's Degree preferably in Information Technology, Computer Science, Information Security, Math, Engineering or business-related discipline preferred.
- Bachelor's Degree preferably in Information Technology, Computer Science, Information Security, Math, Engineering or business-related discipline preferred.

Relevant Work Experience
- Must demonstrate knowledge of project management concepts and ability to support project monitoring, tracking, and facilitation to ensure project deliverance/completion, required.
- Proven experience of process and policy creation and documentation, required.
- Must demonstrate strong analytical skills, required.
- Must have managerial/supervisory experience, required.
- Must demonstrate strong oral and written communication, presentation and interpersonal skills, required.
- Must have used, and have working knowledge of MS Excel, Word and PowerPoint, required.
- Experience and working knowledge of information security governance, risk management, compliance, and related cybersecurity program functions, required.
- Experience developing and delivering well organized analytical presentations, preferred.
- Experience with contract administration a plus, preferred.
- Experience with developing training and awareness programs, preferred.
- Experience working as a project or program manager role a plus, preferred.
- Experience in Information Technology/Cybersecurity a plus, preferred.

Skills and Abilities
- Effectively coaches and delivers constructive feedback
- Demonstrates a high commitment to quality
- Assumes personal responsibility for actions
- Strong verbal communication and listening skills
- Ability to lead/manage others
- Possesses flexibility to work in a fast paced, dynamic environment
- Effective interpersonal skills
- Demonstrated analytical skills
- Ability to simultaneously handle multiple priorities
- Effective interpersonal skills

Licenses and Certifications
- Driver's License Required

Physical Demands
- Ability to push, pull, and lift up to 25 pounds
- Sit or stand to use a keyboard, mouse, and computer for the duration of the workday

Additional Physical Demands
- The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.