NextEra Energy

Cybersecurity Analyst

NextEra Energy$88K — $132K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent experience.
  • 5-7 years of related experience in cybersecurity risk assessments and security compliance activities.
  • Familiarity with cybersecurity controls, vulnerability management, and remediation practices.
  • Strong organizational skills for managing multiple assessments and documentation.
  • Excellent written and verbal communication skills for diverse audiences.

Responsibilities

  • Coordinate and conduct security assessments across applications and technologies.
  • Document risks, control gaps, and remediation activities clearly.
  • Manage third-party vendor security assessments and application reviews.
  • Support penetration testing activities, including result tracking and reporting.
  • Develop and maintain standardized cybersecurity processes and reporting.

Benefits

  • Comprehensive health plans including medical, dental, and vision.
  • Retirement plan options with company matching.
  • Employee wellness programs and resources.
  • Paid time off and flexible work arrangements.
Full Job Description
Requisition ID: 97057

Position Specific Description

We are seeking a cybersecurity professional to support the continued development and execution of NEA's cybersecurity risk management program. This role will coordinate security assessments, third-party risk reviews, application security evaluations, penetration testing activities, and remediation tracking across the organization.

The successful candidate will work closely with engineering teams, application owners, vendors, and business stakeholders to identify cybersecurity risks, document findings, and drive issues through resolution. This individual will also help standardize cybersecurity processes, reporting, and governance while using AI-enabled tools to improve analysis, efficiency, and decision-making.

Key Responsibilities & Expectations

1. Cybersecurity Risk Management
  • Security Assessments: Support cybersecurity assessments and risk reviews across applications, platforms, vendors, and technology solutions.
  • Risk Documentation: Document identified risks, control gaps, findings, compensating controls, and formal risk decisions.
  • Remediation Management: Track cybersecurity findings and remediation activities through validation and closure. Support risk acceptance and exception handling, including documenting formal security decisions when remediation is deferred.


2. Third-Party and Application Security
  • Third-Party Risk Assessments: Support security assessments for vendors, SaaS platforms, development tools, and AI-enabled solutions.
  • Application Security Reviews: Coordinate security reviews for applications and technology tools, including evidence collection, documentation, findings management, and stakeholder follow-up.
  • Stakeholder Coordination: Partner with application owners, engineering teams, vendors, and business stakeholders to obtain required information and resolve identified concerns.


3. Security Testing and Resiliency
  • Penetration Testing Coordination: Support penetration testing activities, including scheduling, scope coordination, results management, remediation tracking, and reporting.
  • Critical Application Resiliency: Assist with resiliency assessments for critical applications by organizing documentation, evaluating risk information, and tracking required actions.
  • Issue Resolution: Work with technical and business teams to identify appropriate remediation plans and ensure cybersecurity risks are addressed in a timely manner.
  • Audit Prep: Assist with audit and evidence requests by organizing support materials, tracking responses, and confirming completeness.


4. Governance, Reporting, and Process Improvement
  • Risk and Assessment Inventories: Maintain accurate inventories of assessed applications, vendors, findings, risk decisions, and remediation status.
  • Standardized Processes: Develop and maintain consistent assessment templates, workflows, procedures, reports, and dashboards.
  • Program Reporting: Provide clear and actionable reporting on cybersecurity risks, assessment activity, remediation progress, and program performance. Analyze recurring findings, remediation patterns, and program trends to help prioritize work and improve the overall cybersecurity program.
  • Continuous Improvement: Identify opportunities to improve the consistency, scalability, and effectiveness of cybersecurity review processes.


5. AI-Enabled Cybersecurity Productivity
  • AI-Assisted Analysis: Use AI assistants and related tools to improve cybersecurity research, risk analysis, documentation, and decision support.
  • Workflow Efficiency: Apply AI-enabled capabilities to streamline evidence review, reporting, remediation tracking, and other repeatable cybersecurity activities.
  • Responsible Adoption: Validate AI-generated outputs, protect sensitive information, and ensure responsible use of AI tools in cybersecurity work.


6. Collaboration and Ownership
  • Cross-Functional Partnership: Collaborate with engineering, application owners, cybersecurity teams, vendors, and business stakeholders to identify security gaps and support remediation.
  • Clear Communication: Translate cybersecurity risks and technical findings into clear, business-relevant language.
  • Ownership and Accountability: Manage assigned assessments and findings from initiation through completion while communicating risks, dependencies, and delays proactively. Apply working knowledge of application security and DevSecOps practices, including vulnerability management concepts and secure delivery workflows.


Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or equivalent practical experience.
  • Experience supporting cybersecurity risk assessments, security compliance activities, application security reviews, or third-party risk management.
  • Familiarity with cybersecurity controls, risk management concepts, vulnerability management, and remediation practices.
  • Experience coordinating work across technical teams, business stakeholders, and external vendors.
  • Strong organizational skills with the ability to manage documentation, findings, deadlines, and multiple concurrent assessments.
  • Strong written and verbal communication skills, including the ability to explain cybersecurity risks to both technical and nontechnical audiences.
  • Experience using reporting, workflow, ticketing, governance, risk, and compliance tools.
  • Familiarity with GRC, workflow, or case management tools used for risk tracking and remediation.
  • Experience with vulnerability management, security review coordination, or penetration test support.
  • Basic familiarity with application security and DevSecOps concepts such as SAST, SCA, DAST, CI/CD, and secure coding.
  • Ability to use AI assistants and related technologies responsibly to improve analysis, documentation, and workflow efficiency.
  • Ability to validate AI-assisted outputs and handle sensitive information appropriately.


Job Overview

This job performs ongoing cybersecurity risk reviews for new and existing technologies and services and supports ongoing and new cybersecurity projects. Individuals develop requirements for and implement technical security projects and tools, as well as define the company's cybersecurity policies and control framework. This position collaborates with the company's IT department and business units to identify the need for, select, and deploy technical controls to meet specific security requirements. Employees in this role build processes and standards to ensure security requirements continue to be met.

Job Duties & Responsibilities

  • Administers, operates and monitors NextEra Energy (NEE) information security sensors, logging, alerting and other detection mechanisms to identify and respond to threats
  • Develops a subject matter expertise for one or multiple assigned cybersecurity technology stacks (e.g., identity and access management, network intrusion detection and prevention, host based security tools)
  • Collaborates with security architecture to identify, evaluate and recommend new security technologies for suitability within NEE's environment and security posture
  • Communicates ongoing cybersecurity activities, priorities and risk measurements or mitigations at multiple organizational levels
  • Provides guidance for security activities and requirements in the system development life cycle (SDLC) and application development efforts. Participates in organizational projects, as required
  • Performs other job-related duties as assigned


Required Qualifications

  • High School Grad / GED
  • Bachelor's or Equivalent Experience
  • Experience: 2+ years


Preferred Qualifications

  • Certified Information Systems Aud (CISA) certification


The estimated base pay for this position is $88,000.00 to $132,000.00 per year. Starting pay will be based on several factors including, but not limited to, experience, qualifications, job-related and industry knowledge and skills and education/training.

NextEra Energy offers a wide range of benefits to support our employees and their eligible family members. Click here to learn more.

Employee Group: Exempt
Employee Type: Full Time
Job Category: Information Technology
Organization: NextEra Analytics, Inc
Relocation Provided: Yes, if applicable

About NextEra Energy

A growth-oriented limited partnership formed by NextEra Energy, Inc., NextEra Energy Partners, LP (NYSE: NEP) acquires, manages, and owns contracted clean energy projects with stable, long-term cash flows. They own interests in wind and solar projects in North America, as well as natural gas infrastructure assets in Texas. Renewable energy projects are fully contracted, use technology, and are located in regions that are favorable for generating energy from the wind and sun. The seven natural gas pipelines in the portfolio are all strategically located, serving power producers and municipalities in South Texas, processing plants and producers in the Eagle Ford Shale, and commercial and industrial customers in the Houston area. The NET Mexico Pipeline, the largest pipeline in the portfolio, provides a critical source of natural gas transportation for low-cost, U.S.-sourced shale gas to Mexico.

NextEra Energy Careers

Join the dynamic team at NextEra Energy, the world’s leading generator of renewable energy from the wind and sun, and a leader in battery storage. At NextEra Energy, we are committed to providing top-tier job opportunities that foster professional growth and innovation in the energy sector.

Work You’ll Do

Embark on a fulfilling career with NextEra Energy, where we offer a variety of job opportunities across multiple disciplines. Whether you're interested in engineering, business development, or environmental stewardship, you will find a position that aligns with your skills and passions. Our team is at the forefront of transforming the energy industry, making it cleaner and more sustainable.

Innovate and Lead

At NextEra Energy, innovation and leadership go hand in hand. Join our team and collaborate with some of the brightest minds in the industry. Our leadership is committed to fostering a culture of innovation that encourages new ideas and solutions. As part of our team, you will have the opportunity to lead projects that make a real impact on our future.

Grow Your Career

NextEra Energy is not just a company; it's a place where you can grow your career. With our extensive range of professional development and diversity training programs, you will have the tools and resources to thrive. Our commitment to your growth is reflected in our robust benefits package, designed to support you both professionally and personally.

Internship Opportunities

Kickstart your career with a NextEra Energy internship. Our internships provide invaluable workplace experience and a chance to see if a career in the energy sector is right for you. You’ll work alongside experienced professionals, gaining the skills and insights that will benefit you as you move forward in your career journey.

Be Part of Our Team

NextEra Energy is looking for passionate, curious, and innovative team players. Explore job opportunities and join a company that values diversity, leadership, and professional growth. Our team members are our greatest asset, and we strive to maintain a culture that celebrates diversity, equity, and inclusion.

Stay Connected

Keep up to date with the latest at NextEra Energy: - **Explore Careers**: Search open positions that match your skills and interests. We are always on the lookout for talented individuals who are eager to contribute to our mission and vision. - **Networking and Professional Development**: Engage with us through various networking events, professional groups, and social platforms. Connect with other professionals who share your passion for renewable energy and environmental sustainability.

Apply Now

Ready to make a difference? Submit your resume, complete your application, prepare for your interview, and join NextEra Energy. Discover the exciting and rewarding career opportunities that await at one of the most respected companies in the energy sector.

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Stay informed about new employment opportunities and industry trends with NextEra Energy. At NextEra Energy, we empower our employees to drive change and push the boundaries of what is possible in the energy industry. Join us and transform the way the world generates and uses energy.
Learn more about NextEra Energy
Size
15,000 employees
Market Cap
$6.1 billion
Industry
Net Income
-$51 million
Founded
2014
5 Year Trend
+4.9%
Revenue
$917 million
NASDAQ

Similar Jobs

More Jobs at NextEra Energy

More Information Technology Jobs

Find similar Cybersecurity Analyst jobs: