VoltaGrid

Cybersecurity Risk & Compliance Analyst

VoltaGrid$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-6 years in GRC, cybersecurity compliance, or risk management
  • Strong knowledge of SOC 2, ISO 27001, and NIST CSF
  • Experience in developing policies and conducting risk assessments
  • Familiarity with audit processes and evidence management
  • Ability to simplify technical requirements into operational processes
  • Strong organizational and communication skills

Responsibilities

  • Develop and maintain cybersecurity policies and procedures
  • Manage risk assessment processes, identifying and tracking risks
  • Drive compliance initiatives for SOC 2 and ISO 27001
  • Establish a control framework aligning security practices with regulations
  • Collaborate with teams to embed security controls in workflows
  • Track risk registers and remediation efforts for leadership visibility
  • Support third-party risk management and vendor assessments
  • Produce executive-ready reporting on risk posture and compliance status

Benefits

  • Opportunity to evolve a cybersecurity program and framework
  • Work in a rapidly scaling organization with growth potential
  • Collaborate across engineering, IT, and operations teams
  • Impactful role in establishing risk governance and compliance
  • Engagement in continuous evaluation and improvement of cybersecurity processes
Full Job Description
Position Title: Cybersecurity Risk & Compliance Analyst
Location: HOUSTON, TX
FLSA Class: EXEMPT
Responsible to: Senior Manager of Technical Operations

Position Summary: VoltaGrid is seeking a Cybersecurity Risk & Compliance Analyst to help formalize and scale our risk governance, compliance, and policy framework across both IT and operational environments.

This role is central to evolving our cybersecurity program from reactive support to structured, institutionalized risk governance. You will drive clarity and consistency in how we manage risk, controls, policies, and audit readiness, ensuring alignment with both regulatory requirements and real-world operational needs.

The ideal candidate brings a strong understanding of GRC principles, paired with the ability to translate complex requirements into practical, enforceable processes that integrate seamlessly into day-to-day operations.

As VoltaGrid continues to scale, cybersecurity must evolve into a structured, measurable, and governance-driven function. This role ensures that our approach to risk and compliance is not just about meeting requirements, but about building a repeatable, scalable framework that supports secure growth across both digital and physical infrastructure. You will play a key role in establishing clarity, accountability, and trust in how VoltaGrid manages risk across the organization

Essential Duties and Responsibilities:
  • Develop, implement, and maintain cybersecurity policies, standards, and procedures, ensuring they are clear, actionable, and aligned with organizational needs.
  • Own and manage risk assessment processes, including identifying, evaluating, and tracking risks across IT and operational technology environments.
  • Support and drive compliance initiatives (e.g., SOC 2, ISO 27001), including control design, evidence collection, and audit coordination.
  • Establish and maintain a control framework that aligns security practices with regulatory and business requirements.
  • Partner with engineering, IT, and operations teams to ensure controls are implemented effectively and embedded into workflows.
  • Manage and track risk registers, control gaps, and remediation efforts, providing visibility to leadership.
  • Support third-party risk management, including vendor assessments and ongoing monitoring.
  • Collaborate with cybersecurity and technology teams to align security tooling and monitoring with compliance and risk objectives.
  • Assist in developing and maintaining security awareness and policy training programs.
  • Produce clear, executive-ready reporting on risk posture, compliance status, and program maturity.
  • Continuously evaluate and improve the organization's governance model, processes, and documentation.

Other Requirements:
  • 3-6 years of experience in GRC, cybersecurity compliance, risk management, or related roles.
  • Strong understanding of common frameworks and standards such as:
    • SOC 2
    • ISO 27001
    • NIST CSF or similar
  • Experience developing and managing policies, controls, and risk assessments.
  • Familiarity with audit processes and evidence management.
  • Ability to translate technical and regulatory requirements into practical processes.
  • Strong organizational, analytical, and communication skills.

Preferred Qualification:
  • Experience in critical infrastructure, energy, or industrial environments.
  • Familiarity with OT/ICS risk and compliance considerations.
  • Experience with GRC tools or compliance automation platforms (e.g., Drata).
  • Understanding of third-party risk management frameworks.
  • Relevant certifications (e.g., CISA, CRISC, CISSP, ISO 27001 Lead Implementer)

About VoltaGrid

VoltaGrid is a renewable energy company that specializes in developing and operating distributed energy resources. The company's mission is to accelerate the transition to a clean energy future by providing reliable, affordable, and sustainable energy solutions to businesses and communities. VoltaGrid's innovative technology platform enables customers to optimize their energy usage, reduce their carbon footprint, and save money on their energy bills. The company is committed to delivering exceptional customer service and building long-term relationships with its clients.
Learn more about VoltaGrid
Size
50 employees
Industry
Net Income
$1 million
Founded
2010
5 Year Trend
+20%
Revenue
$5 million
NASDAQ

Similar Jobs

More Jobs at VoltaGrid

More Information Technology Jobs

Find similar Cybersecurity Risk & Compliance Analyst jobs: