Luma Energy logo
Luma EnergyPosted 1 week ago

Specialist, GRC (Governance, Risk & Compliance)

On-siteSanturce, Santa Fe Province, Argentine Republic

Full TimeBachelors DegreeLarge

Job Summary

Execute IT/OT security risk assessments and compliance reviews aligned with the LUMA Cybersecurity Controls Program and frameworks such as NIST CSF, CIS Controls, and NERC CIP. Maintain the risk register and self-identified issue tracker to ensure accurate status reporting and timely escalation of risks. Support audit activities by assessing compliance with information security policies, coordinating third-party assessments, and tracking remediation progress for identified control gaps. Monitor technology projects to validate secure-by-design principles and support incident response through review of data protection controls and log reports. Prepare monthly and quarterly compliance reports with data-driven insights and deliver cybersecurity awareness training across IT/OT teams. Participate in storm restoration tasks and assigned drills to contribute to service recovery.

Required Qualifications

  • Bachelor's degree Information Technology, Computer Science, Engineering, or related field
  • 5 years of related experience in information security governance, risk management, compliance, or audit functions
  • Demonstrated experience executing audit plans, maintaining risk registers, and supporting compliance programs
  • Experience working with cybersecurity frameworks such as NIST CSF, CIS Controls, NERC CIP, or equivalent standards
  • Experience with evidence repositories, compliance dashboards, and GRC tools
  • Experience collaborating with cross-functional technical teams and external auditors in a regulated or highly controlled environment
  • Knowledge of governance, risk, compliance, and audit frameworks (NIST CSF, CIS v8, NERC CIP, PR Cybersecurity Act)
  • Strong analytical and critical thinking skills with ability to interpret complex data
  • Understanding of relevant laws, regulations, and industry standards applicable to IT/OT environments
  • Excellent communication skills, with the ability to translate complex technical concepts for non-technical audiences
  • Ability to collaborate effectively with cross-functional teams and external auditors
  • Strong planning and organizational skills, with the ability to manage multiple audit and compliance workstreams simultaneously
  • 20% travel

Desired Qualifications

  • Associate's degree in information technology, Computer Science
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • Additional NIST, NERC CIP, or cybersecurity framework certifications
  • Experience collaborating with cross-functional technical teams and external auditors in a regulated or highly controlled environment preferred

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce