bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesCareers Gannettfleming Icims ComPrincipal Cybersecurity Compliance Analyst

Principal Cybersecurity Compliance Analyst

Careers Gannettfleming Icims Com · Roseville, CA, US; Sacramento, CA, US; Oakland, CA, US · Remote · Active · $150,000–$200,000 / year · iCIMS

Job facts

FieldValue
CompanyCareers Gannettfleming Icims Com
TitlePrincipal Cybersecurity Compliance Analyst
Normalized title-
Department / teamSafety & Security
LocationRoseville, CA, United States
Work modelRemote / Remote
Employment typeFull Time
Salary$150,000–$200,000 / year
Statusactive
ATS provideriCIMS
Posted / first seen2026-06-03 / 2026-06-04
Changed / last seen2026-06-04 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Careers Gannettfleming Icims Com.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through iCIMS.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in Roseville.Open
Department jobsActive postings in Safety & Security.Open
Work model jobsActive Remote postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyCareers Gannettfleming Icims Com
Sourcec00651d8-ad75-45e4-8161-fed1dab4d1c1
ATS provideriCIMS

Description

GFT is seeking a Principal Cybersecurity Compliance Analyst to join our Security and Safety team in Northern Califonria! This role follows a hybrid work model, requiring regular attendance at our client's office. What you’ll be challenged to do: As a Principal Cybersecurity Compliance Analyst, you will support critical compliance initiatives across a client’s generation assets. This role will focus on ensuring adherence to regulatory requirements, internal cybersecurity standards, and industry best practices. The ideal candidate will have a proven track record of managing compliance projects within highly regulated environments, particularly in the energy or utilities sector. In this capacity, the successful candidate will be responsible for the following: Lead and support the development, implementation, and continuous improvement of governance, risk, and compliance (GRC) programs aligned with FERC (D2SI SPHP Section 9) and NERC CIP standards for PG&E’s power generation assets. Develop, maintain, and operationalize policies, procedures, standards, and guidelines to meet regulatory requirements and industry best practices. Conduct compliance gap assessments, risk analyses, and control testing for cybersecurity and OT systems. Prepare and maintain audit-ready documentation, including compliance narratives, evidence repositories, and records retention practices. Coordinate and support internal and external audits, including NERC Regional Entity audits, spot checks, and self-certifications. Collaborate with cybersecurity, IT, OT, engineering, legal, and enterprise risk teams to align compliance requirements with business operations. Serve as a liaison between technical teams and compliance leadership to translate regulatory requirements into actionable controls. Track compliance metrics, risks, and issues; prepare reports and dashboards for leadership. Monitor regulatory developments, FERC and NERC standards changes, and enforcement trends. Support compliance training and awareness efforts for internal stakeholders. Assist in the integration of compliance controls into operational and cybersecurity processes. Participate in mock audits, tabletop exercises, and incident response planning. What you will bring to our firm: Bachelor’s degree in cybersecurity, information systems, engineering, business, or a related field. Minimum of 10 years of relevant experience in the power utility industry, with a focus on governance, risk, and compliance (GRC), cybersecurity, or operational technology. Deep working knowledge of NERC CIP standards and the FERC regulatory environment. Direct experience supporting NERC CIP audits (self-certifications, spot checks, or enforcement actions). Experience with compliance documentation, evidence collection, and audit support. Familiarity with electric utility operations, OT environments, or ICS/SCADA systems. Strong analytical, organizational, and technical writing skills. Excellent communication and interpersonal skills, with the ability to work independently and collaboratively. Certification from a recognized risk, governance, or cybersecurity organization (e.g., CISSP, CISM, RIMS-CRMP, or equivalent) required What we prefer you bring: Experience in the energy sector, particularly power generation or utilities. PMP certification Familiarity with SCADA/ICS systems and processes. Knowledge of related frameworks (e.g., NIST CSF, NIST SP 800-53, ISO 27001). Experience in project management, including scope, schedule, and budget tracking. Involvement in professional organizations or industry committees. Compensation: The salary range for this role is $150,000 - $200,000. Salary is dependent upon experience and geographic location. Featured Benefits: • Hybrid (in-person and remote) work environment.• Comprehensive benefits package including wellness programs, parental leave, and pet insurance, in addition to medical, dental, vision, disability, and life insurance.• Tax-deferred 401(k) savings plan.• Competitive paid-time-off (PTO) accrual.• Tuition reimbursement for continued education.• Commitment to professional development, access to internal and external training programs, and support of active participation in professional organizations• Incentive compensation for eligible positions. At GFT, a privately held AEC firm, we innovate where transportation, water, power, and buildings converge. We call this the Infrastructure of Life. We measure our success by the strength of our relationships – that’s why we’re the employer of choice for 5,000+ of the industry’s brightest engineers, planners, architects, inspectors, designers, and more. Our clients choose us for our expertise and prefer us for our nimble approach, creativity, and personal touch. Backed by over a century’s experience, together we’re building a lasting legacy for future generations: stronger communities, a healthier planet, and better lives. GFT: Ingenuity That Shapes Lives™ is an Equal Opportunity Employer. All qualified candidates will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veterans’ status or other characteristics protected by law. Unsolicited resumes from third party agencies will be considered the property GFT. GFT does require the successful completion of a criminal background check for all advertised positions. Location: Sacramento, CA; Roseville, CA; Oakland, CA Core Business Hours: 8:00 AM – 5:00 PM Employment Status: Full-Time Applicants in the County of Los Angeles- Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Applicants in the City of San Francisco- Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Applicants in the State of California -Qualified applications with arrest or conviction records will be considered for employment in accordance with the California Fair Chance Act. #LI-hybrid #LI-KV1

Full job record

Job ID2e4c0cd4d7d7fe98a253543cef50da9f24a943ef
Org ID9ea6b224-5b4a-4ec8-ab6d-e7b1fca3bc93
Source IDc00651d8-ad75-45e4-8161-fed1dab4d1c1
Board IDc00651d8-ad75-45e4-8161-fed1dab4d1c1
Providericims
Provider Job Key14226
TitlePrincipal Cybersecurity Compliance Analyst
Normalized Title
Statusactive
Activeyes
Location TextRoseville, CA, US; Sacramento, CA, US; Oakland, CA, US
DepartmentSafety & Security
Team
Employment Typefull_time
Workplace Typeremote
Remote Policyremote
CountryUnited States
RegionCA
CityRoseville
Salary RawGFT is seeking a Principal Cybersecurity Compliance Analyst to join our Security and Safety team in Northern Califonria! This role follows a hybrid work model, requiring regular attendance at our client's office. What you’ll be challenged to do: As a Principal Cybersecurity Compliance Analyst, you will support critical compliance initiatives across a client’s generation assets. This role will focus on ensuring adherence to regulatory requirements, internal cybersecurity standards, and industry best practices. The ideal candidate will have a proven track record of managing compliance projects within highly regulated environments, particularly in the energy or utilities sector. In this capacity, the successful candidate will be responsible for the following: Lead and support the development, implementation, and continuous improvement of governance, risk, and compliance (GRC) programs aligned with FERC (D2SI SPHP Section 9) and NERC CIP standards for PG&E’s power generation assets. Develop, maintain, and operationalize policies, procedures, standards, and guidelines to meet regulatory requirements and industry best practices. Conduct compliance gap assessments, risk analyses, and control testing for cybersecurity and OT systems. Prepare and maintain audit-ready documentation, including compliance narratives, evidence repositories, and records retention practices. Coordinate and support internal and external audits, including NERC Regional Entity audits, spot checks, and self-certifications. Collaborate with cybersecurity, IT, OT, engineering, legal, and enterprise risk teams to align compliance requirements with business operations. Serve as a liaison between technical teams and compliance leadership to translate regulatory requirements into actionable controls. Track compliance metrics, risks, and issues; prepare reports and dashboards for leadership. Monitor regulatory developments, FERC and NERC standards changes, and enforcement trends. Support compliance training and awareness efforts for internal stakeholders. Assist in the integration of compliance controls into operational and cybersecurity processes. Participate in mock audits, tabletop exercises, and incident response planning. What you will bring to our firm: Bachelor’s degree in cybersecurity, information systems, engineering, business, or a related field. Minimum of 10 years of relevant experience in the power utility industry, with a focus on governance, risk, and compliance (GRC), cybersecurity, or operational technology. Deep working knowledge of NERC CIP standards and the FERC regulatory environment. Direct experience supporting NERC CIP audits (self-certifications, spot checks, or enforcement actions). Experience with compliance documentation, evidence collection, and audit support. Familiarity with electric utility operations, OT environments, or ICS/SCADA systems. Strong analytical, organizational, and technical writing skills. Excellent communication and interpersonal skills, with the ability to work independently and collaboratively. Certification from a recognized risk, governance, or cybersecurity organization (e.g., CISSP, CISM, RIMS-CRMP, or equivalent) required What we prefer you bring: Experience in the energy sector, particularly power generation or utilities. PMP certification Familiarity with SCADA/ICS systems and processes. Knowledge of related frameworks (e.g., NIST CSF, NIST SP 800-53, ISO 27001). Experience in project management, including scope, schedule, and budget tracking. Involvement in professional organizations or industry committees. Compensation: The salary range for this role is $150,000 - $200,000. Salary is dependent upon experience and geographic location. Featured Benefits: • Hybrid (in-person and remote) work environment.• Comprehensive benefits package including wellness programs, parental leave, and pet insurance, in addition to medical, dental, vision, disability, and life insurance.• Tax-deferred 401(k) savings plan.• Competitive paid-time-off (PTO) accrual.• Tuition reimbursement for continued education.• Commitment to professional development, access to internal and external training programs, and support of active participation in professional organizations• Incentive compensation for eligible positions. At GFT, a privately held AEC firm, we innovate where transportation, water, power, and buildings converge. We call this the Infrastructure of Life. We measure our success by the strength of our relationships – that’s why we’re the employer of choice for 5,000+ of the industry’s brightest engineers, planners, architects, inspectors, designers, and more. Our clients choose us for our expertise and prefer us for our nimble approach, creativity, and personal touch. Backed by over a century’s experience, together we’re building a lasting legacy for future generations: stronger communities, a healthier planet, and better lives. GFT: Ingenuity That Shapes Lives™ is an Equal Opportunity Employer. All qualified candidates will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veterans’ status or other characteristics protected by law. Unsolicited resumes from third party agencies will be considered the property GFT. GFT does require the successful completion of a criminal background check for all advertised positions. Location: Sacramento, CA; Roseville, CA; Oakland, CA Core Business Hours: 8:00 AM – 5:00 PM Employment Status: Full-Time Applicants in the County of Los Angeles- Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Applicants in the City of San Francisco- Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Applicants in the State of California -Qualified applications with arrest or conviction records will be considered for employment in accordance with the California Fair Chance Act. #LI-hybrid #LI-KV1
Salary Min150,000
Salary Max200,000
Salary CurrencyUSD
Salary Periodyear
Source URLhttps://careers-gannettfleming.icims.com/jobs/14226/principal-cybersecurity-compliance-analyst/job
Apply URLhttps://careers-gannettfleming.icims.com/jobs/14226/principal-cybersecurity-compliance-analyst/job
First Seen At2026-06-04 14:09:33Z
Last Seen At2026-06-06 08:34:28Z
Last Checked At2026-06-06 08:34:28Z
Last Changed At2026-06-04 14:09:33Z
Inactive At
Source Posted At2026-06-03 04:00:00Z
Source Updated At2026-06-03 17:51:26Z
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=icims/board=careers-gannettfleming.icims.com/date=2026-06-06/2026-06-06T08-34-17-811Z-234fd0fd9bdd26c6ec6ad84d00ef36565a6d003899c663968932373d99966f76.json
Event Fields
{
  "content_hash": "ad1493b12270920be0f3ce39abf6c09fc99eb9ceea5dcc004d6bc0368bdbd8ae",
  "source_hash": "1561fe303bf72ac987d026dda6060ea8ed5738857e2d8580ee4a963b4025bc2a",
  "last_changed_at": "2026-06-04T14:09:33.711Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "Roseville, CA, US",
    "city": "Roseville",
    "region": "CA",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.8
  },
  "salary_max": 200000,
  "salary_min": 150000,
  "inferred_at": "2026-06-06T08:34:27.808Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "Roseville, CA, US",
      "city": "Roseville",
      "region": "CA",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.8
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "remote",
  "salary_period": "year",
  "workplace_type": "remote",
  "salary_currency": "USD"
}
Extensions
{}
Native Structured
{
  "json_ld": {
    "url": "https://careers-gannettfleming.icims.com/jobs/14226/principal-cybersecurity-compliance-analyst/job",
    "@type": "JobPosting",
    "title": "Principal Cybersecurity Compliance Analyst",
    "@context": "http://schema.org",
    "datePosted": "2026-06-03T04:00:00.000Z",
    "description": "<h2></h2>\n<p><strong>GFT</strong> is seeking a <strong>Principal Cybersecurity Compliance Analyst</strong> to join our Security and Safety team in Northern Califonria! This role follows a hybrid work model, requiring regular attendance at our client's office.</p>\n<p> </p>\n<p><strong>What you’ll be challenged to do:</strong>As a Principal Cybersecurity Compliance Analyst, you will support critical compliance initiatives across a client’s generation assets. This role will focus on ensuring adherence to regulatory requirements, internal cybersecurity standards, and industry best practices. The ideal candidate will have a proven track record of managing compliance projects within highly regulated environments, particularly in the energy or utilities sector.</p>\n<p> </p>\n<p><strong>In this capacity, the successful candidate will be responsible for the following:</strong> </p>\n<ul>\n <li>Lead and support the development, implementation, and continuous improvement of governance, risk, and compliance (GRC) programs aligned with FERC (D2SI SPHP Section 9) and NERC CIP standards for PG&E’s power generation assets.</li>\n <li>Develop, maintain, and operationalize policies, procedures, standards, and guidelines to meet regulatory requirements and industry best practices.</li>\n <li>Conduct compliance gap assessments, risk analyses, and control testing for cybersecurity and OT systems.</li>\n <li>Prepare and maintain audit-ready documentation, including compliance narratives, evidence repositories, and records retention practices.</li>\n <li>Coordinate and support internal and external audits, including NERC Regional Entity audits, spot checks, and self-certifications.</li>\n <li>Collaborate with cybersecurity, IT, OT, engineering, legal, and enterprise risk teams to align compliance requirements with business operations.</li>\n <li>Serve as a liaison between technical teams and compliance leadership to translate regulatory requirements into actionable controls.</li>\n <li>Track compliance metrics, risks, and issues; prepare reports and dashboards for leadership.</li>\n <li>Monitor regulatory developments, FERC and NERC standards changes, and enforcement trends.</li>\n <li>Support compliance training and awareness efforts for internal stakeholders.</li>\n <li>Assist in the integration of compliance controls into operational and cybersecurity processes.</li>\n <li>Participate in mock audits, tabletop exercises, and incident response planning.</li>\n</ul>\n<h2></h2>\n<strong>What you will bring to our firm: </strong>\n<ul>\n <li>Bachelor’s degree in cybersecurity, information systems, engineering, business, or a related field.</li>\n <li>Minimum of 10 years of relevant experience in the power utility industry, with a focus on governance, risk, and compliance (GRC), cybersecurity, or operational technology.</li>\n <li>Deep working knowledge of NERC CIP standards and the FERC regulatory environment.</li>\n <li>Direct experience supporting NERC CIP audits (self-certifications, spot checks, or enforcement actions).</li>\n <li>Experience with compliance documentation, evidence collection, and audit support.</li>\n <li>Familiarity with electric utility operations, OT environments, or ICS/SCADA systems.</li>\n <li>Strong analytical, organizational, and technical writing skills.</li>\n <li>Excellent communication and interpersonal skills, with the ability to work independently and collaboratively.</li>\n <li>Certification from a recognized risk, governance, or cybersecurity organization (e.g., CISSP, CISM, RIMS-CRMP, or equivalent) required</li>\n</ul> \n<strong>What we prefer you bring: </strong>\n<ul>\n <li>Experience in the energy sector, particularly power generation or utilities.</li>\n <li>PMP certification</li>\n <li>Familiarity with SCADA/ICS systems and processes.</li>\n <li>Knowledge of related frameworks (e.g., NIST CSF, NIST SP 800-53, ISO 27001).</li>\n <li>Experience in project management, including scope, schedule, and budget tracking.</li>\n <li>Involvement in professional organizations or industry committees.</li>\n</ul>\n<strong> </strong>\n<strong>Compensation:</strong>The salary range for this role is $150,000 - $200,000. Salary is dependent upon experience and geographic location. \n<strong>Featured Benefits: </strong>• Hybrid (in-person and remote) work environment.• Comprehensive benefits package including wellness programs, parental leave, and pet insurance, in addition to medical, dental, vision, disability, and life insurance.• Tax-deferred 401(k) savings plan.• Competitive paid-time-off (PTO) accrual.• Tuition reimbursement for continued education.• Commitment to professional development, access to internal and external training programs, and support of active participation in professional organizations• Incentive compensation for eligible positions.\n<p> </p>\n<h2></h2>\n<p>At GFT, a privately held AEC firm, we innovate where transportation, water, power, and buildings converge. We call this the Infrastructure of Life. We measure our success by the strength of our relationships – that’s why we’re the employer of choice for 5,000+ of the industry’s brightest engineers, planners, architects, inspectors, designers, and more.</p>\n<p> </p>\n<p>Our clients choose us for our expertise and prefer us for our nimble approach, creativity, and personal touch. Backed by over a century’s experience, together we’re building a lasting legacy for future generations: stronger communities, a healthier planet, and better lives.<strong>GFT: Ingenuity That Shapes Lives™</strong> is an Equal Opportunity Employer. All qualified candidates will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veterans’ status or other characteristics protected by law.</p>\n<p> </p>\n<p>Unsolicited resumes from third party agencies will be considered the property GFT.</p>\n<p> </p>\n<p>GFT does require the successful completion of a criminal background check for all advertised positions. </p>\n<p> </p>\n<p><strong>Location: </strong>Sacramento, CA; Roseville, CA; Oakland, CA<strong>Core Business Hours:</strong> 8:00 AM – 5:00 PM<strong>Employment Status:</strong> Full-Time</p>\n<p> </p>\n<p><strong>Applicants in the County of Los Angeles- </strong>Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.</p>\n<p><strong>Applicants in the City of San Francisco- </strong>Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.</p>\n<p><strong>Applicants in the State of California</strong>-Qualified applications with arrest or conviction records will be considered for employment in accordance with the California Fair Chance Act.</p>\n<p> </p>\n<p>#LI-hybrid</p>\n<p>#LI-KV1</p>",
    "directApply": true,
    "jobLocation": [
      {
        "@type": "Place",
        "address": {
          "@type": "PostalAddress",
          "postalCode": "95661",
          "addressRegion": "CA",
          "streetAddress": "UNAVAILABLE",
          "addressCountry": "US",
          "addressLocality": "Roseville",
          "postOfficeBoxNumber": "UNAVAILABLE"
        }
      },
      {
        "@type": "Place",
        "address": {
          "@type": "PostalAddress",
          "postalCode": "UNAVAILABLE",
          "addressRegion": "CA",
          "streetAddress": "UNAVAILABLE",
          "addressCountry": "US",
          "addressLocality": "Sacramento",
          "postOfficeBoxNumber": "UNAVAILABLE"
        }
      },
      {
        "@type": "Place",
        "address": {
          "@type": "PostalAddress",
          "postalCode": "UNAVAILABLE",
          "addressRegion": "CA",
          "streetAddress": "UNAVAILABLE",
          "addressCountry": "US",
          "addressLocality": "Oakland",
          "postOfficeBoxNumber": "UNAVAILABLE"
        }
      }
    ],
    "validThrough": "2027-06-03T04:00:00.000Z",
    "employmentType": "FULL_TIME",
    "hiringOrganization": {
      "name": "GFT.",
      "@type": "Organization",
      "sameAs": "www.gannettfleming.com"
    },
    "occupationalCategory": "Safety & Security"
  },
  "detail_meta": {
    "url": "https://careers-gannettfleming.icims.com/jobs/14226/principal-cybersecurity-compliance-analyst/job?in_iframe=1",
    "http_status": 200,
    "content_type": "text/html;charset=UTF-8",
    "response_bytes": 42565,
    "compact_response_bytes": 8640,
    "original_response_bytes": 42565
  },
  "sitemap_job": {
    "id": "14226",
    "url": "https://careers-gannettfleming.icims.com/jobs/14226/principal-cybersecurity-compliance-analyst/job",
    "slug": "principal-cybersecurity-compliance-analyst",
    "lastmod": "2026-06-03T13:51:26-04:00"
  },
  "detail_errors": []
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/2e4c0cd4d7d7fe98a253543cef50da9f24a943ef?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/9ea6b224-5b4a-4ec8-ab6d-e7b1fca3bc93JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/c00651d8-ad75-45e4-8161-fed1dab4d1c1JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/2e4c0cd4d7d7fe98a253543cef50da9f24a943ef/eventsJSON