×
Register Here to Apply for Jobs or Post Jobs. X

Specialist Cybersecurity Risk & Compliance Analyst

Job in Atlanta, Fulton County, Georgia, 30301, USA
Listing for: Southern Company
Full Time position
Listed on 2026-03-14
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Job Description & How to Apply Below
Specialist Cybersecurity Risk & Compliance Analyst

Location:

Birmingham, AL or Atlanta, GA

Onsite 4 days per week.

Job Description

Southern Company's Cybersecurity organization is committed to reducing risk using a threat-informed approach, enhancing the cyber resilience of Southern Company while delivering clean, safe, reliable, and affordable energy to the communities we serve.

Position Overview:

Southern Company, a major U.S. energy firm, is seeking a cybersecurity professional to reduce risk as part of the Cybersecurity Assurance Team. This hybrid role reports directly to the Company's Senior Manager for Cybersecurity Assurance. This position is an analyst role responsible for assessing cyber security risk across multiple business units, managing compliance programs linked to applicable Federal cyber security directives/regulations, managing third party penetration testers, and engaging externally with key industry partners/organizations both as advocate and educator.

The analyst will combine solid business knowledge, strong understanding of cybersecurity principles, and close familiarity with Federal requirements to reduce cybersecurity and business risk over time. Up to 20% travel may be required.

In-office presence four days a week is expected either in Atlanta or Birmingham.

Job Responsibilities:

+ Serve as the lead in performing and coordination of cyber security assessments throughout the company.

+ Department of War (DoW) Cybersecurity Maturity Model Certification (CMMC)

+ Department of Homeland Security Safety Act

+ NIST Cyber Security Framework

+ DoW Defense Federal Acquisition Regulation Supplement (DFARS) , Safeguarding Covered Defense Information and Cyber Incident Reporting and DFARS  contractor compliance with the cybersecurity maturity model certification level requirements (Nov 2025)

+ Edison Electric Institute (EEI) Culture of Security

+ Adversarial assessments (penetration tests)

+ Perform analysis of assessment findings

+ Perform or coordinate related remediation by technology stewards and/or recommend investments to address identified cybersecurity gaps/risk

+ Manage CUI compliance program with and all required reporting for DFARS 252.204‑7021, Contractor Compliance with the CMMC Level Requirements

+ Consult/collaborate with inside and external Counsel regarding CUI requirements

+ Respond to requests from prime contracting officers on matters relating to CUI scope

+ Manage External Enclave used for sharing Controlled Unclassified Information with business and Federal partners, including the enforcement of all required configuration(s), compliance attestations, reporting, and licensing

+ Perform Department of War Cyber Incident Reporting as required

+ Serve as the Cyber Liaison for the Company's Federal Energy Services group

+ Keep senior leadership apprised of pending state regulations pertaining to cybersecurity and impacting utilities; provide Southern Company response to proposed state legislation

+ Provide briefings to senior leadership and external stakeholders in a way that links technical and business risk to drive prioritization of effort and investment decisions

+ External Engagement/executive support (

NOTE:

Requires face to face meetings and travel, up to 20%)

+ Interact with external organizations such as state Public Service Commissions, State representatives, other utilities, trade organizations, and federal partners in representing Southern Company's cyber security practice.

+ Represent Southern Company by presenting or speaking at various federal conferences

+ Influence the utility industry's creation, adoption and implementation of information security practices by participating in industry forums, events, and committees

+ Participate in the EEI Peer Review process

+ Lead cross-functional efforts for monitoring and maintaining compliance of security controls associated with Federal projects

+ Build and maintain strategic partnerships with key business stakeholders; collaborate closely with solution owners from the business and Technology Organization, seeking to understand business imperatives while educating them as needed regarding relevant requirements and controls

+ Support…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary