About this role
<p>Requisition Number: 29670 </p> <p><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">At UGI Utilities, Inc. we believe in providing a superior range of energy products and services to our customers in a safe, affordable manner. As our energy needs evolve, UGI will be there providing safe and reliable service that brings warmth and comfort to our 750,000 customers in 45 counties in Pennsylvania and 1 county in Maryland.</span></span></p> <p> </p> <p><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">We strive to reflect the communities we serve by attracting and retaining top talent, while maintaining a diverse workforce that embraces our culture of safety, service, and integrity. As an employee of UGI Utilities, you can expect a competitive total compensation plan and comprehensive benefits. Employees work in a collaborative environment, have upward mobility opportunities, and the ability to enjoy a true work life balance.</span></span></p> <p> </p> <p><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">To learn more about UGI's workplace culture, sustainability efforts, and commitment to inclusivity, we invite you to visit our <a id="menur8n6" title="https://ugiesg.com/" href="https://ugiesg.com/" target="_blank" rel="noreferrer noopener">UGI Corporate sustainability page</a>. </span></span></p> <p> </p> <p><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">Apply to UGI Utilities today to share in our mission and support countless neighbors, friends, and families in providing best-in-class products and services!</span></span></p><p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif">Job Summary:</p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif">The Global Cybersecurity Senior GRC Analyst plays a critical role in ensuring that the organization operates within its regulatory, legal, and compliance obligations while managing risk effectively. The Global GRC Senior Analyst will report directly to the Global Cybersecurity Governance, Risk and Compliance Manager. This role involves collaborating with cross-functional teams to design, implement, and maintain governance, risk, and compliance processes. The ideal candidate is detail-oriented, analytical, and experienced in regulatory compliance, risk management frameworks, and governance best practices and must develop and apply continuous improvement strategies in all aspects of the job function.</p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Key Responsibilities:</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Governance:</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif"> • Develop and maintain corporate policies, procedures, and frameworks to align with industry best practices (e.g., NIST CSF, SOX, PCI, etc.).</span></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="margin:0.0in 0.0in 0.0in 12.0px;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Assist with the development and maintenance of GRC process and procedure documentation.</span></li> </ul> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif"> • Ensure IT functions are in compliance with best practices and company policies and standards through assessments (i.e. peer reviews, audits, etc.) </span></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="margin:0.0in 0.0in 0.0in 12.0px;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Track key risk indicators and security metrics </span></li> </ul> <p style="margin:0.0in 0.0in 0.0in 9.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Risk Management:</span></p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif"> • Assist with conducting gap assessments to identify threats, vulnerabilities, and potential impacts on the organization.</span></p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif"> • Develop and maintain the risk register, ensuring risks are documented, prioritized, and mitigated.</span></p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif"> • Perform third-party/vendor risk assessments to evaluate potential risks associated with external partnerships and perform on-going monitoring to assess risk of engagement. </span></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="margin:0.0in 0.0in 0.0in 12.0px;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Maintain centralized documentation, continuous monitoring for vendors, formal escalation protocols for non-compliance to ensure alignment with enterprise risk tolerance.</span></li> <li style="margin:0.0in 0.0in 0.0in 12.0px;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Document risk acceptance decisions and compensating controls</span></li> <li style="margin:0.0in 0.0in 0.0in 12.0px;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Develop and maintain templates for consistent risk documentation</span></li> <li style="margin:0.0in 0.0in 0.0in 12.0px;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Assist in evaluating cybersecurity risk on incoming projects.</span></li> <li style="margin:0.0in 0.0in 0.0in 12.0px;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Assist and support team in performing cybersecurity due diligence on merger/acquisition targets.</span></li> </ul> <p style="margin:0.0in 0.0in 0.0in 45.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p><span style="font-size:11.0pt;line-height:107%;font-family:'Aptos Display', sans-serif"> </span></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Compliance:</span></p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif"> • Ensure compliance with regulatory requirements (e.g., GDPR, HIPAA, SOX, PCI-DSS) and industry standards through monitoring and reporting metrics, security exceptions and using other methods to monitor compliance</span></p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif"> •Drive compliance by maintaining the compliance framework to ensure policies and standards align to regulatory requirements, laws and best practices. </span></p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Stakeholder Engagement </span></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Collaborate with business units to understand critical processes </span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Educate stakeholders on risk management concepts and frameworks </span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Partner with technical teams to validate remediation plans </span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:107%;font-size:11.0pt;font-family:Aptos, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Present risk findings to appropriate governance committees</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Coordinate and collaborate with stakeholders to establish and track metrics for governance programs.</span></li> </ul> <p style="margin:0.0in 0.0in 0.0in 0.25in;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif"> • Collaborate with stakeholders to monitor regulatory and industry developments to ensure </span></p> <p style="margin:0.0in 0.0in 0.0in 0.25in;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif"> compliance with changes.</span></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="margin:0.0in 0.0in 0.0in 0.0px;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Coordinate and collaborate with stakeholders to track outcomes and metrics for all third-party breaches. </span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Advise stakeholders on compliance requirements and incorporate new metrics into governance life cycle process, including new tools as they are onboarded.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-family:'Aptos Display', sans-serif">Coordinate the review of Policies and Standards through collaborating with stakeholders. </span></li> </ul> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif">Collaboration and Reporting:</p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"> • Partner with IT, Legal, HR, and other departments to ensure alignment on risk and compliance efforts.</p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"> • Create and deliver regular risk and compliance metrics for senior leadership and boards.</p> <p style="margin:0.0in 0.0in 0.0in 27.0pt;text-indent:-27.0pt;font-size:11.0pt;font-family:Calibri, sans-serif"> • Serve as a subject matter expert (SME) for GRC-related queries and initiatives.</p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif">Qualifications:</p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif">Education and Experience:</p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 22.5pt;text-indent:-22.5pt;font-size:11.0pt;font-family:Calibri, sans-serif"> • Bachelor’s degree in Information Security, Risk Management, Computer Science, or related field, preferred.</p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> • At least 4 years of experience in GRC, risk management, or compliance roles.</p> <p style="margin:0.0in 0.0in 0.0in 22.5pt;text-indent:-22.5pt;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 22.5pt;text-indent:-22.5pt;font-size:11.0pt;font-family:Calibri, sans-serif">Skills and Competencies:</p> <p style="margin:0.0in 0.0in 0.0in 22.5pt;text-indent:-22.5pt;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 0.0in 22.5pt;text-indent:-22.5pt;font-size:11.0pt;font-family:Calibri, sans-serif"> • Strong understanding of GRC tools and platforms (e.g., RSA Archer, ServiceNow GRC).</p> <p style="margin:0.0in 0.0in 0.0in 22.5pt;text-indent:-22.5pt;font-size:11.0pt;font-family:Calibri, sans-serif"> • Familiarity with risk management frameworks (e.g., COBIT, FAIR) and compliance standards.</p> <p style="margin:0.0in 0.0in 0.0in 22.5pt;text-indent:-22.5pt;font-size:11.0pt;font-family:Calibri, sans-serif"> • Exceptional analytical, problem-solving, and organizational skills.</p> <p style="margin:0.0in 0.0in 0.0in 22.5pt;text-indent:-22.5pt;font-size:11.0pt;font-family:Calibri, sans-serif"> • Strong written and verbal communication skills, with the ability to interact effectively with stakeholders at all levels.</p> <p style="margin:0.0in 0.0in 0.0in 22.5pt;text-indent:-22.5pt;font-size:11.0pt;font-family:Calibri, sans-serif"> • Certifications such as CRISC, CISM, CISA or CISSP highly preferred.</p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif">Key Attributes:</p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> • Attention to detail and ability to manage multiple priorities.</p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> • Proactive mindset with a focus on continuous improvement.</p> <p style="margin:0.0in;font-size:11.0pt;font-family:Calibri, sans-serif"> • Collaborative team player who can influence without authority.</p><p><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif"><span id="cke_bm_871S" style="display:none"> </span><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">UGI Utilities, Inc</span></span></span></span><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif"> is an Equal Opportunity Employer. The Company does not discriminate on the basis of race, color, sex, national origin, disability, age, gender identity, sexual orientation, veteran status, or any other legally protected class in its practices.</span></span></p> <p><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">Successful applicants shall be required to pass a pre-employment drug screen as a condition of employment, and if hired, shall be subject to substance abuse testing in accordance with UGI policies.</span></span></p> <p><span style="font-size:16.0px"><span style="font-family:Arial, Helvetica, sans-serif">As a federal contractor that engages in safety-sensitive work, UGI cannot permit employees in certain positions to use medical marijuana, even if prescribed by an authorized physician. Similarly, applicants for such positions who are actively using medical marijuana may be denied hire on that basis.</span></span></p>