
Information Security Compliance Analyst
Sungrow
Visa & sponsorship
- The posting says it will not sponsor a visa for this role.
Job description
Information Security Compliance Analyst
About Sungrow:
Sungrow North America is a leading provider of renewable energy solutions, specializing in the development and manufacturing of photovoltaic inverters and energy storage systems. .
The company offers a comprehensive range of products and services designed to optimize the performance and efficiency of solar power installations. Sungrow North America is known for its commitment to innovation, high-quality standards, and exceptional customer service, aiming to provide sustainable and reliable energy solutions to meet the growing demand for clean power.
As Sungrow continues to expand its operations and critical infrastructure footprint in the United States, cybersecurity governance, regulatory alignment, customer assurance, and demonstrable security controls are increasingly important components of the company's cybersecurity program.
The Position:
Sungrow is seeking an Information Security Compliance Analyst II to join the Information Security organization. Reporting to the Information Security GRC Manager, this position will support the implementation, documentation, validation, and ongoing monitoring of cybersecurity controls across enterprise and product environments.
This is a hands-on governance, risk, and compliance role requiring a strong foundation in cybersecurity, security controls, risk analysis, technical documentation, and evidence management.
The Information Security Compliance Analyst II will work closely with Information Security leadership, technical teams, business functions, and control owners to translate cybersecurity policies, framework requirements, customer expectations, and compliance obligations into practical and sustainable controls.
A primary responsibility of this position is ensuring that Sungrow can substantiate the implementation and effectiveness of its cybersecurity controls through accurate, complete, traceable, and defensible evidence.
The analyst will support policy development, control implementation, compliance assessments, evidence management, remediation tracking, customer security assurance, and continuous compliance activities while developing deeper expertise in cybersecurity governance and critical-infrastructure requirements.
Essential Duties and Responsibilities
1. Security Control Implementation and Validation
-
Support the development, implementation, documentation, and maintenance of cybersecurity controls across enterprise and product environments.
-
Work directly with control owners to translate cybersecurity requirements into practical operational and technical controls.
-
Document control objectives, ownership, scope, frequency, procedures, dependencies, and evidence requirements.
-
Review existing security practices against established requirements and identify potential control deficiencies.
-
Validate that controls have been implemented and are operating in accordance with documented requirements.
-
Coordinate with responsible teams to address identified deficiencies and track remediation through closure.
-
Assist in identifying appropriate compensating controls where primary controls cannot reasonably be implemented.
-
Support documentation and tracking of control exceptions and risk-acceptance decisions.
2. Evidence Management and Control Substantiation
-
Collect, organize, review, and maintain evidence demonstrating the implementation and operation of cybersecurity controls.
-
Evaluate whether submitted evidence is sufficient to substantiate control performance and effectiveness.
-
Maintain traceability between requirements, policies, controls, control owners, testing activities, and supporting evidence.
-
Identify incomplete, outdated, inconsistent, or insufficient evidence and coordinate resolution with responsible stakeholders.
-
Establish repeatable evidence-collection processes and evidence requirements.
-
Maintain organized evidence repositories supporting audits, assessments, customer reviews, and internal compliance activities.
-
Support periodic control testing and validation activities.
-
Maintain documentation in accordance with applicable confidentiality, integrity, retention, and chain-of-custody requirements.
3. Policy, Standards, and Procedure Governance
-
Assist in drafting, reviewing, maintaining, and implementing information security policies, standards, procedures, and supporting governance documentation.
-
Work with the GRC Manager and subject-matter experts to translate cybersecurity requirements into organizational policies and controls.
-
Support policy review, approval, publication, acknowledgement, and periodic review processes.
-
Monitor adherence to established cybersecurity policies and standards.
-
Assist business and technical teams in understanding and implementing policy requirements.
-
Document policy exceptions and support associated review, remediation, and risk-acceptance processes.
-
Track policy and standards lifecycle requirements and associated compliance activities.
4. Cybersecurity Framework and Regulatory Alignment
-
Support implementation and maintenance of cybersecurity requirements associated with applicable frameworks, standards, and regulatory expectations, including:
-
NIST Cybersecurity Framework (CSF)
-
NIST SP 800-series guidance
-
ISO/IEC 27001 and ISO/IEC 27002
-
SOC 2
-
NERC CIP, where applicable
-
Other cybersecurity and critical-infrastructure requirements applicable to Sungrow's business, products, and customers
-
-
Research cybersecurity requirements and assist in determining their applicability to Sungrow environments.
-
Map organizational controls to applicable framework, regulatory, contractual, and customer requirements.
-
Support cybersecurity gap assessments and compliance-readiness reviews.
-
Assist in developing and tracking remediation plans for identified gaps.
-
Maintain awareness of evolving cybersecurity requirements affecting the U.S. energy and critical-infrastructure sectors.
5. Enterprise and Product Compliance
-
Support cybersecurity compliance activities across both enterprise IT and product environments.
-
Coordinate with Product Security, Engineering, Information Technology, Security Operations, and other stakeholders to document and substantiate applicable controls.
-
Support tracking of cybersecurity requirements across systems, products, business units, and organizational functions.
-
Assist in establishing consistent control and evidence practices across enterprise and product security programs.
-
Maintain records of compliance status, identified gaps, exceptions, remediation activities, and supporting evidence.
6. Assessments and Audit Readiness
-
Support internal and external cybersecurity assessments, audits, customer reviews, and certification activities.
-
Coordinate evidence requests with control owners and responsible stakeholders.
-
Review evidence for completeness, accuracy, relevance, and traceability prior to submission.
-
Prepare and organize supporting documentation for assessments.
-
Document findings and track corrective actions through remediation and validation.
-
Assist control owners in understanding assessment requirements and preparing for evidence reviews.
-
Support continuous audit readiness rather than relying solely on point-in-time audit preparation.
7. Customer and Third-Party Security Assurance
-
Support completion of customer, partner, and third-party cybersecurity questionnaires and due-diligence requests.
-
Research questions and coordinate responses with appropriate internal subject-matter experts.
-
Ensure statements regarding Sungrow's cybersecurity practices are supported by documented controls and available evidence.
-
Maintain reusable evidence and validated responses to improve consistency and efficiency.
-
Escalate questions involving material regulatory, contractual, or cybersecurity representations to Information Security leadership and Legal as appropriate.
-
Support third-party cybersecurity assessments and associated compliance documentation.
8. Compliance Monitoring, Remediation, and Reporting
-
Maintain compliance trackers, control records, evidence inventories, findings, exceptions, and remediation activities.
-
Monitor evidence currency, remediation deadlines, policy reviews, control status, and other compliance obligations.
-
Assist in developing cybersecurity compliance metrics, dashboards, and key control indicators.
-
Prepare clear written summaries of findings, risks, compliance gaps, and remediation status.
-
Provide accurate compliance information to the Information Security GRC Manager for leadership and governance reporting.
-
Escalate material, overdue, or unresolved compliance issues through established governance processes.
9. Cross-Functional Collaboration
-
Build effective working relationships with technical and nontechnical stakeholders throughout the organization.
-
Communicate cybersecurity requirements clearly and professionally.
-
Facilitate control-design, evidence-collection, and compliance-review discussions.
-
Help control owners understand both the requirement and the underlying security objective.
-
Work collaboratively to develop sustainable controls that satisfy security requirements without creating unnecessary operational burden.
-
Maintain appropriate independence when evaluating whether controls and evidence satisfy established requirements.
10. Program Development and Continuous Improvement
-
Support continued development and maturation of Sungrow's U.S. cybersecurity governance and compliance program.
-
Develop repeatable templates, procedures, evidence standards, control documentation, and compliance workflows.
-
Identify opportunities to automate evidence collection, control monitoring, and compliance reporting.
-
Support implementation and administration of GRC and compliance-management technologies.
-
Research evolving cybersecurity frameworks, regulatory requirements, and industry practices.
-
Continuously develop expertise in cybersecurity governance, risk, compliance, product security, and critical-infrastructure security.
Minimum Qualifications
-
3+ years of professional experience in cybersecurity, information security, information technology, information assurance, intelligence, security operations, risk management, compliance, audit, or another security-related discipline.
-
Experience working within structured security, technical, regulatory, military, government, critical-infrastructure, or other high-accountability environments.
-
Experience collecting, analyzing, documenting, or reporting technical, operational, or security-related evidence.
-
Experience implementing, validating, monitoring, assessing, or operating security controls or security configurations.
-
Working knowledge of cybersecurity risk and fundamental security-control concepts.
-
Familiarity with cybersecurity policies, standards, procedures, or formal security requirements.
-
Foundational knowledge of one or more cybersecurity frameworks or standards such as NIST CSF, NIST SP 800-series guidance, ISO/IEC 27001, SOC 2, NERC CIP, or comparable frameworks.
-
Strong analytical, technical-writing, and documentation skills.
-
Demonstrated attention to detail and ability to maintain accurate and defensible records.
-
Ability to communicate effectively with both technical and nontechnical stakeholders.
-
Ability to independently research unfamiliar cybersecurity requirements and translate findings into practical recommendations.
-
Ability to manage multiple priorities and follow assigned compliance activities through completion.
Preferred Qualifications
-
Bachelor's degree in Cybersecurity, Information Security, Information Technology, Computer Science, or a related discipline. Equivalent military, government, technical, or professional experience may be considered.
-
Experience supporting cybersecurity evidence collection, control validation, risk assessments, compliance assessments, or audit activities.
-
Experience working in military, government, defense, energy, critical infrastructure, manufacturing, industrial technology, or similarly controlled environments.
-
Experience operating under formal security protocols, access-control requirements, information-handling procedures, or chain-of-custody requirements.
-
Experience preparing formal technical, security, risk, or compliance reports.
-
Familiarity with enterprise security technologies, networking, identity and access management, vulnerability management, security monitoring, or incident response concepts.
-
Exposure to customer security questionnaires, third-party risk assessments, audit preparation, or compliance activities.
-
Relevant cybersecurity certifications such as CompTIA Security+, CySA+, Network+, CISA, CRISC, ISO/IEC 27001 certifications, or comparable credentials.
-
Demonstrated interest in developing advanced expertise in cybersecurity governance, risk, compliance, and critical-infrastructure security.
Core Competencies
-
Evidence Discipline: Produces accurate, traceable, and well-organized documentation capable of supporting cybersecurity and compliance conclusions.
-
Analytical Thinking: Evaluates technical and operational information, identifies deficiencies, and develops defensible conclusions.
-
Technical Aptitude: Understands cybersecurity concepts sufficiently to communicate with technical control owners and evaluate supporting evidence.
-
Procedural Discipline: Operates effectively within established security requirements and structured processes.
-
Accountability: Takes ownership of assigned activities and follows requirements, findings, and remediation through completion.
-
Communication: Translates technical and compliance requirements into clear documentation for technical, business, and leadership audiences.
-
Collaboration and Influence: Works constructively with control owners and cross-functional teams while maintaining the integrity of security requirements.
-
Learning Agility: Quickly develops working knowledge of unfamiliar frameworks, regulations, systems, technologies, and business processes.
-
Integrity and Discretion: Handles sensitive cybersecurity and business information with appropriate confidentiality and professional judgment.
-
Continuous Improvement: Looks beyond completion of individual compliance activities to improve the sustainability, efficiency, and maturity of the overall program.
Travel
Up to 25%, based on business requirements.
Work Location and Status
-
Full-time position.
-
Remote with on-site work as required.
-
No visa sponsorship.
Compensation
-
$110,000โ$135,000 annual base salary.
-
Comprehensive benefits package and professional development opportunities.
Sungrow is an equal opportunity employer. Due to strong interests in this position, Sungrow will only reach out to those candidates who best meet the requirements. Thank you for your interest in Sungrow.