Cybersecurity Analyst/Sr Cybersecurity Analyst (Full Time)
Location: Palmer
CYBERSECURITY ANALYST/SR CYBERSECURITY ANALYST - RFT |
|
Who can apply? |
MEA Employees & The General Public |
Posting Date |
March 18, 2025 |
Closing Date |
Open Until Filled |
Department |
Information Technology |
Grade/Annual Pay |
Grade 8 $77,313 Min DOE Grade 10 $92,040 Min DOE |
Union Representation |
N/A |
Hours of Work |
8AM-5PM Note: May be needed after hours and/or weekends. |
Work Location |
Palmer, AK |
PURPOSE
Ensures the Association achieves optimum use of infrastructure, including networks, servers, desktop computers, mobile devices, phones, and other computing and communications-related resources, while maintaining a strong cybersecurity posture. Participates in development of the Association’s cybersecurity related training, infrastructure planning, policies, and procedures.
ESSENTIAL FUNCTIONS OF THE POSITION
The Cybersecurity Analyst performs the below functions comfortably with supervisory oversight.
The Senior Cybersecurity Analyst performs and masters all the below functions and exercises independent judgement.
1.Manages the Association’s overarching cybersecurity efforts with a thorough understanding and application of industry best practices.
2.Directs technical aspects of system operations by identifying and prioritizing projects and managing tasks necessary in providing and maintaining a secure and reliable computing and communications infrastructure.
3.Architect, design, implement, administer, maintain, monitor, and collaborate with network and system administrators for security architecture technology processes and products including security information and event management, firewalls, anti-malware, intrusion detection, public key management, certificate management, physical security management, and identity and password management solutions.
4.Manages cybersecurity, disaster recovery, and data backups to ensure the safety, availability, and reliability of the Association’s cyber assets.
5.Manages cyber incident response, mitigation, and forensics as a lead member of the Cyber Response Team. Providing first responder forensics analysis and investigation. Investigate and lead response activities to security events and potential incidents in accordance with prescribed procedures.
6.Drive containment strategy during data loss or breach events.
7.Identify infrastructure, system and end user device vulnerabilities and communicate remediation actions to Network and System Administrators, and Support Specialists.
8.Triage and respond to active cyber-attacks or intrusions in accordance with the Incident Response Plan and organization policies.
9.Collaborate with organization vendors or Managed Security Service Providers, to tune logging and monitoring tools.
10.Monitor Security Information and Event Management (SIEM) systems and various client and server defense systems to ensure availability to all systems in conjunction with Managed Security Service Providers.
11.Administer, manage, maintain, and use system and application vulnerability scanning tools.
12.Maintain a high level of situational awareness by reviewing current, real time, and relevant threat information provided by Managed Security Service Providers, information sharing organizations like E-ISAC, CISA, and FBI alerts. Regularly brief staff of emerging threats including both general threats and those specifically targeting the electric sector and industrial control systems.
13.Develops, implements, and manages cybersecurity related policies and procedures.
14.Coordinates and prepares documentation required from outside audits to establish and substantiate compliance with regulatory requirements.
15.Assess infrastructure needs and proactively research, select, plan and implement appropriate, cost-effective solutions to meet business needs.
16.Responsible for active threat hunting and adversary tracking, to include using security technologies (firewall, antivirus, intrusion detection/prevention, PKI, encryption, SEIM, etc.).
17.Develop system standards, short and long-term goals, project management, process improvement, and strategic directions.
18.Manages and develops the Association’s cybersecurity training program. Conduct regular mandatory security trainings for all existing employees and new hires.
19.Performs routine audits of the Association’s information systems to ensure compliance with all Association policies, Government regulations and industry best practices.
20.Coordinates with various Operational Technology (OT) staff in managing and maintaining the security posture of OT systems.
21.Supports planning and management of the Association’s local and wide area networks and communications links, including Association-owned, leased, and/or shared fiber optic, copper, RF, and cellular communications circuits and related firewalls, routers, switches, and other devices and software.
22.Promotes a safety culture in which safety is a value. This culture is based on joint and individual engagement, ownership, and accountability regarding job safety and responsibility to perform work safely and adhere to safe work practices.
23.Performs the essential functions of this position in a safe and efficient manner.
The above items are not intended to be all inclusive of the essential functions or requirements of this type of work as they are subject to change based on operating necessity. The employee may also perform other related business duties as assigned.
ESSENTIAL POSITION REQUIREMENTS
Cybersecurity Analyst Requirements
Qualified candidates are required to have:
-A high school diploma/GED and four (4) years of relevant experience; or
-A relevant bachelor’s degree; or
-A relevant associate degree and two (2) years of relevant experience; or
-Completed relevant vocational training and two (2) years of relevant experience.
-A valid driver’s license and a driving record, which is acceptable by the Association’s Driving Policy and insurable by the Association and the Association’s insurance carrier at standard group rates.
Electric utility experience preferred.
Senior Cybersecurity Analyst Requirements
Qualified candidates are required to have:
-A high school diploma/GED and nine (9) years of relevant experience; or
-A relevant bachelor’s degree and five (5) years relevant experience; or
-A relevant associate degree and seven (7) years relevant experience; or
-Completed relevant vocational training and seven (7) years of relevant experience.
-A valid driver’s license and a driving record, which is acceptable by the Association’s Driving Policy and insurable by the Association and the Association’s insurance carrier at standard group rates.
Preference may be given to candidates with:
-Experience in cybersecurity and/or network infrastructure in an electric or other utility environment.
-Familiarity with cybersecurity maturity models (i.e., C2MS0, and those holding CISSP, GISP, Security +, or other applicable cybersecurity related certifications).
-Electric utility experience preferred.
KNOWLEDGE, SKILLS AND ABILITIES
•Supports a culture of safety excellence through active involvement in safety improvement and promotes a sense of shared responsibility for safety.
•Knowledge of new developments and practices relating to cybersecurity.
•Knowledge of new or developing technologies and solutions and seeks creative solutions to meet changing Association requirements.
•Knowledge of the principles, theories and methods of management as applied to cybersecurity, network and communications systems, current developments and trends within the technology field.
•Knowledge of incident and forensic response planning and execution.
•Knowledge of federal copyright laws and licensing agreements.
•Knowledge of auditing and related compliance documentation.
•Knowledge of legal, regulatory, and other applicable items as they relate to cybersecurity, information services, and communications technology.
•Knowledge of cybersecurity concerns, best practices, and protection of PII, including a working knowledge of NERC-CIP, NIST, PCI, HIPAA, and related security guidelines.
•Skill in threat intelligence consumption and management, malware infection root causes and proactive mitigation, and lateral movement, footholds, and data exfiltration techniques.
•Skill in threat intelligence consumption and management, malware infection root causes and proactive mitigation, and lateral movement, footholds, and data exfiltration techniques.
•Skill in providing high level customer-service when dealing with internal and external customers, business partners and others.
•Skill in effectively managing multiple projects simultaneously.
•Skill in organization, interpersonal communication, and attention to detail.
•Skill in developing and fostering effective teamwork and encourages growth and development of coworkers.
•Skill in effective and professional verbal, telephonic, and written communication.
•Ability to problem solve and investigate issues.
•Ability to conduct research into IT/OT security issues and products as required.
•Ability to maintain complete confidentiality of classified and confidential information.
•Ability to analyze processes and make recommendations for improvement.
•Ability to lead multi-disciplinary team in implementing systems.
•Ability to make well-reasoned accountable decisions.
•Ability to communicate persuasively and professionally with diverse audiences.
•Ability to establish and maintain professional relationships to effectively accomplish the goals of the Association.
•Ability to facilitate cooperation between work groups and work functionally across all levels of the organization.
•Ability to self-motivate improvement based on successes and failures.
•Ability to analyze processes for efficiency and recommend improvement(s).
•Embrace and embody the Association’s Core Values through decisions, actions, attitude, and behavior to directly contribute to the success of the organization.
PHYSICAL DEMANDS
•The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this position; this list is not inclusive of all the physical demands that may be required. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
•Physical demand activity percentages:
Major occurs 60% or more of work time.
Moderate occurs between 20-60% of work time.
Minor occurs less than 20% of work time.
•Physical demand requirements:
Ability to understand, read, and carry out written instructions.
Ability to understand, read, and verify documents electronically, verbally, or hard copy.
Major amount of acute seeing - near, sitting, working inside.
Moderate amount of ordinary hearing.
Minor amount of standing, walking, lifting/carrying/pushing up to 50 pounds, stair climbing, ladder climbing, kneeling, crouching, crawling, turning/twisting, bending at waist, handling of items, finger use, feeling/touching, eye-hand coordination, foot-hand-eye coordination, acute seeing – far, depth perception.
ENVIRONMENTAL CONDITIONS
•The work environment conditions described here are representative of those an employee encounters while performing the essential functions of this position. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
•This position primarily works in an office setting.
EMPLOYMENT STATUS
This position is classified as an exempt, non-represented position; and therefore, is not eligible for overtime compensation. All Association employees are expected to work widely varying amounts of time outside the normal shifts to assist in power restoration or other needs of the Association.
MEA requires a post offer drug test. Any positive test result or refusal to consent will disqualify an applicant from employment.
MEA is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.
Individuals with disabilities who require reasonable accommodation(s) to participate in any portion of the application or interview process should advise MEA in advance by calling 907-761-9218.
Applicants must be currently authorized to work in the United States on a full-time basis.
To apply, please visit www.mea.coop to submit an application by the closing date.
Matanuska Electric Association, Inc.
163 East Industrial Way (P.O. Box 2929), Palmer, Alaska 99645
Telephone: (907) 761-9218/ Fax: (907) 761-9264
MEA is an Equal Employment Opportunity Veterans/Disabled employer.
Benefits Include
•401(k) matching 2%
•Medical, Dental, Vision insurance - $120/month for entire family
•Life insurance 100% paid by MEA
•Long Term Disability 100% paid by MEA
•Employee assistance program
•Paid time off starts at 3.385 hrs/wk
•11.5 paid holidays per year.
•Retirement Defined Benefit plan/Pension
Copyright 2021 Matanuska Electric Association, Inc.