← back to jobs
> job detail
E
👽Other

Information Security Analyst I

Entergy · The Woodlands, Texas, United States
// classified as
Other (Adjacent or hard to classify.)
posted
1d ago
location
The Woodlands, Texas, United States
languages
tools
> education
bachelorsms
> description
<p><span style="font-size:12.0px"><b><span style="font-family:Arial, Helvetica, sans-serif">Job Title: </span></b><span style="font-family:Arial, Helvetica, sans-serif">Information Security Analyst I - III</span></span></p> <p><span style="font-size:12.0px"><b><span style="font-family:Arial, Helvetica, sans-serif">Work Place Flexibility:</span></b><span style="font-family:Arial, Helvetica, sans-serif"> Hybrid </span></span></p> <p><span style="font-size:12.0px"><b><span style="font-family:Arial, Helvetica, sans-serif">Legal Entity:</span></b><span style="font-family:Arial, Helvetica, sans-serif"> Entergy Services, LLC</span> </span></p> <p style="text-align:center"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">***Preferred location for this role is The Woodlands, TX or Little Rock, AR; however, New Orleans, LA and Jackson, MS will also be considered. ***</span></strong></p> <p style="text-align:center"><strong><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">***This position will be filled as an Information Security Analyst I, II or III, depending on the candidate’s experience and education. ***</span></strong></p> <p> </p> <p><span style="font-size:12.0pt"><strong><span style="font-family:arial, helvetica, sans-serif">Job Summary/Purpose:</span></strong></span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">The Consolidated Security Operations Center Analyst will report to the Supervisor of CSOC and will manage day-to-day tasks as noted below, with additional projects as they arise. The Analyst to join our dynamic team with the Cybersecurity Organization at Entergy will have curiosity, critical thinking, analysis background and security background. This position will play a critical role in safeguarding our infrastructure and ensuring the integrity of our operations. The analyst will be responsible for investigating and responding to security incidents, understanding, and mitigating attack vectors, and staying abreast of the evolving threat landscape. They will also be able to lead junior analysts and assist in maturing the security program.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">The ideal candidate is detail oriented, a problem solver with critical thinking skills, and focused on process improvement.</span></p> <p> </p> <p><span style="font-size:12.0pt"><strong><span style="font-family:arial, helvetica, sans-serif">Job Duties/Responsibilities:</span></strong></span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Understanding of digital evidence and forensic analysis.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Assist in continuously improving the existing daily operational and incident response procedures and playbooks.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Identify automation opportunities to improve capabilities.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Identify problematic trends and take proactive steps to mitigate negative impacts to customer base.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Conduct investigations and understand security incidents, including but not limited to, malware infections, phishing attempts, and unauthorized access attempts.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Analyze and understand various attack vectors used by threat actors to compromise systems and data.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Monitor and assess the threat landscape to identify emerging threats and vulnerabilities relevant to our environment.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Knowledge of using SIEM tools with possible areas of development and upkeep of detections</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Maintain understanding of the various threats and risks related to utility workforce, energy providers and/or NERC/CIP.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Monitor and participate in training and exercises to ensure CSOC team proficiency.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Participate in post-incident reviews to identify lessons learned and best practices.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Ability to work in network investigations to identify and mitigate potential security risks and intrusions.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Knowledge in Cloud (SaaS, IaaS, PaaS) Industrial Control Systems (ICS) and Operational Technology (OT) to protect critical infrastructure and operational assets.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Collaborate with cross-functional teams to understand security controls and measures to enhance our overall security posture.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Understand cloud security monitoring and support improvements for maturity posture.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Understand and recommend incident response process, procedures and playbooks to ensure effective and efficient response to security incidents.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Support the threat hunting team to identify gaps of coverage and make recommendations on use cases for monitoring.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Understand MITRE Framework, identify TTPs and identify patterns and threat actors focused to the industry.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Provide timely and accurate reports on security incidents, trends, and metrics to stakeholders and management.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Available to travel up to 25%</span></p> <p> </p> <p><span style="font-size:12.0pt"><strong><span style="font-family:arial, helvetica, sans-serif">MINIMUM REQUIREMENTS Minimum education required of the position.</span></strong></span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Typically requires an associate’s degree or university degree in related field (i.e. Cybersecurity, Information security, criminal justice, computer science, etc.) or the equivalent work experience.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Minimum experience required of the position</span></p> <p>Analyst I:</p> <p>0 to 1+ years of security experience, across multiple disciplines (incident response, threat hunting, monitoring, crisis management, log gathering, event correlation, configuration, behavior analytics, network engineering data analytics, application security, database security, risk management, project management, physical security, etc.). Typically requires an associate’s degree or university degree in related field (i.e. Cybersecurity, Information security, criminal justice, computer science, etc.) or the equivalent work experience.</p> <p>Analyst II:</p> <p>2+ years of cybersecurity experience, across multiple disciplines (playbook development, incident response, threat hunting, monitoring, crisis management, log gathering, event correlation, configuration, behavior analytics, network engineering data analytics, application security, database security, risk management, project management, physical security, etc.) experience can be substituted with education as follows:</p> <ul type="disc"> <li>Associate degree in cybersecurity or related field and 1+ years of experience</li> </ul> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Analyst III:</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· 5+ years of cyber security experience, across multiple disciplines (playbook development, incident response, threat hunting, monitoring, log gathering, event correlation, configuration, behavior analytics, network engineering data analytics, application security, database security, risk management, project management, physical security, etc.) experience can be substituted with education as follows:</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">o Bachelor’s degree in cybersecurity and 3+ years of experience</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· 3 years of hands-on experience working with Security Incident and Event Management, incident response in a SOC environment with a structured after-hours process</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Hands-on experience working with Security Information Event Management (SIEM), event and incident investigations and incident response in a 24/7 SOC environment</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Ability to work effectively with team members and with customers</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Knowledge of various attack vectors, threat intelligence sources, and the cybersecurity threat landscape.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Experience to include some of the following: access control, CCTV, network investigations, intrusion detection systems (IDS), and/or security information and event management (SIEM) tools.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Understanding of Cloud (SaaS, IaaS, PaaS), Industrial Control Systems (ICS) and Operational Technology (OT) security principles and best practices.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Understanding of cloud environment for security principles and best practices</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Provide guidance and mentorship to others in cyber threat analysis and operations.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Proactively identify possible threats, security gaps and vulnerabilities</span></p> <p> </p> <p><span style="font-size:12.0pt"><strong><span style="font-family:arial, helvetica, sans-serif">Minimum knowledge, skills and abilities required of the position</span></strong></span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Good planning, organizational and time management skills; detail and process-oriented; able to juggle multiple priorities.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Understanding of MITRE ATT&amp;CK Framework</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Good problem-solving/decision making ability</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Good written and verbal communication skills.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Good interpersonal skills, including teamwork.</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Highly collaborative, able to work cross-functionally; possessing the ability to forge relationships and partner effectively</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Resourceful and self-motivated, able to work independently when required</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Good analytical, critical thinking and decision-making skills</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Cloud understanding of secure monitoring and incident response</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Understanding of systems (including industrial control systems)</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Good report writing and communication and ability to effectively communicate across the organization</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Demonstrated commitment to customer service with excellent oral and written communication skills</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Self-motivated, with ability to work independently and in a team setting while following up on multiple tasks</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Any certificates, licenses, etc. required for the position One or more technical or InfoSec certifications are a plus, i.e., CompTIA, ISACA, EC-Council, Cloud or ISC2.</span></p> <p> </p> <p><span style="font-size:12.0pt"><strong><span style="font-family:arial, helvetica, sans-serif">Technical Competencies</span></strong></span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Hands-on technical engineering and process management skills and the ability to advocate positive transformation</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Knowledgeable about security operations, cyber security monitoring, intrusion detection, and secure networks</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Some knowledge of multiple UNIX OS platforms and Windows-based operating systems</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Some knowledge of current IT Security trends and best practices in technology, as well as monitoring best practices and tools</span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">· Some knowledge of security, risk, and control frameworks and standards such as ISO 27001 and 27002, SANS-CAG, NIST, FISMA, COB</span></p> <p> </p> <p> </p> <p><span style="color:white"><strong>#LI-DG1 </strong><strong>#LI-HYBRID</strong> </span></p><p><span style="font-size:12.0px"><span style="font-family:Arial, Helvetica, sans-serif"><b>Primary Location:</b> Texas-The Woodlands Texas : The Woodlands || Arkansas : Little Rock || Louisiana : New Orleans || Mississippi : Jackson</span> <br> <span style="font-family:Arial, Helvetica, sans-serif"><b>Job Function</b>: Corporate<br> <b>FLSA Status</b>: Professional</span> <br> <span style="font-family:Arial, Helvetica, sans-serif"><b>Relocation Option:</b> <br> <b>Union description/code</b>: NON BARGAINING UNIT</span> <br> <span style="font-family:Arial, Helvetica, sans-serif"><b>Number of Openings</b>: 1<br> <b>Req ID:</b> 123818<br> <b>Travel Percentage</b>:Up to 25%</span></span></p> <p><span style="font-size:12.0px"><span style="font-family:Arial, Helvetica, sans-serif">An Equal Opportunity Employer, Minority/Female/Disability/Vets. Please click <a href="https://jobs.entergy.com/content/EEO/?locale=en_US"><u>here</u> </a>to view the EEO page, or see statements below.</span></span></p> <p><span style="font-size:12.0px"><b>EEO Statement: </b>The Entergy System of Companies provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a protected veteran in accordance with applicable federal, state and local laws. The Entergy System of Companies complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment including, but not limited to, recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. <br> <br> The Entergy System of Companies expressly prohibits any form of unlawful employee harassment based on race, color, religion, sex, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status. Improper interference with the ability of the Entergy System of Company employees to perform their expected job duties is absolutely not tolerated.</span></p> <p><span style="font-size:12.0px"><b>Accessibility: </b>Entergy provides reasonable accommodations for online applicants. Requests for a reasonable accommodation may be made orally or in writing by an applicant, employee, or third party on his or her behalf. If you are an individual with a disability and you are in need of an accommodation for the recruiting process please click <b><u><a href="mailto:humanr@entergy.com?subject=Accessibility" target="_blank" title="here">here</a></u></b> and provide your name, contact number, the accommodation requested and the requisition number that you are requesting the accommodation for. Employee Services will contact you regarding your request.</span></p> <p><span style="font-size:12.0px"><b>Additional Responsibilities:</b> As a provider of essential services, Entergy expects its employees to be available to work additional hours, to work in alternate locations, and/or to perform additional duties in connection with storms, outages, emergencies, or other situations as deemed necessary by the company. Exempt employees may not be paid overtime associated with such duties.</span></p> <p><span style="font-size:12.0px"><u><b><a href="https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12ScreenRdr.pdf" target="_blank" title="Equal Opportunity">Know Your Rights: Workplace Discrimination is Illegal</a></b></u></span></p> <p><span style="font-size:12.0px">The non-confidential portions of the affirmative action program for individuals with disabilities and protected veterans shall be available for inspection upon request by any employee or applicant for employment.  Please contact HRCompliance@entergy.com to schedule a time to review the affirmative action plan during regular office hours.</span></p> <p><span style="font-size:12.0px"><span style="font-family:Arial, Helvetica, sans-serif"><b>WORKING CONDITIONS: </b><br> As a provider of essential services, Entergy expects its employees to be available to work additional hours, to work in alternate locations, and/or to perform additional duties in connection with storms, outages, emergencies, or other situations as deemed necessary by the company. Exempt employees may not be paid overtime associated with such duties.</span></span></p> <p><span style="font-size:12.0px"><span style="font-family:Arial, Helvetica, sans-serif"><b>Please note: </b>Authorization to work in the United States is a precondition to employment in this position. Entergy will not sponsor candidates for work visas for this position.</span></span></p>