> job detail
E
👽Other
Information Security Analyst Senior (The Woodlands, Texas, United States)
Entergy · The Woodlands, Texas, United States
// classified as
Other (Adjacent or hard to classify.)
posted
1d ago
location
The Woodlands, Texas, United States
languages
python
tools
aws, azure
> stack
pythonawsazure
> description
<p><span style="font-size:12.0px"><strong><span style="font-family:Arial, Helvetica, sans-serif">Job Title: </span></strong><span style="font-family:Arial, Helvetica, sans-serif">Information Security Analyst Senior</span></span></p>
<p><strong><span style="font-size:12.0px"><span style="font-family:Arial, Helvetica, sans-serif">PS Job Title: </span></span></strong><span style="font-size:12.0px"><span style="font-family:Arial, Helvetica, sans-serif">Info Sec Analyst Sr</span></span></p>
<p><span style="font-size:12.0px"><strong><span style="font-family:Arial, Helvetica, sans-serif">Work Place Flexibility:</span></strong><span style="font-family:Arial, Helvetica, sans-serif"> Hybrid </span></span></p>
<p><span style="font-size:12.0px"><strong><span style="font-family:Arial, Helvetica, sans-serif">Legal Entity:</span></strong><span style="font-family:Arial, Helvetica, sans-serif"> Entergy Services, LLC</span> </span></p><p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p>
<p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Job Summary</strong></span></p>
<p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">As a Senior Threat and Vulnerability Management (TVM) Analyst, you will design, configure, and support the TVM Team in identifying, assessing, and remediating technical vulnerabilities across a global enterprise IT and OT infrastructure. You will be responsible for executing automated scans, prioritizing risks based on business impact, and collaborating with owners to track the timely patching of assets and applications. This role offers an advanced opportunity to exercise your expertise in risk analysis and security tooling within a complex, high-scale environment. </span></p>
<p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Job Duties</strong></span></p>
<ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc">
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Scan All Assets</strong>: Run vulnerability scans across corporate networks, OT environments, web applications, APIs, and public/hybrid cloud infrastructure.</span></li>
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Audit Cloud Security</strong>: Continuous assessment of cloud workloads, identities, storage buckets, and configurations to detect security drift and misconfigurations.</span></li>
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Test Code & APIs</strong>: Perform Static (SAST) and Dynamic (DAST) application security testing, and audit API endpoints for data leakage and authentication flaws.</span></li>
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Filter Flaws</strong>: Eliminate false positives to isolate true risks threatening energy delivery systems, customer portals, and critical cloud infrastructure.</span></li>
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Assess Risk</strong>: Prioritize vulnerabilities using Threat Intelligence, CVSS scores, OWASP Top 10, OWASP API Security Top 10, and cloud-specific threat matrices.</span></li>
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Guide Remediation</strong>: Provide clear mitigation steps to IT engineers, substation OT technicians, software developers, and cloud infrastructure teams.</span></li>
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Ensure Compliance</strong>: Map vulnerability data directly to NERC CIP (including cloud-hosted BCSI requirements) and the NIST Cybersecurity Framework.</span></li>
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Report Risks</strong>: Draft executive risk reports, secure software metrics, and cloud compliance posture charts for leadership and federal regulatory auditors.</span></li>
</ul>
<p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Required Skills</strong></span></p>
<ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc">
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Industry Experience</strong>: 5+ years in cybersecurity, with a preferred 2 years protecting a large enterprise with exposure to energy, utility, or industrial environments.</span></li>
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Technical Knowledge</strong>: Strong understanding of traditional Windows and Linux enterprise deployments, SCADA networks, PLC systems, microservices architectures, REST/GraphQL APIs, Cloud Security Posture Management (CSPM), Infrastructure as Code (IaC) security, and cloud identity management (IAM).</span></li>
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Tool Proficiency</strong>: Mastery of vulnerability management tools, application security tools, and native cloud security CNAPP tools. Experience with scripting languages such as Perl or Python. Ability to leverage Artificial Intelligence (AI) to solve problems or automate work processes.</span></li>
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Regulatory Compliance</strong>: Practical knowledge of NERC CIP, NIST CSF, CIS Benchmarks, and secure coding standards.</span></li>
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Clear Communication</strong>: Ability to bridge the gap between corporate IT security, cloud architects, software developers, and field-level engineering constraints.</span></li>
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Certifications</strong>: Preferred credentials include CISSP, GICSP, GRID, CSSLP, CCSP, AWS Certified Security, or Microsoft Certified: Azure Security Engineer.</span></li>
<li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Proficiency</strong>: Capable of managing multiple tasks and meeting deadlines. Ability to work well independently or with a team. </span></li>
</ul>
<p style="margin:0.0in 0.0in 8.0pt 0.5in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p>
<p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Education required</strong></span></p>
<ul style="margin-bottom:0.0in;margin-top:0.0px">
<li style="margin:0.0in 0.0in 8.0pt 0.0px;line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent practical experience).</span></li>
</ul>
<p style="line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif;margin:0.0in 0.0in 8.0pt 0.0px"> </p>
<p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="color:white;font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span><strong>#LI-DG1 #LI-HYBRID</strong></span> </span></p><p><span style="font-size:12.0px"><span style="font-family:Arial, Helvetica, sans-serif"><strong>Primary Location:</strong> Texas-The Woodlands Louisiana : New Orleans || Arkansas : Little Rock || Mississippi : Jackson || Texas : The Woodlands</span> <br><span style="font-family:Arial, Helvetica, sans-serif"><strong>Job Function</strong>: Corporate<br><strong>FLSA Status</strong>: Professional</span> <br><span style="font-family:Arial, Helvetica, sans-serif"><strong>Relocation Option:</strong> <br><strong>Union description/code</strong>: NON BARGAINING UNIT</span> <br><span style="font-family:Arial, Helvetica, sans-serif"><strong>Number of Openings</strong>: 1<br><strong>Req ID:</strong> 124253 <br><strong>PS Job Title</strong>: Info Sec Analyst Sr <br><strong>Travel Percentage</strong>:Up to 25%</span></span></p>
<p><span style="font-size:12.0px"><span style="font-family:Arial, Helvetica, sans-serif">An Equal Opportunity Employer, Minority/Female/Disability/Vets. Please click <a href="https://jobs.entergy.com/content/EEO/?locale=en_US"><u>here</u> </a>to view the EEO page, or see statements below.</span></span></p>
<p><span style="font-size:12.0px"><strong>EEO Statement: </strong>The Entergy System of Companies provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a protected veteran in accordance with applicable federal, state and local laws. The Entergy System of Companies complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment including, but not limited to, recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. <br><br>The Entergy System of Companies expressly prohibits any form of unlawful employee harassment based on race, color, religion, sex, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status. Improper interference with the ability of the Entergy System of Company employees to perform their expected job duties is absolutely not tolerated.</span></p>
<p><span style="font-size:12.0px"><strong>Accessibility: </strong>Entergy provides reasonable accommodations for online applicants. Requests for a reasonable accommodation may be made orally or in writing by an applicant, employee, or third party on his or her behalf. If you are an individual with a disability and you are in need of an accommodation for the recruiting process please click <strong><u><a title="here" href="mailto:humanr@entergy.com?subject=Accessibility" target="_blank" rel="noopener">here</a></u></strong> and provide your name, contact number, the accommodation requested and the requisition number that you are requesting the accommodation for. Employee Services will contact you regarding your request.</span></p>
<p><span style="font-size:12.0px"><strong>Additional Responsibilities:</strong> As a provider of essential services, Entergy expects its employees to be available to work additional hours, to work in alternate locations, and/or to perform additional duties in connection with storms, outages, emergencies, or other situations as deemed necessary by the company. Exempt employees may not be paid overtime associated with such duties.</span></p>
<p><span style="font-size:12.0px"><u><strong><a title="Equal Opportunity" href="https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12ScreenRdr.pdf" target="_blank" rel="noopener">Know Your Rights: Workplace Discrimination is Illegal</a></strong></u></span></p>
<p><span style="font-size:12.0px">The non-confidential portions of the affirmative action program for individuals with disabilities and protected veterans shall be available for inspection upon request by any employee or applicant for employment. Please contact HRCompliance@entergy.com to schedule a time to review the affirmative action plan during regular office hours.</span></p>
<p><span style="font-size:12.0px"><span style="font-family:Arial, Helvetica, sans-serif"><strong>WORKING CONDITIONS: </strong><br>As a provider of essential services, Entergy expects its employees to be available to work additional hours, to work in alternate locations, and/or to perform additional duties in connection with storms, outages, emergencies, or other situations as deemed necessary by the company. Exempt employees may not be paid overtime associated with such duties.</span></span></p>
<p><span style="font-size:12.0px"><span style="font-family:Arial, Helvetica, sans-serif"><strong>Please note: </strong>Authorization to work in the United States is a precondition to employment in this position. Entergy will not sponsor candidates for work visas for this position.</span></span></p>