Senior Cyber Security Vulnerability Analyst
Bethpage, NY, US
Full Time Senior-level / Expert USD 101K - 160K
Requisition: 81048
PSEG Company: PSEG Long Island
Salary Range: $ 101,600 - $ 160,900
Work Location Category: Hybrid Flexible
PSEG operates under a Flexible Work Model where flexible work is offered when job requirements allow. In support of this model, roles have been categorized into one of four work location categories:
Onsite are roles that have specific onsite requirements and are typically onsite daily.
Hybrid fixed are roles that are a blend of onsite work/in-person interactions with some ability to work remotely and require employees to live within a commutable distance and be onsite fixed days each week.
Hybrid flexible are roles that can be performed remotely but require some level of onsite work/in-person interactions on a regular basis, require employees to live within a commutable distance and, since business needs vary by position and may change over time, managers will set expectations and flexibility regarding where and when work is performed.
Fully remote are roles that can be performed remotely, require employees to live in approved states and will have purpose-driven in-person interactions on occasion.
We want you to be healthy, balanced, and feel secure. That’s why you’ll enjoy a comprehensive range of benefits, with a focus on supporting your whole health. Starting on day one of your employment, you’ll be offered several health-related benefits including medical, vision, dental, well-being and behavioral health programs. We also offer a retirement program, 401(k) with company match, company paid life insurance, tuition reimbursement and a minimum of 18 days of paid time off per year (including vacation, scheduled holidays, and floating holidays).
PSEG offers a unique experience to our more than 12,000 employees – we provide the resources and opportunities for career development that come with being a Fortune 500 company, as well as the attention, camaraderie, and care for one another you might typically associate with a small business. Our focus on combatting climate change through clean energy technology, our new net zero climate vision for 2030 and enhanced commitment to diversity, equity, and inclusion; and supporting the communities we serve make this a particularly exciting time to join PSEG.
Job Summary
This position is an experienced, senior level, hands-on technical lead, performing IT security functions and maintaining systems, while providing technical guidance to the team. Ensures the implementation of robust security measures to protect organization communications and control networks, reducing the risk of unauthorized access and cyber threats. Implements and maintain effective measures to prevent data leaks, safeguarding sensitive information and ensuring compliance with data protection policies and regulations.
Job Responsibilities
Include but are not limited to:
•Performing vulnerability and compliance management activities, while providing technical guidance to the team.
•Operates vulnerability, compliance, and pen testing tools, and complies with security policies and procedures (T0028)
•Support incident response activities as needed. (T0041)
•Provides technical expertise and support to IT management and staff in cybersecurity threat risk assessments, development, testing and the implementation and operation of appropriate information security plans, procedures, and control techniques designed to prevent, minimize or quickly recover from cyber-attacks or other serious events.
•Evaluate the severity and potential impact of identified vulnerabilities aligned to PSEG’s risk tolerance and business priorities.
•Coordinate and oversee the patching process to ensure timelines align to the defined cadences.
•Develop and present key security reports on the status of vulnerabilities, risk assessments, and mitigation efforts to various security stakeholders and PSEG leadership.
Job Specific Qualifications
Required
- Bachelor's degree in Computer Science, Information Systems, Cyber Security, or Engineering
- In lieu of a degree, 10 years of cyber experience
- 6 or more years of experience in Information Security Proficient with vulnerability management solutions such as Qualys, Nexpose, Nessus, Kenna Security, Tanium and open source
- Experience leading and managing organization-wide vulnerability scanning and remediation processes.
- Understanding of OWASP, CVSS, the MITRE ATT&CK framework and the software development lifecycle.
- Experience with key information security technologies such as SIEM, firewalls, intrusion detection/prevention systems, vulnerability assessment, encryption, identity and access control systems, anti-malware, and security event analysis.
- Travel approximate 5%
Minimum Years of Experience
6 years of experienceEducation
Certifications
None NotedDisclaimer
Certain positions at the Company may require you to have access to Part 810-Controlled Information. Under the law, the Company is limited in who it can share this information with and in certain circumstances it is necessary to obtain specific authorization before the Company can share this information. Accordingly, if the position does require access to this information, you must complete a 10 CFR Part 810 Export Control Compliance Nationality Request Form, a copy of which will be provided to you by Talent Acquisition if an offer is made. If there is a need for specific authorization, due to the time it takes to obtain authorization from the government, we will likely not be able to further proceed with an offer.
If you are a current PSEG employee and if you are offered an opportunity with PSEG Long Island, you will be treated as a new hire. Please note that as a new hire to the Long Island subsidiary, your benefits will change and generally will be consistent with other similarly situated PSEG Long Island new hires. Similarly, for PSEG Long Island employees who accept job opportunities with PSEG or any of its subsidiaries (other than PSEG Long Island), their benefits would change and generally be consistent with other similarly situated new hires of that company.
As an employee of PSE&G or PSEG LI, you should be aware that during storm restoration efforts, you may be required to perform functions outside of your routine duties and on a schedule that may be different from normal operations.
For all roles, PSEG’s drug and alcohol testing program includes pre-employment testing, testing for cause, and post-incident/accident testing. For employees in federally regulated roles (including positions covered by USDOT, PHMSA, or NRC regulations), this also includes random testing. Although numerous states throughout the country have legalized marijuana/cannabis products recreationally and/or medically, it is prohibited for employees in federally regulated roles. Employees who are hired or transfer into a federally regulated role are subject to drug and alcohol testing, inclusive of marijuana. Please note that the use of CBD products may result in a positive drug test for THC/Marijuana and such use is not a legitimate medical explanation for such a positive result.
PSEG is an equal opportunity employer, dedicated to a policy of non-discrimination in employment, including the hiring process, based on any legally protected characteristic. Legally protected characteristics include race, color, religion, national origin, sex, age, marital status, sexual orientation, disability or veteran status or any other characteristic protected by federal, state, or local law in locations where PSEG employs individuals.
PSEG is committed to providing reasonable accommodations to individuals with disabilities. If you have a disability and need assistance applying for a position, please call 973-430-3845 or email accommodations@pseg.com.
If you need to request a reasonable accommodation to perform the essential functions of the job, email accommodations@pseg.com. Any information provided regarding a disability will be kept strictly confidential and will not be shared with anyone involved in making a hiring decision.
ADDITIONAL EEO/AA INFORMATION (Click link below)
Know your Rights: Workplace Discrimination is Illegal
Pay Transparency Nondiscrimination Provision
Tags: Compliance Computer Science CVSS Encryption Firewalls Incident response Intrusion detection Malware MITRE ATT&CK Nessus Open Source OWASP Pentesting Qualys Risk assessment SDLC SIEM Vulnerabilities Vulnerability management
Perks/benefits: 401(k) matching Career development Equity / stock options Flex hours Flex vacation Health care Insurance Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.