Hawaiian Electric Company - Honolulu, HI

posted 5 months ago

Full-time - Senior
Honolulu, HI
Utilities

About the position

The Senior Information Assurance Analyst position at Hawaiian Electric Company is a critical role within the Information Assurance Department, specifically focusing on Security Architecture and Vulnerability Management. This position reports directly to the Information Assurance Manager and is designed for professionals who are not only experienced but also passionate about information security. The role involves mentoring other team members on Information Security Architecture reviews and risk and control assessments, which includes developing detailed plans and requirements for security controls and monitoring solutions for information systems. The analyst will provide consulting-level expertise in various functions of the Information Assurance department, including the development of information security policies and standards, information risk management, and ensuring compliance with both information technology (IT) and operational technology (OT) standards. Additionally, the role requires coordination of ongoing compliance reviews with Process Area representatives and the development of practices and procedures to ensure cost-effective information security and IT controls are in place. In the area of Vulnerability Management, the Senior Information Assurance Analyst will also serve as a mentor, guiding the team in program development, coordination, and reporting. This includes supporting information security risk assessments and recommending mitigating controls for IT and OT projects. The analyst will assist in managing various security and compliance programs, such as privacy, e-discovery, security awareness training, and vulnerability remediation. The position also entails supporting the review and approval processes for IT policies and procedures necessary to meet the company's compliance requirements, including Sarbanes-Oxley (SOX) and privacy regulations. Furthermore, the analyst will play a role in IT business continuity planning, disaster recovery planning, and participate in emergency response activities as assigned. The ideal candidate will possess a deep understanding of computer networking concepts, risk management processes, cybersecurity principles, and the legal landscape surrounding cybersecurity and privacy. They will be skilled in conducting vulnerability scans, assessing security systems, and utilizing various tools and techniques for penetration testing and threat detection. With a minimum of 7 years of experience in a relevant field, the candidate should also hold certifications such as CISSP, CISM, or CAP, which are highly preferred. This position not only offers a competitive salary range of $105,600 to $137,100 but also provides an opportunity to contribute to the safety and security of the Hawaiian Electric Companies, which serve a significant portion of the state's population.

Responsibilities

  • Mentor team members on Information Security Architecture reviews and risk assessments.
  • Develop detailed plans and requirements for information systems' security controls.
  • Provide consulting-level expertise in information security policies and standards.
  • Coordinate ongoing compliance reviews with Process Area representatives.
  • Assist in developing practices and procedures for cost-effective information security and IT controls.
  • Support information security risk assessments and recommend mitigating controls for IT and OT projects.
  • Manage programs for privacy, e-discovery, security awareness training, and vulnerability remediation.
  • Support the review and approval processes for IT policies and procedures.
  • Ensure compliance with Sarbanes-Oxley (SOX) and other regulatory requirements.
  • Participate in IT business continuity and disaster recovery planning.

Requirements

  • Advanced (7+ years) analysis and/or leadership experience in a multi-level service or consulting organization, preferably in IT, application security, or network security.
  • Information security experience is required.
  • Knowledge of computer networking concepts and protocols, and network security methodologies.
  • Understanding of risk management processes and cybersecurity principles.
  • Familiarity with laws, regulations, policies, and ethics related to cybersecurity and privacy.
  • Experience with cryptography and cryptographic key management concepts.
  • Knowledge of data backup and recovery concepts.
  • Experience with host/network access control mechanisms and identity management.
  • Understanding of network security architecture concepts and principles.

Nice-to-haves

  • Certified Information Systems Security Professional (CISSP) certification.
  • Certified Information Security Manager (CISM) certification.
  • Certified Authorization Professional (CAP) certification.
  • GIAC Security Leadership (GSLC) certification.

Benefits

  • Competitive compensation package
  • Opportunities for challenge and advancement
  • Support for community and educational programs
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service