Advisor IT Security Analyst or below DOE #17679
Job Field: Office Jobs
Location: BELLEVUE, WA
Salary: $-
Job Type: Part Time
JOB SUMMARY:
</tr>
</table>
<table border="0" bgColor="#F5F5F5" cellpadding="5" cellspacing="0" style="border-collapse: collapse" width="100%">
<tr>
<td align="left"><font style="font-size: 100%;">PSE is looking for two IT Security Analysts at the Advisor level or below, depending on experience, to develop, deliver, maintain or monitor IT security policies, standards, and best practices. These roles will be looked upon to implement, integrate, maintain, report on or monitor security and compliance risk management procedures to reduce financial loss and critical business services and to provide subject matter expertise to departments on issues of Information Security and compliance. The IT Security Analysts will primarily support PSE compliance with NERC CIP standards. Specific responsibilities include supporting NERC CIP audits (every 3 years); reviewing and suggesting improvements to NERC CIP related IT processes; annual NERC CIP self certifications; creating and/or maintaining NERC Reliability Standard Audit Worksheets (RSAWs); collecting and reviewing compliance documentation; drafting, submitting and maintaining NERC Technical Feasibility Exceptions (TFEs); assisting with potential self report investigations; and preparing for the implementation of version 5 of the NERC CIP standards. <BR><BR>These roles may also be expected to perform security, vulnerability and threat assessments; participate in security incident management or response; manage user identities and access; help coordinate the development of disaster recovery plans and testing; provide technical guidance and training; and design and implement programs for user awareness. These positions may also support the review of and compliance with SOX key controls.<BR><BR>MINIMUM QUALIFICATIONS<BR>• Bachelor’s degree and 5-8 years of experience or combination of specialized training/experience and 5-8 years of directly relevant experience.<BR>• Technical proficiency in security-related hardware and software; ability to function as a consultant to other IT groups on security matters as a recognized technical expert and to lead teams<BR>• Knowledge of security controls for mainframe, midrange, PCs, laptops<BR>• Understanding of various operating environments, e.g. MVS, Unix, Windows NT, Linux, Novell, Cisco IOS, Solaris, Open VMS, AIX. <BR>• Hands-on knowledge of working with network routers, LAN bridges, and the communication architectures that link them together (e.g. LAN's, WAN's ISDN, PSTN, FDDI, ATIVI, Frame Relay, X.25, X.400, Internet). <BR>• Understanding of security 'firewall' gateways and their designs, configuration and management, including appreciation of the value of computer and firewall audit logs, automated compliance checkers and break-in detection and evasion utilities. <BR>• Knowledge of security frameworks such as: ISO 27001, NIST 800-53, COBIT and COSO<BR>• Experience with implementation and management of compliance requirements such as NERC and SOX<BR>• Understanding and experience with other security products and techniques such as token-based dialup authentication, modem callback and password management is desirable<BR>• Ability to effectively adapt to and apply rapidly changing technology to business needs<BR>• Strong knowledge and understanding of business needs, with the ability to establish and maintain a high level of customer trust and confidence<BR>• Proven ability to work under stress in emergencies; flexibility to handle pressure coming from all directions at one time<BR>• Strong analytical and problem-solving skills<BR>• Strong customer focus and ability to manage client expectations</font></td>
</tr>
</table>
<table border="0" bgColor="#F5F5F5" cellpadding="0" cellspacing="0" style="border-collapse: collapse" width="100%">
<tr>