FuelCell Energy Inc

Cyber Security Analyst

FuelCell Energy Inc • $95K — $110K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in IT, cybersecurity, computer science, or related field; extensive experience may substitute for degree.
  • Certifications such as CompTIA Security+, CySA+, GIAC (GSEC/GCIH), or Microsoft Security (SC-200).
  • 3-5 years of experience in cybersecurity or IT with a security focus, covering both IT and OT environments.
  • Demonstrable knowledge in security monitoring, incident response, and alert triage across various platforms.
  • Experience in running security awareness and phishing programs, including campaign design and metrics.

Responsibilities

  • Monitor security tools and logs to detect and respond to potential threats.
  • Investigate security incidents, documenting findings and lessons learned.
  • Perform vulnerability management, coordinating remediation with IT teams.
  • Support identity and access management controls, enforcing least-privilege access.
  • Contribute to the organization's security architecture and standards.
  • Maintain and tune security controls and tooling, ensuring effectiveness.
  • Assist with compliance activities related to frameworks like NIST CSF and SOX.

Benefits

  • Comprehensive medical, dental, and vision insurance.
  • Company-paid life and disability insurance.
  • 401(k) plan with company match.
  • Employee stock purchase plan.
  • Generous paid leave policy.
Full Job Description
Overview

We are currently seeking a motivated and experienced Cyber Security Analyst to join our Global Infrastructure team to help protect FuelCell Energy's people, data, and systems across corporate, manufacturing, and operational (OT) environments. Reporting to the Senior Director, Infrastructure, Cybersecurity & AI, this hands-on analyst monitors for threats, hunts for emerging risks, responds to incidents, and strengthens the organization's security posture. This is a hybrid position based in Danbury, CT, with onsite presence critical to collaborate with cross-functional teams, support operational systems, and ensure the security and resilience of our infrastructure.

The Cyber Security Analyst combines technical security skills with strong judgment and clear communication. Core areas of focus include tuning firewall rules and security tooling to industry best practices, proactive threat hunting, and leading the company's security awareness and phishing program-running simulated phishing campaigns, educating employees, and reducing human risk-while partnering with IT and business stakeholders to detect, respond to, and prevent security threats.

Responsibilities:
  • Monitor security tools, alerts, and logs across endpoints, network, cloud (Azure), email, and identity to detect, triage, and respond to potential threats.
  • Investigate and respond to security incidents, including containment, eradication, and recovery, and document findings, root causes, and lessons learned.
  • Perform vulnerability management activities, including scanning, prioritization, tracking, and coordinating remediation with IT and infrastructure teams.
  • Support identity and access management controls, including access reviews, least-privilege enforcement, and multi-factor authentication.
  • Contribute to the company's overall information systems and security architecture strategy, standards, and design.
  • Maintain and tune security controls and tooling, such as endpoint detection and response (EDR), email security, SIEM, and cloud security tools.
  • Assist with security compliance activities and control evidence in support of frameworks such as NIST CSF, IEC 62443, and SOX.
  • Develop and maintain security documentation, including procedures, playbooks, and reporting for technical and non-technical audiences.
  • Provide guidance and second-level support to IT and end users on security issues, safe practices, and incident reporting.
  • Track the evolving threat landscape and recommend improvements to controls, processes, and awareness efforts.

Firewall, Tooling & Threat Management:
  • Tune firewall rules and policies in alignment with security best practices, removing unnecessary or risky rules and enforcing least-privilege network access.
  • Continuously monitor firewalls and network security events, and take timely action to investigate, contain, and mitigate relevant risks.
  • Tune and optimize existing security toolsets to industry best practices and in alignment with NIST CSF, improving detection, coverage, and signal quality.
  • Maintain the organization's security tool sets and become a subject matter expert (SME) across each, ensuring they are healthy, current, and effective.
  • Regularly review and update security tools as new features, capabilities, and risks emerge, and recommend enhancements or replacements where appropriate.
  • Perform proactive threat hunting across endpoints, network, cloud, and identity to identify indicators of compromise and emerging threats before they cause impact.
  • Use threat hunting and monitoring findings to strengthen controls, tune detections, and reduce the organization's attack surface over time.

Security Awareness & Phishing Program:
  • Design, run, and continuously improve simulated phishing campaigns across the organization, using realistic scenarios that reflect current attacker techniques.
  • Analyze simulation results, track click and report rates, identify high-risk users and departments, and target follow-up education where it is needed most.
  • Develop and deliver phishing and security awareness education, including training content, tips, and just-in-time coaching that changes user behavior and reduces human risk.
  • Manage the response and remediation process for repeat offenders, coordinating additional training and appropriate follow-up actions with IT and leadership.
  • Promote a strong security culture through ongoing communication, awareness campaigns, and clear guidance on how employees can recognize and report threats.
  • Investigate real reported phishing emails, contain and remediate malicious messages, and use lessons learned to strengthen both technical controls and user education.
  • Report on program effectiveness-awareness metrics, phishing trends, and improvements over time-to IT leadership and business stakeholders.

Qualifications:

Education: Bachelor's degree in information technology, cybersecurity, computer science, or a related discipline. Extensive experience will be considered in lieu of a degree.
  • Certifications: CompTIA Security+, CySA+, GIAC (GSEC/GCIH), Microsoft Security (SC-200), or similar.

Experience:
  • Three to five years of experience in cybersecurity, security operations, or IT with a security focus, spanning IT and OT environments.

Candidate must have demonstrable knowledge/experience in:
  • Security monitoring, alert triage, and incident response across endpoints, network, cloud, email, and identity.
  • Running security awareness and simulated phishing programs, including campaign design, metrics, and follow-up education.
  • Tuning firewall rules and policies to best practices, and monitoring firewalls to detect and mitigate risks.
  • Proactive threat hunting to identify indicators of compromise and emerging threats.
  • Tuning, maintaining, and serving as an SME for security tool sets, aligned to NIST CSF and industry best practices.
  • Vulnerability management, including scanning, prioritization, and coordinating remediation.
  • Security tooling such as EDR, SIEM, email security, and cloud security (ESET Protect, Microsoft Defender, or similar).
  • Identity and access management concepts, including least privilege, access reviews, and multi-factor authentication.
  • Common attacker techniques, phishing and social engineering, and how to detect, contain, and prevent them.
  • Security standards and frameworks, such as NIST CSF and IEC 62443, and how they influence security controls and processes.
  • Excellent communication skills with the ability to create clear documentation and communicate security concepts to non-technical stakeholders.
  • Strong problem-solving skills, attention to detail, and sound judgment under pressure.

Physical Requirements/Working Conditions:
  • Work is performed in office, manufacturing, and warehouse environments and involves the use of a computer and other office equipment.
  • Ability to wear required personal protective equipment (PPE), including safety glasses, safety shoes, hard hats, and other PPE as designated.
  • Ability to access systems and equipment in office, manufacturing, and data center areas as required.
  • Occasional travel to company locations and availability outside of core business hours to respond to security incidents may be required.


We offer a competitive compensation package as well as comprehensive benefits including medical, dental, vision, company-paid life/disability insurance, 401(k) plan, employee stock purchase plan, and generous paid leave.

#LI-AD1

#LI-hybrid

About FuelCell Energy Inc

FuelCell Energy, Inc. designs, manufactures, sells, installs, operates, and services stationary fuel cell power plants for distributed power generation. The company offers SureSource product line based on carbonate fuel cell technology in various configurations, including on-site power, utility grid support, distributed hydrogen, and micro-grid, as well as multi-megawatt applications; and SureSource Recovery power plants for natural gas pipeline applications. It also provides SureSource Capture system that separates carbon dioxide from the flue gases of natural gas, biomass, or coal-fired power plants, as well as industrial facilities; and SOFC/SOEC and Energy Storage, a solution for energy storage using solid oxide technology. The company's SureSource power plants generate electricity and usable heat, and provide hydrogen and/or drinking water. It serves various markets, such as utilities and independent power producers, industrial and process applications, education and health care, data centers and communication, wastewater treatment, government, and commercial and hospitality. The company primarily operates in the United States, South Korea, England, Germany, Canada, and Spain. FuelCell Energy, Inc. was founded in 1969 and is headquartered in Danbury, Connecticut.
Learn more about FuelCell Energy Inc
Size
382 employees
Market Cap
$1 billion
Industry
Net Income
-$89.1 million
Founded
1969
5 Year Trend
+6.4%
Revenue
$70.8 million
NASDAQ

Similar Jobs

More Jobs at FuelCell Energy Inc

More Information Technology Jobs

Find similar Cyber Security Analyst jobs: