Job DescriptionPosition Summary:The person in this role supports the Cybersecurity Operations and Engineering team by applying operational security practices, standards, technologies, and internal NRECA processes. They will coordinate security operations activities, including implementation of effective processes and deployment of security applications and infrastructure. They will monitor critical applications and systems, investigate security events, and respond to potential malicious activity, security exploits, or data breaches.
This position is eligible for NRECA's hybrid schedule which allows flexibility to work from home up to 2 days per/week.Key Responsibilities- Monitors, triages, and investigates security tools, critical applications, and systems for suspicious activity, potential malicious behavior, security exploits, and data breaches.
- Provides backup and rotational 24/7 on-call support for security monitoring and incident response activities to meet response-time service levels and support real-time monitoring when required.
- Reviews, classifies, correlates, and analyzes security alerts and logs from SIEM platforms, servers, applications, endpoints, file systems, and network devices to identify threats and determine risk, severity, and appropriate response actions.
- Escalates and responds to security events according to risk and established response procedures.
- Configures, maintains, and tunes security monitoring, alerting, and operational security tools, including SIEM, EDR, cloud security, and other monitoring platforms.
- Deploys, tests, evaluates, and implements security solutions and infrastructure in partnership with internal technology teams, external vendors, and suppliers.
- Ability to report to the office when required
QualificationsFormal Education Required:- Bachelor's degree in cybersecurity, information technology, computer science, or a related field preferred; equivalent technical training, certifications, or 3-4 years of relevant information technology experience will also be considered
Experience and Certifications Required:- 3+ years of experience defining, implementing, and maintaining complex security infrastructure applications, including:
- Using ServiceNow IT Service Management (ITSM) or similar ticketing workflows to document, track, and resolve security-related work.
- Collaborating with internal and external stakeholders to validate detections, coordinate response actions, and support remediation efforts.
- Certifications Required: CompTIA Security+ or equivalent
Preferred Qualifications:- Certifications Preferred: GIAC Security Essentials (GSEC), GIAC Security Incident Handler (GCIH), or CompTIA CySA+ (Cybersecurity Analyst)
Salary Range: $90,000-$110,000 annual salary
Final compensation determined by individual qualifications, experience, and internal equity.
Essential Physical Requirements:
- The worker is required to have close visual acuity to perform an activity such as: preparing and analyzing data and figures; transcribing; viewing a computer terminal and extensive reading.
- Exerting up to 20 pounds of force occasionally, and/or up to 10 pounds of force frequently, and/or a negligible amount of force constantly to move objects. If the use of arm and/or leg controls requires exertion of forces greater than that for sedentary work and the worker sits most of the time, the job is rated for light work.
Disclaimer Statement
: The preceding job description has been written to reflect management's assignment of essential functions. It does not prescribe or restrict the tasks that may be assigned.