Senior Analyst, Cyber Security - (26-IT-601015-087)

DC Water

• $95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in Information Systems
  • Strong understanding of cybersecurity functions and risk mitigation
  • Proficient in programming or scripting languages (PowerShell, Python, etc.)
  • Intermediate knowledge of MITRE ATT&CK framework
  • Advanced understanding of system and network logging events
  • Familiarity with NIST 800-53 control families

Responsibilities

  • Support the Director in addressing cyber risks
  • Monitor SOC operations for cyber incidents
  • Analyze security events and investigate root causes
  • Deploy and maintain software to manage network defenses
  • Assist in disaster recovery and business continuity efforts
  • Conduct vulnerability testing on IT and OT systems
  • Generate security metrics and reports for executive visibility

Benefits

  • Hybrid work format
  • Opportunity for continuous learning and training
  • Collaboration with industry-leading professionals
  • Access to advanced cybersecurity tools and technologies
  • Regular assessment and enhancement of cybersecurity capabilities
Full Job Description
Job Description

The intent of this job description is to provide a representative summary of the major duties, locations, and responsibilities performed by incumbent(s) in this job. Incumbent(s) may not be required to perform all duties in this description, and incumbent(s) may be required to perform work-related tasks other than those specifically listed in this description. This job description is not a "contract" between the employee and the Authority. The job duties and essential functions may be changed at the discretion of the General Manager.

General

Job Title:Senior Analyst, Cyber Security Job Code:P0548Supervises Directly:NoNew or Revised:RevisedRegular or At-Will:At-WillDate Last Revised:9/10/2026Exempt or Non-Exempt:ExemptCompensation Approval Signature: Union/ Non-Union:Non-Union

Division:

Department:

Information Technology

IT-Information Security
Salary Schedule: Non-Union Salary RangeCost Center Code: 601015Grade:NU17Essential Position:NoReports To:Manager, Cyber Security OperationsEEO Code:ProfessionalsWork Format:Hybrid

Role Description:
The Senior Analyst, Cyber Security is responsible for the administration of deployed cyber control technologies and is part of the Security Operation Center (SOC) which monitors, analyzes, detects, and responds to cyber incidents on both traditional Information Technology (IT) and Operational Technology (OT) networks. This position partners with IT and OT teams to administer and monitor access to DC Water resources. Responsibilities include monitoring security vulnerabilities and threats, collecting and evaluating threat intelligence, supporting disaster recovery and business continuity efforts, and assisting with the implementation and enhancement of cyber controls informed by third-party intelligence sources. The role also maintains accountability for identifying and tracking IT assets that support DC Water's business processes.

Essential Duties & Responsibilities:
  • Supports the Director, Cyber Security Services in ensuring DC Water's preparedness to address cyber risks.
  • Maintains user access controls for computing resources.


  • Monitors SOC operations to detect, analyze, and respond to cyber incidents, including intrusion attempts, malware infections, and other security threats across IT and OT networks.


  • Analyzes security events and incidents within the DC Water computing and network environment, investigates root causes, assesses impacts, and coordinates and documents response actions to mitigate risks and minimize operational disruptions.


  • Tests, implements, deploys, maintains, reviews, and administers the infrastructure software required to effectively manage DC Water's network defenses and resources.
  • Monitors DC Water's network to actively remediate unauthorized activities.


  • Assists in disaster recovery operations using preparation, identification, mitigation, remediation, and recovery approaches, as needed to maximize business resilience and information security.


  • Collaborates with the Director, Cyber Security Services to incorporate threat intelligence obtained from third-party providers into cyber controls, enhancing DC Water's ability to proactively identify and mitigate emerging threats.


  • Conducts and reports outcomes of vulnerability and penetration testing on IT and OT systems; identifies and prioritizes vulnerabilities for remediation to reduce the risk of exploitation by malicious actors.


  • Uses advanced threat hunting techniques and tools to identify and neutralize threats before they escalate.


  • Documents security incidents, investigations, and response activities in accordance with established procedures; ensures accurate and thorough reporting for compliance, audit, and legal purposes.


  • Determines deviations from acceptable configuration, vendor, or IT policy.


  • Generates security metrics, dashboards, and reports to provide visibility into key cybersecurity performance indicators, trends, and emerging risks for the senior executive team.


  • Oversees the receipt and distribution of IT assets owned, leased, or subleased by DC Water to IT and OT, including creation and maintenance of supporting documentation to manage the acquisition and disposal of IT assets.


  • Continuously assesses and improves DC Water's cybersecurity capabilities, processes, and procedures, leveraging lessons learned, industry best practices, and emerging technologies to enhance overall cyber resilience and readiness.


  • Performs other related duties as assigned at the discretion of the immediate supervisor.


Supervisory Responsibilities: N/A

Key Working Relationships: Works with the Information Technology Solution Center (ITSC) and Infrastructure teams to enable the delivery and disposal of computing and network assets. Maintains and manages Role-Based Access to the Information Technology Asset Management Database. Partners with internal stakeholders to understand and logically document current and future processes.

Skills & Qualifications:
The qualifications listed below are representative of the knowledge, skill, and ability necessary for an individual to perform each essential responsibility satisfactorily. Reasonable amounts of training are provided.

Required Skills & Qualifications
Required Experience:Five (5) years of experience in Information Systems.Strong understanding of the key functions of cybersecurity, cyber risk mitigation strategies, and event and incident flows within a Security Event and Incident (SEIM) system.Ability to define the problem, generate and select alternatives, and implement solutions.Intermediate understanding of MITRE and Adversarial Tactics, Techniques and Common Knowledge (ATT&CK) framework for Information Technology and Operational Technology Networks.Strong understanding of one or more computer programming and/or scripting languages (PowerShell, KQL, Python, etc.).Intermediate understanding of network ports, protocols, and services, host and network-based Intrusion Prevention Systems (IPS).Advanced understanding of system and network logging events.Familiarity with the National Institute of Standards and Technology NIST 800-53 Control Families and the NIST Cyber Incident Response steps.Minimum Education Requirements:A Bachelor's degree in Information Systems, Computer Science, or a related technical field from an accredited college or university.Required Skills:Cybersecurity Tools & TechnologiesInformation SecurityAccess ControlIncident ResponseAdaptable & AgileAttention to DetailAnalytical & Problem-Solving SkillsTeamworkCommunication SkillsRequired Licenses & Certifications:NoneRequired Languages: English Physical Requirements: General Office Conditions

Preferred Skills & Qualifications
Preferred Experience:Experience in cybersecurity incident response and network security monitoring and must be proficient in using technology tools such as CheckPoint, Azure, Microsoft Entra, Defender, and Purview. Preferred Education Requirements:Master's degree in cybersecurity, information technology security, computer engineering, computer information systems, computer science or related field from an accredited college or university.Preferred Skills:Cyber Threat IntelligenceVulnerability AssessmentCyber Risk Analysis & MitigationContinuous MonitoringEmerging Trends in CybersecurityBusiness AlignmentEnterprise Security MessagingKPI/KPR Validation and OversightSecurity Compliance ReportingTraining Design and DevelopmentPreferred Licenses & Certifications:Certifications in cybersecurity, such as a CompTIA Security+, GIAC Certifications, or similar.

*The work environment characteristics described in the physical requirements section of the required skills & qualifications table are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential responsibilities.

Similar Jobs

More Jobs at DC Water

More Information Technology Jobs

Find similar Senior Analyst, Cyber Security - (26-IT-601015-087) jobs: