ISO New England

Senior Cyber Security Analyst - Cloud, DevSecOps & AI Security

ISO New England$127K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in cybersecurity, cloud security, or AI security roles
  • Strong understanding of AWS and/or Azure cloud platforms
  • Experience with CI/CD environments and DevSecOps practices
  • Knowledge of AI security concepts, including generative AI
  • Familiarity with container orchestration technologies like Amazon ECS and EKS
  • Expertise in vulnerability management, IAM, and security compliance
  • Excellent analytical, troubleshooting, and communication skills

Responsibilities

  • Conduct cloud security assessments for AWS and Azure environments
  • Integrate security within CI/CD pipelines and DevSecOps cultures
  • Assess and secure AI/ML systems and applications throughout their lifecycle
  • Evaluate risks associated with AI usage and third-party services
  • Implement governance controls to protect sensitive data in AI platforms
  • Develop security protocols for responsible AI usage and access controls
  • Monitor AI security risks, industry standards, and regulatory requirements

Benefits

  • A stable, mission-driven work environment
  • Inclusive and collaborative workplace culture
  • Robust benefits package supporting professional development
  • Enhanced 401(k) with financial planning support
  • Flexible scheduling and remote work options
  • Wellness programs, including gym access
  • Relocation assistance for non-local candidates
Full Job Description
ISO New England is seeking an experienced Cyber Security Analyst to support and enhance enterprise cloud, infrastructure, AI, and DevSecOps security initiatives. This role is responsible for proactively identifying vulnerabilities, compliance gaps, misconfigurations, and security risks across enterprise systems, cloud platforms, AI/ML environments, CI/CD pipelines, and regulated CIP environments. The ideal candidate will have strong experience in cloud security, vulnerability management, DevSecOps, AI security, and security compliance, with the ability to collaborate across technical teams to implement and maintain enterprise security standards. What we offer you: • A stable, mission-driven workplace where your impact truly matters • A highly engaged work environment that values inclusion, collaboration, and employee safety and wellbeing • Competitive compensation with a base salary + performance bonus • Robust benefits package, including: • Enhanced 401(k) and financial planning support • Tuition reimbursement and professional development • Wellness programs, including an onsite gym • Flexible work hours • Employee Business Networks • Free coffee at our onsite café • Hybrid work environment (3 days/week onsite) • Distance-based relocation assistance available • 5/6 person paid on-call rotation How you will make an Impact • Conduct cloud security assessments across AWS and Azure environments, including CSPM, CIEM, IAM, and container security reviews. • Integrate and support security controls within CI/CD pipelines and DevSecOps environments. • Assess and secure AI/ML systems, generative AI applications, and AI-enabled business solutions throughout their lifecycle. • Evaluate risks associated with AI model usage, training data, third-party AI services, and Large Language Model (LLM) integrations. • Implement AI governance controls to protect sensitive data and prevent unauthorized disclosure through AI platforms. • Develop security guardrails for AI adoption, including data classification, access controls, prompt security, and responsible AI usage. • Perform AI threat modeling to identify risks such as prompt injection, data poisoning, model manipulation, model theft, and insecure AI integrations. • Perform vulnerability assessments, configuration reviews, and remediation tracking across enterprise and CIP systems. • Review and validate baseline configurations, logging requirements, and compliance controls. • Evaluate network topology and infrastructure changes to determine CIP impact and SOC visibility requirements. • Partner with application development, cloud platform engineering, infrastructure, enterprise architecture, IAM, network, SOC, and business teams to integrate security into system design, projects, and operational processes. • Support phishing simulations, security awareness initiatives, AI security awareness training, and audit evidence collection. • Provide security recommendations and risk mitigation strategies for cloud, AI, and enterprise environments. • Support and maintain enterprise security platforms including CNAPP, EDR, vulnerability management, SIEM, DSPM, and cloud security monitoring tools. • Monitor evolving AI security risks, industry standards, and regulatory requirements. What we are looking for • Experience in cybersecurity, cloud security, security engineering, or AI security roles. • Experience with AWS and/or Azure cloud platforms. • Experience with container orchestration technologies including Amazon ECS and Amazon EKS. • Experience implementing security controls within CI/CD and DevSecOps environments. • Knowledge of AI security concepts, including securing generative AI applications, LLMs, AI governance, and AI risk management. • Familiarity with AI threats such as prompt injection, data leakage, model poisoning, model theft, and insecure AI APIs. • Knowledge of vulnerability management, cloud security, IAM, CSPM, and configuration management practices. • Experience with security monitoring and logging platforms. • Familiarity with Terraform, infrastructure-as-code, and policy governance frameworks such as OPA. • Understanding of data governance, data protection, and responsible AI principles. • Strong analytical, troubleshooting, communication, and collaboration skills. • Self-starter with the ability to work independently in a fast-paced environment. Desired not required • Bachelor's degree in information technology, Cybersecurity, Computer Science, or related field. • Advanced degree such as a Master's in Cybersecurity Management, Information Assurance, Artificial Intelligence, or related fields. • Industry cybersecurity, cloud security, and AI security certifications preferred, including: • ISC2 Certified Information Systems Security Professional (CISSP) • ISACA Certified Information Security Manager (CISM) • Amazon Web Services Certified Security - Specialty • Microsoft Azure Security Engineer Associate (AZ-500) • ISC2 Certified in AI Security (when available) • OWASP AI Security and LLM Security knowledge/training This employer will not sponsor applicants for work visas for this position (ex: H-1B, F-1/CPT/OPT, O-1, E-3, TN, J, etc.). The expected salary range for this position is $127,000 - $150,000per year. This role is also eligible for an annual performance bonus, comprehensive health insurance (medical, dental and vision), flexible spending and health savings accounts, a 401(k) plan with generous employer contributions and a student debt benefit, life and AD&D insurance, disability insurance, critical illness and hospital indemnity benefits, paid time off, paid leave, a wellness program, an employee assistance program and other great company perks. #LI-HYBRID This is a U.S. based role. If the successful candidate resides outside of the U.S., relocation will be required.

About ISO New England

ISO New England Inc. is an independent, non-profit Regional Transmission Organization, headquartered in Holyoke, Massachusetts, serving Connecticut, Maine, Massachusetts, New Hampshire, Rhode Island, and Vermont. ISO-NE oversees the operation of New England's bulk electric power system and transmission lines, generated and transmitted by its member utilities, as well as Hydro-Québec, NB Power, the New York Power Authority and utilities in New York state, when the need arises. ISO-NE is responsible for reliably operating New England's 32,000 megawatt bulk electric power generation and transmission system. One of its major duties is to provide tariffs for the prices, terms, and conditions of the energy supply in New England. ISO New England's stated mission is to protect the health of New England's economy and the well-being of its people by ensuring the constant availability of electricity, today and for future generations. ISO New England ensures the day-to-day reliable operation of New England's bulk power generation and transmission system, oversees the administration of the region's wholesale electricity markets, and manages the regional planning processes. ISO-NE was created in 1997 by the Federal Energy Regulatory Commission, as a replacement for the New England Power Pool, which was created in 1971. The ISO-NE grid does not extend to remote parts of eastern and northern Maine in Washington and Aroostook Counties. In these areas, residents receive their electricity from Canadian providers such as NB Power and Hydro-Québec.
Learn more about ISO New England
Industry
Founded
1997

Similar Jobs

More Jobs at ISO New England

More Information Technology Jobs

Find similar Senior Cyber Security Analyst - Cloud, DevSecOps & AI Security jobs: