Information Security Analyst I-Sr

PNM Resources
Albuquerque, NM, United States
$109.3K a year
Full-time
We are sorry. The job offer you are looking for is no longer available.

POSTING DEADLINE

This position is posted until filled.

DEPARTMENT

Department : Information Security

JOB DESCRIPTION

Sr. Information Security Analyst

Salary Grade : G06

Minimum Midpoint Maximum

$74,796 - $100,975 - $127,152

Personnel in this job title may be covered by NERC CIP cyber security standards. If the position is covered, prior to being hired, promoted, or transferred into the position, the candidate must successfully pass a Personnel Risk Assessment, which includes identity verification and a criminal background check.

Prior to being granted unescorted access to cyber secure areas, the candidate must attend cyber security training. Annual cyber security training is also required.

SUMMARY :

Acts as an IT security subject matter expert and technical consultant for security initiatives. Functions as technical engineer, system architect and operational support for the Identity Management (IDM) suite of products.

Analyzes the security of systems and applications, and develops security baselines to protect information against unauthorized access.

Conducts forensic investigations including investigations done in coordination with other departments.

ESSENTIAL DUTIES AND RESPONSIBILITIES :

Assesses, designs, and recommends security access requirements for systems and applications; creates ad hoc reports for review

Collaborates with enterprise architecture on the development of system and application security standards and baselines

Provisions electronic access for supported systems and applications in accordance with the Enterprise Access Provisioning Program

Ensures all access issues are handled in a timely manner and that supported systems are functioning properly

Creates, modifies and deletes profiles and other access controls as part of Role Based Access Control (RBAC) program

Provides routine reaccreditation of existing users and associated entitlements

Produces evidence in support of Company policies and regulatory requirements, such as Sarbanes-Oxley (SOX) and North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP)

Participates in projects as a subject matter expert in support of business initiatives; ensures project work is completed in a timely manner in accordance with Information Security policies, programs and standards;

oversees and continuously improves the Enterprise Access Provisioning Program

Performs user access reviews supporting Company investigation needs; assists with data preservation requests for litigation holds;

conducts digital forensics in support of the Information Security program

Ensures teamwork to reduce security exposures

COMPETENCIES :

Strong knowledge of Company business practices and familiarity with Company products and services

Strong knowledge of digital forensic steps and incident response

Ability to develop and make recommendations for complex security processes, procedure improvements and management level security standards

Ability to identify best practices for security risk assessments, policies, standards and processes

Extensive policy, process, and standard development experience

Ability to demonstrate leadership skills and provide guidance to less experienced team members

QUALIFICATIONS

MINIMUM EDUCATION AND / OR EXPERIENCE :

Bachelors degree from a four-year college or university in Information Resource Management, Business Computer Systems, Computer Science or Computer Security with five to seven years related experience, or equivalent combination of education and / or experience related to the discipline.

COMMUNICATION SKILLS :

Ability to maintain positive and productive working relationships with various individuals and groups

Ability to recognize and initiate complex tasks without direction

Ability to read and interpret technical manuals and reports, instructional documents, and procedure manuals

Ability to write procedural documentation and user instructions

Ability to speak effectively with various individuals, groups, and vendors

MATHEMATICAL SKILLS :

Ability to calculate figures and amounts such as discounts, interest, commissions, proportions, percentages, area, circumference, and volume

Ability to apply concepts of basic algebra and geometry

COMPUTER SKILLS :

In-depth knowledge and experience with Linux / UNIX servers, client & server applications and information security issues

In-depth knowledge of Microsoft, Linux and UNIX server security functionality

In-depth knowledge of related security software

In-depth knowledge of database product security technology, specifically Oracle and SQL, and general knowledge of physical security methods

ANALYSIS AND PROBLEM-SOLVING ABILITY :

Ability to understand and assimilate complex technical information. Ability to solve partial problems and deal with a variety of concrete variables in situations where only limited standardization exists.

Ability to interpret a variety of instructions furnished in written, oral, diagram or schedule form.

DECISION MAKING :

Ability to make access management and provisioning decisions without direction, in accordance with Company policies, procedures and programs.

Examines potential areas for service improvement and makes recommendations for changes to senior staff or management.

PHYSICAL DEMANDS :

While performing the duties of this job, the employee is regularly required to sit up to 2 / 3 of the time and talk and listen for long periods of time.

WORK ENVIRONMENT : Office environment.

Office environment.

JOB DESCRIPTION

Information Security Analyst I

Salary Grade : G07

Minimum Midpoint Maximum

$66,267 - $87,804 - $109,340

Personnel in this job title may be covered by NERC CIP cyber security standards. If the position is covered, prior to being hired, promoted, or transferred into the position, the candidate must successfully pass a Personnel Risk Assessment, which includes identity verification and a criminal background check.

Prior to being granted unescorted access to cyber secure areas, the candidate must attend cyber security training. Annual cyber security training is also required.

SUMMARY :

Under general supervision, provisions electronic access to systems and applications. Acts as an IT security subject matter expert for supported systems and applications.

Responsible for Identity and Access Management (IAM), access management, provisioning and compliance controls relating to managing access based on business need.

Analyzes the security of systems and applications, and develops security baselines to protect information against unauthorized access.

ESSENTIAL DUTIES AND RESPONSIBILITIES :

Provisions electronic access for supported systems and applications in accordance with Access Management and Provisioning program

Ensures all access issues are handled in a timely manner and that supported systems are functioning properly

Creates, modifies and deletes profiles and other access controls as part of Role Based Access Control (RBAC) program

Provides routine reaccreditation of existing users and associated entitlements

Produces evidence in support of Company policies and regulatory requirements, such as Sarbanes-Oxley (SOX) and North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP)

Recommends security access requirements for systems and applications; creates ad hoc reports for review

Participates in major projects, as needed, in support of business initiatives; ensures project work is completed in a timely manner in accordance with Information Security policies, programs and standards;

contributes and recommends improvements to the Access Management and Provisioning program

Performs user access reviews supporting Company investigation needs; assists with data preservation requests for litigation holds;

conducts digital forensics in support of the Security program

COMPETENCIES :

Knowledge of Company business practices and familiarity with Company products and services

Ability to develop and make recommendations for security processes, procedure improvements and management level security standards

Ability to identify best practices for security risk assessments, policies, standards and processes

Policy, process, and standard development experience

QUALIFICATIONS

MINIMUM EDUCATION AND / OR EXPERIENCE :

Bachelors degree from a four-year college or university in Information Resource Management, Business Computer Systems, Computer Science or Computer Security with three to five years related experience, or equivalent combination of education and / or experience related to the discipline.

COMMUNICATION SKILLS :

Ability to maintain positive and productive working relationships with various individuals and groups

Ability to recognize and initiate tasks without direction

Ability to read and interpret technical manuals and reports, instructional documents, and procedure manuals

Ability to write procedural documentation and user instructions

Ability to speak effectively with various individuals, groups, and vendors

MATHEMATICAL SKILLS :

Ability to calculate figures and amounts such as discounts, interest, commissions, proportions, percentages, area, circumference, and volume

Ability to apply concepts of basic algebra and geometry

COMPUTER SKILLS :

To perform this job successfully, an individual should have in-depth knowledge and experience with IBM / UNIX servers, client / server applications and information security issues

In-depth knowledge of Microsoft, IBM and UNIX server security functionality

Working knowledge of related security software

Working knowledge of database product security technology, specifically Oracle, SQL and DB2 and general knowledge of physical security methods for securing automated systems and network components

ANALYSIS AND PROBLEM-SOLVING ABILITY :

Ability to understand and assimilate complex technical information. Ability to solve partial problems and deal with a variety of concrete variables in situations where only limited standardization exists.

Ability to interpret a variety of instructions furnished in written, oral, diagram or schedule form.

DECISION MAKING :

Ability to make access management and provisioning decisions without direction, in accordance with Company policies, procedures and programs.

Examines potential areas for service improvement and makes recommendations for changes to senior staff or management.

PHYSICAL DEMANDS :

While performing the duties of this job, the employee is regularly required to sit up to 2 / 3 of the time and talk and listen for long periods of time.

WORK ENVIRONMENT : Office environment.

Office environment.

EQUAL OPPORTUNITY STATEMENT

Safety Statement :

Safety is a core value at (PNMR / PNM / TNMP) and our vision, "everyone goes home safe", reflects our commitment to promoting an environment conducive to learning, improving and building safety practices.

Our safety value is built upon the belief that every employee deserves to work in an environment free from harm.

Americans with Disabilities Act (ADA) Statement :

PNM Resources is committed to providing reasonable accommodations for qualified individuals with disabilities in compliance with the ADA.

If you require assistance with the job application process due to a disability, please contact HR ADA Analyst, at 505-241-4627.

DEI Statement :

At PNM Resources, we value the diversity of our workforce and actively seek opportunities for incorporating Diversity, Equity, and Inclusion (DEI) within our family of companies.

We believe a diverse workforce enriches our environment and helps us better meet the needs of our employees, customers, and shareholders.

We remain committed to attracting and sustaining a diverse workforce and retaining high-performing employees who work collaboratively to carry out the Company's purpose.

PNM Resources and affiliates are Equal Opportunity / Affirmative Action employers. Women, minorities, disabled individuals and veterans are encouraged to apply.

7 days ago
Related jobs
ISYS Technologies.
Albuquerque, New Mexico

This essential position will provide services for Information Technology, including Web/Software Development, Information Assurance/Information Security, IT Customer Service Desk Support, System Administration, and Network Administration. Whether the focus is on space exploration, national security,...

Promoted
Keenbee Talent Soluitions
Albuquerque, New Mexico

Cybersecurity Information Systems Security Engineer!. This position involves working closely with the program manager on classified projects, ensuring the security and efficiency of our operations supporting the Department of Defense (DoD). Collaborate with government stakeholders to enhance cyberse...

Promoted
Allied Universal®
Albuquerque, New Mexico

As a Security Officer, you will serve and safeguard clients in a range of industries such as Commercial Real Estate, Healthcare, Education, Government and more. Allied Universal®, North America's leading security and facility services company, provides rewarding careers that give you a sense...

Promoted
Parsons Corporation
Albuquerque, New Mexico

This includes process support, analysis support, coordination support, security certification test support, security documentation support, investigations, software research, hardware introduction and release, emerging technology research inspections, and periodic audits. Performs analyses to valida...

Promoted
Route 66 Casino Hotel
Albuquerque, New Mexico

A Security Officer provides site protection to all LDC properties and physical protection to all LDC patrons and personnel addressing issues including, but not limited to altercations, theft, vandalism, fire, illegal entry and illegal activities. ...

Promoted
Santa Ana Star Casino Hotel
Bernalillo, New Mexico

Security Officer responsible for the safety and security of the facility by being visible, mobile and vigilant. Experience in the Security field is a plus. ...

Promoted
TELUS International
Albuquerque, New Mexico

We are hiring freelance English & Spanish speaking Online Data Analyst’s for a project aimed at improving the content and quality of digital maps, which are used by millions of users globally. TELUS International AI-Data Solutions partners with a diverse and vibrant community to help our customers e...

Promoted
Sandia National Laboratories
Albuquerque, New Mexico

Security Police Officers assist in controlling the ingress and egress of all persons in certain security areas in accordance with established identification procedures. As a condition of employment, Security Police Officers are represented by the Security Police Association (SPA) and represented emp...

Promoted
PNM Resources, Inc.
Albuquerque, New Mexico

Sr Customer Services Performance Analyst (Data and Analytics). Advanced ability to analyze, summarize, and effectively present data. Ability to present data in formats prompting sound decision-making. Advanced experience with MS Office applications and proficiency with data analysis applications and...

Promoted
NANA Regional Corp
Albuquerque, New Mexico

We are looking for a Cyber Security Engineer to help us protect our systems and networks from cyber threats. As a cybersecurity engineer, you will be responsible for designing, implementing, and maintaining security solutions that align with Federal objectives and industry best practices. Tuvli is l...