Senior Cyber Security Analyst (Governance/Risk/Compliance)
New York Power AuthorityAbout the role
Summary
The Senior Cyber Security Analyst manages or performs work associated with all aspects of activities, services, technology, and products that IT provides and IT governance to ensure that IT investments sustain and extend its strategies and objectives. This includes providing direction and developing information technology strategies, policies, and plans, performing maintenance of information technology resources, training and supporting technology users, providing network and communications services, data governance and management, IT governance framework, processes, management and performance reporting of IT services, as well as, AGILe (Advanced Grid Innovation Lab for Energy), digital transformation, and research and development services. Manages all activities necessary to enable NYPA to anticipate, prevent, and respond to technology interruptions.
This role ensures the confidentiality, integrity, and availability of NYPA information through the establishment of security controls, governance instruments (policies, standards) and associated processes, and provides governance and oversight to ensure that appropriate security measures are designed and architected into IT solutions and services and that vulnerabilities are identified and remediated, plus monitors NYPA’s technology landscape to detect and respond to threats.
This position will be focused particularly on Cyber Governance, including policies, procedures, Cyber Awareness, Incident Response readiness exercise planning, Information Protection, and 3rd party/vendor/Supplier security (for enterprise IT and Bulk Electric System (BES) Cyber Systems as part of the NERC Critical Infrastructure Protection (CIP) standards).
#LI-JP1
Responsibilities
- Ensure the development, implementation and refinement of security policies, procedures, and programs to protect the New York Power Authority’s Information Technology cyber assets and enterprise digital ecosystem on premise and in cloud which include computers, networks, telecommunications equipment, data centers, and firewalls.
- Develop recommendations for IT Solutions based on business requirements; includes understanding and documenting business needs.
- Develop, implement, and monitor and enforce appropriate cyber security policies and standards pertaining to security, account access and control, incident and escalation reporting, intrusion detection, data protection and threat vulnerability management.
- Threat and vulnerability management, remediation, and oversight.
- Cyber Security Awareness and Education program management.
- Assist with the configuration of and monitoring health of NYPA Cyber Security Services and Technologies.
- Create, maintain, and manage documentation on cyber security assets, tools, and software.
- Collaborate with other IT disciplines as necessary to achieve Cyber Security outcomes.
Knowledge, Skills and Abilities
- Strong understanding of interactions of applications, operating systems, and hardware configurations to produce high quality technically sound solutions.
- Robust understanding of IT industry trends and tools as they apply to providing solutions to stated business issues and opportunities.
- Comprehensive understanding of the IT system infrastructure and network topology, familiarity with cyber security strategies and Security Information and Event Management (SIEM) tools.
- Strong knowledge of cyber security policies and practices found throughout both the public and private sectors.
- Ability to understand and communicate complex IT security and policy planning.
- Demonstrated analytical problem-solving skills and practical cyber security experience.
- Ability to communicate complex technical and security related concepts to a broad range of technical and non-technical staff.
- Demonstrated ability to assist in managing complex projects as required.
Education, Experience and Certifications
- Associate's Degree / Military Veteran required with minimum 7 years of experience in Information Technology or Cyber Security
Preferred Education/Experience:
- Bachelor’s degree with minimum 5 years of experience in Information Technology
- Industry Certification such as CISSP or CISM certification, or equivalent
Physical Requirements
May be required to respond Cyber Security alerts and communicate during off hours.
The New York Power Authority is committed to providing fair, competitive, and market-informed compensation. The target salary range for this position is: $108,060.00 - $135,000.00. The salary offered will be determined based on the successful candidates’ relevant experience, knowledge, skills, and abilities.
The New York
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s