Senior Cyber Security Analyst - (25-IT-601015-079)
DC WaterAbout the role
The intent of this job description is to provide a representative summary of the major duties, locations, and responsibilities performed by incumbent(s) in this job. Incumbent(s) may not be required to perform all duties in this description, and incumbent(s) may be required to perform work-related tasks other than those specifically listed in this description. This job description is not a “contract” between the employee and the Authority. The job duties and essential functions may be changed at the discretion of the General Manager.
General
Job Title: Senior Cyber Security Analyst Job Code: P0548 Supervises Directly: No New or Revised: Revised Regular or At-Will: At-Will Date Last Revised: 5/23/2025 Exempt or Non-Exempt: Exempt Compensation Approval Signature: Union/ Non-Union: Non-Union Department Name and Division: IT-Information Security Salary Schedule: Non-Union Salary Range Cost Center Code: 601015 Grade: NU17 Essential Position: No Reports To: Director, Cyber Security Services EEO Code: Professionals Work Format Hybrid
Who We Are & What We Do:
At DC Water, we provide more than 700,000 District of Columbia residents and 24.6 million annual visitors with essential water, wastewater, and stormwater services. DC Water also provides wholesale wastewater treatment services for 1.8 million people in Montgomery and Prince George's counties in Maryland, and Fairfax and Loudoun counties in Virginia. We aspire to be known for superior service, ingenuity, and stewardship to advance the health and well-being of our diverse workforce and communities. To achieve this vision, we commit to our shared mission every day—exceeding expectations by providing high quality water services in a safe, environmentally friendly, and efficient manner.
Role Description:
The Senior Cyber Security Analyst is responsible for the administration of deployed cyber control technologies. The role is part of the Security Operation Center (SOC) which monitors, analyzes, detects, and responds to cyber incidents on both traditional IT and Operational Technology (OT) networks. The role coordinates with both the Information Technology (IT) team and Operational Team (OT) to ensure individuals have the appropriate access to DC Water Resources, monitors vulnerabilities and threats, collects intelligence, assists in disaster recovery operations, and in updating cyber controls with intelligence obtained from third-party providers. This role is also responsible for the identification of IT assets supporting DC Water’s business processes.
Essential Duties & Responsibilities:
- Supports the Director, Cyber Security Services, in ensuring DC Water’s preparedness to address cyber risks.
- Maintains user access controls for computing resources.
- Monitors SOC operations to detect, analyze, and respond to cyber incidents, including intrusion attempts, malware infections, and other security threats, across IT and OT networks.
- Analyzes security events and incidents within the DC Water Computing and Network environment, investigating root causes, assessing impact, and coordinate and document response actions to mitigate risks and minimize operational disruptions.
- Tests, implements, deploys, maintains, reviews, and administers the infrastructure software required to effectively manage the DC Water network defenses and resources.
- Monitors DC Water’s network to actively remediate unauthorized activities.
- Assists in disaster recovery operations, using preparation, identification, mitigation, remediation, and recovery approaches, as needed to maximize business resilience and information security.
- Collaborates with the Director, Cyber Security Services, to incorporate threat intelligence obtained from third-party providers into Cyber Controls, enhancing DC Water's ability to proactively identify and mitigate emerging threats.
- Conducts and reports outcomes of vulnerability and penetration testing on IT and OT systems, identifying and prioritizing vulnerabilities for remediation to reduce the risk of exploitation by malicious actors.
- Uses advanced threat hunting techniques and tools to identify and neutralize threats before they escalate.
- Documents security incidents, investigations, and response activities in accordance with established procedures, ensuring accurate and thorough reporting for compliance, audit, and legal purposes.
- Determines deviations from acceptable configuratio
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s