Information Security Risk Analyst IIIJob Title: Information Security Risk Analyst III Job ID: 104293 Location: MD - Baltimore
Full/Part Time: Full-Time Regular/Temporary: Regular Return to Previous Page
Responsibilities Job Summary:
The Information Security Risk Analyst III (ISRA III) provides cyber and information security expertise in the analysis, assessment, development, and evaluation of security solutions and architectures to secure applications, operating systems, databases, and networks. The ISRA III develops security requirements, conducts security risk assessments, designs security solutions, evaluates application and system architectures, and develops and reviews security policies and standards. The ISRA provides cyber and information security risk consulting to business units, information technology (IT) organizations, and support and operational functions. The ISRA III leads the cyber and information security aspects of business initiatives and IT projects to assist in mitigating security risks for information, business, and operational applications and systems across the company. This role serves as a senior staff member of the Information Risk (IR) team with technical cyber and information security expertise to mitigate cyber security risks to the company, including its stakeholders and customers.
Reports To:
Supervisor, Information Risk
Primary Duties and Responsibilities:
1. Provides subject matter expertise in information systems security and risk management for BGE¿s Smart Grid Initiative (SGI) and other BGE Vision 2020 projects. 2. Performs application and technology design reviews, security risk assessments, requirements analysis, security testing oversight, risk remediation planning, and security project management. 3. Develops and supports the integration of processes and procedures for secure application development, security risk management, and effective risk assessment practices. 4. Serves as a cyber and information security consultant by providing research, analysis, and guidance on management, operational and technical security requirements and solutions for business and technology initiatives. 5. Provides security project management, risk assessments, security requirements analysis, design reviews, security testing oversight, and risk remediation planning and coordination. 6. Develops and executes Smart Grid cyber security strategy and plan, including ensuring that security deliverables and milestones are achieved. 7. Assists systems engineers, application developers, and IT architects in defining Smart Grid cyber security requirements. 8. Develops, reviews, and maintains security risk management policies, standards, and practices, including technical IT security standards for 9. Analyze and evaluate cyber and information security solutions, including technologies and architectures, security controls and procedures, and contracting documentation. 10. Other duties as assigned. Qualifications Job Specifications:
Knowledge, Skills, and Abilities:
¿ Demonstrated experience and subject matter knowledge in cyber and information security for applications, web architectures, operating systems, databases, and networks. ¿ Experience in security risk assessment, requirements development, secure design analysis, architecture assessment and development, and security testing of applications and systems. ¿ Experience in analyzing and evaluating security applications and systems, such as Cisco firewalls, security appliances, IDS/IPS, SSL or TLS, IPsec, and web services security. ¿ Extensive experience developing, evaluating, and implementing cyber and information security architectures, technologies, standards, and practices to secure systems and applications. ¿ Experience in developing, analyzing, and implementing security controls and solutions for Smart Grid or energy-related technologies, applications, systems and networks. ¿ Knowledge and proven experience with information security program development and implementation for energy and utility systems ¿ Working knowledge of network security engineering principles, practices, and architecture. ¿ Working knowledge of modern application security principles and practices. ¿ Ability to provide policy, process, operational, and technical guidance as they relate to Smart Grid or energy-related cyber security risk management. ¿ Knowledge and experience in the implementation of security risk management processes and frameworks, such as NIST and ISO guidelines and standards. ¿ Demonstrated experience in addressing regulatory compliance for the security requirements in applicable laws and regulations, such as NERC CIP and SOX. ¿ Ability to demonstrate analytical skills, technical knowledge, and practical application of cyber and information security principles to business leaders and technical staff. ¿ Excellent oral and written communications skills
Education/Experience: ¿ Bachelor¿s Degree in Computer Science, Information Technology (IT), or a related discipline ¿ Minimum 7 years of cyber and information security experience. ¿ Certified Information Systems Security Professional (CISSP), Certified Information Systems Manager (CISM), or other equivalent security certifications preferred. ¿ Must maintain the highest level of confidentiality and discretion regarding all corporate matters. ¿ Must meet the requirements of Company¿s candidate screening policies and/or regulations.
- Candidates must have the ability to speak, read and write English EEO & Employment Eligibility Equal Employment Opportunity
Constellation Energy and its member companies do not discriminate in employment with regard to age, citizenship, color, disability, marital status, national origin or ancestry, race, religion, sex, sexual orientation, gender identity or expression, veteran status, union affiliation, or any other basis prohibited by applicable federal, state, or local laws. In addition, no question contained in this application is intended to or will be used for the purpose of limiting or excluding the applicant's consideration for employment on any such basis.
Employment Eligibility
The Immigration and Reform and Control Act of 1986 prohibits the employment of unauthorized aliens and requires employers to verify the employment eligibility of all new employees. Any offer of employment made by Constellation Energy or any of its member companies will be conditioned on your providing the documentation required by law as evidence of your personal identity and your authorization to work in the United States. Any offer of employment is also conditioned upon the successful completion of a background investigation, a post-offer physical evaluation (if applicable) and a drug screen.
|