Jobs · OTHR · California

Cyber Threat Intelligence Advisor

Southern California Edison (SCE) · Rosemead, CA · 3 wk ago
OTHRFull-time

Join the Cyber Threat Intelligence team at Southern California Edison (SCE), a sub-team under SCE’s broader Cybersecurity Operations Center (CSOC). Help shape and mature SCE's Cyber Threat Intelligence program while contributing to both tactical execution and long-term program development in a mission-critical environment.

About the role

In this role, you will refine intelligence strategy, processes, capabilities, operating models, collection priorities, toolsets, and workflows. You will lead the operationalization and sustainment of SCE's classified intelligence program, including engagement with federal, industry, and intelligence-sharing partners. Your work will include developing intelligence products, executive briefings, and threat assessments that communicate actionable insights to technical stakeholders and senior leaders. You will analyze emerging threats, adversary campaigns, tactics, techniques, and procedures (TTPs) through classified and unclassified sources to assess risks and drive intelligence activities aligned to Priority Intelligence Requirements (PIRs).

Responsibilities

  • Manage cybersecurity project delivery by ensuring the cybersecurity team meets success criteria.
  • Deliver project reporting for assigned projects, conduct critical analysis of project status, potential risks, and continual process improvement.
  • Coordinate and perform appropriate maintenance to ensure reliable and secure performance of security systems, including applying security patches, implementing version upgrades, modifying and improving services, and performing ongoing operational management tasks.
  • Contribute to an overall cybersecurity governance strategy, standards, and operational procedures.
  • Ensure technology risks impacting the business are effectively identified, quantified, communicated, and managed, including recommendations for resolution and identifying root causes/key themes.
  • Prepare and update Plan of Actions & Milestones (POA&M) that identify security weaknesses, establish milestones, and implement compensating controls for remediating these weaknesses while tracking progress and effectiveness.
  • Oversee the production of evidence to support internal and external audits.
  • Provide cybersecurity and risk assessments for new networks, services, and devices as needed.
  • Drive periodic monitoring of audit logs in accordance with requirements, and report findings and concerns for further analysis and action, including breach notification and initiation of incident response.
  • Deliver programs and processes to reduce information security risk and strengthen SCE's security posture.
  • Regularly develop intelligence products, executive briefings, and threat assessments that communicate actionable insights, emerging risks, and strategic intelligence.
  • Analyze emerging threats, adversary campaigns, TTPs through classified and unclassified sources to assess potential risks to SCE and drive intelligence activities aligned to Priority Intelligence Requirements (PIRs).
  • Execute and support day-to-day intelligence program operations including developing and tuning intelligence-related alerts, leveraging intelligence platforms and tooling, conducting research in support of PIRs, and integrating intelligence into CSOC activities such as incident response and investigations.

Requirements

  • Seven or more years of experience in information technology, information security, and/or cybersecurity.
  • US Citizenship required.

Preferred Qualifications

  • Active TS/SCI Security Clearance.
  • Experience working in classified facilities and engaging in federal intelligence programs.
  • Experience as an Intel Analyst AND in a SOC, IR, or specialized cybersecurity role.
  • Understanding of threat intelligence collection methodologies.
  • Excellent verbal and written communication.
  • Experience with data analysis and threat intelligence platforms.

Schedule

This position’s work mode is hybrid. The employee will report to an SCE facility for a set number of days with the option to work remotely on the remaining days. The work mode can be changed based on business needs.

Position will require up to 20% traveling and being out in the field throughout the SCE service territory.

Similar jobs

Cyber Advisor

KBR CareersMcLean, VA· 1 mo ago
Engineering$160k–$196k/yrapply on careers.kbr.com