Information Assurance Analyst - Oahu
We recognize our competitive advantage — our people. We believe in our employees, who share our vision of meeting the needs of our employees, customers, and communities and who carry out the continued success of the company. Our employees are committed to the company's foundational values: integrity, excellence, teamwork, environmental stewardship, and community commitment. In turn, we invest in our employees, providing opportunities for challenge and advancement and offering a competitive compensation package.
About the role
The Information Assurance Department within the Information Assurance Division at Hawaiian Electric Company has two professional-level vacancies. This role performs assessments of systems and networks to identify deviations from acceptable configurations, policies, or guidance, measures the effectiveness of defense-in-depth architecture, and assists with risk assessments and security architecture solutions.
Responsibilities
- Performs information security risk assessments and recommends mitigating controls and solutions for IT and Operations Technology (OT) projects and applications, including proposals for externally hosted applications and new utility technology projects.
- Assists with system assessments for conformance with configuration control, policy, and guidance.
- Assists with program development and management for privacy, e-discovery, security awareness training, digital forensics, vulnerability remediation, and other security and compliance programs.
- Performs miscellaneous administrative roles such as schedule development, information tracking, updating deliverables, and other assigned work.
- Supports the Company’s business continuity planning, IT disaster recovery planning, cybersecurity incident response planning and team (CS-IMT), with occasional on-call support.
- Participates in Company emergency response activities as assigned, including preparation for such responses.
Requirements
Knowledge
- Computer networking concepts and protocols, and network security methodologies.
- Risk management processes (e.g., methods for assessing and mitigating risk).
- Cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
- Laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
- Cyber threats and vulnerabilities.
- Cryptography and cryptographic key management concepts.
- Data backup and recovery concepts.
- Host/network access control mechanisms (e.g., access control list, capabilities list).
- Network access, identity, and access management (e.g., public key infrastructure, OAuth, OpenID, SAML, SPML).
- Traffic flows across the network (e.g., TCP/IP, OSI Model, ITIL).
- Programming language structures and logic.
- System and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL injections, race conditions, covert channel, replay, return-oriented attacks, malicious code).
- Network attacks and their relationship to threats and vulnerabilities.
- System administration, network, and operating system hardening techniques.
- Different classes of attacks (e.g., passive, active, insider, close-in, distribution attacks).
- Different cyber attackers (e.g., script kiddies, insider threat, non-nation state sponsored, and nation sponsored).
- Different cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
- Network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
- Specific operational impacts of cybersecurity lapses.
- Security models (e.g., Bell-LaPadula model, Biba integrity model, Clark-Wilson integrity model).
- Ethical hacking principles and techniques.
- Penetration testing principles, tools, and techniques.
Skills
- Conducting vulnerability scans and recognizing vulnerabilities in security systems.
- Assessing the robustness of security systems and designs.
- Detecting host and network-based intrusions via intrusion detection technologies (e.g., Snort).
- Mimicking threat behaviors.
- Use of penetration testing tools and techniques.
- Use of social engineering techniques (e.g., phishing, baiting, tailgating).
- Use of network analysis tools to identify vulnerabilities (e.g., fuzzing, nmap).
- Reviewing logs to identify evidence of past intrusions.
- Conducting application vulnerability assessments.
- Performing impact/risk assessments.
- Developing insights about the context of an organization’s threat environment.
- Collaborating with teammates and other employees.
- Communicating effectively in writing and verbally.
Experience
Entry Level: 1–3 years of experience in systems administration, basic cyber analysis/operations, cyber threats, risk management, network management, IT system design, cloud deployment, or wireless networking. Associate’s degree or equivalent work experience in computer science, cybersecurity, information technology, software engineering, information systems, or computer engineering. Must obtain one or more of the following certifications within the first six months of employment: A+ CE, CCNA-Security, CND, Network+ CE, SSCP, CySA+ (CSA+), GICSP, GSEC, Security+ CE (other certifications may be considered).
Intermediate Level: 4–7 years of experience in information assurance, incident handling, risk management, vulnerability management and analysis, and assistance programs. Bachelor’s degree (or higher) in computer science, cybersecurity, information technology, software engineering, information systems, or computer engineering. One or more of the following certifications: A+ CE, CCNA-Security, CND, Network+ CE, SSCP, CySA+ (CSA+), GICSP, GSEC, Security+ CE (other certifications may be considered).
Pay
The hiring range for this position is $89,100.00 to $113,700.00. The selected candidate will be placed according to skills and qualifications.
About Hawaiian Electric Companies
Hawaiian Electric Companies provide electricity and services to 95 percent of the state's 1.4 million residents. The company is also one of the state's leading employers and a major contributor and supporter of community and educational programs. With over a century of service, the company is committed to providing quality service and seeking clean local energy sources to power generations of Hawaii families and businesses.