Information Security Analyst - Topeka, KS

Date Posted: 11/08/2019

o Summary of Primary Duties and Responsibilities:
With general supervision, this position provides support to ensure compliance with North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) standards and Corporate Information Security Policies. The position will be responsible for monitoring and responding to security events and ensuring security controls are functioning as expected. Maintaining accurate documentation in all aspects of this position is required. The individual will operate in a cross functional capacity working closely with vendors, engineers, operators, technicians, and information technology resources.

 Monitors various tools for security related events (including participation in after-hours on-call rotation).
 Researches, analyzes and troubleshoots compliance and security related events.
 Record, track and document security related events including all successful and unsuccessful decisions made, actions taken, through to final resolution.
 Escalates security related issues as needed.
 Assist in the creation, analysis and distribution of threat intelligence.
 Access knowledge bases and FAQ resources on the Internet/Intranet to aid in problem resolution.
 Produce and maintain clear and concise documentation of security monitoring procedures.
 Follow documented procedures.
 Manage the creation, analysis and distribution of security monitoring reporting.
 Apply knowledge of IT systems to aid in troubleshooting.
 Identify an learn appropriate software and hardware used and supported by the organization.
 Suggests and assists in implementation of process improvement opportunities.
 Store and maintain appropriate evidence to ensure compliance with regulatory standards.
 Identify possible threats to information systems and supporting communication networks by analyzing results produced by using technical security monitoring tools.
 Ensure protection of corporate assets by assisting with the Information Security business function.
 Proactively identifies and implements process improvement opportunities.
 Maintain accurate lists of IP ports and services of related cyber assets.
 Execute and document cyber security controls testing to validate security controls are present and operating as expected.
 Increase information security awareness within the corporation by designing, developing and presenting training on all aspects of information security.
 Contribute to the effectiveness of the Information Security Program by assisting with the documentation and implementation of plans that deter security threats and minimize the impact of a system breach.
 Other duties as assigned.
Education and Experience Requirements:
A bachelor’s degree is desired in Information Systems, Computer Science or related field. The successful candidate typically has 2 or more years of experience in information technology or information security. The incumbent must pass a criminal and employment background investigation.

Skills, Knowledge, and Abilities Required:
 Good understanding of general networking (OSPF, TCP/IP, etc.) required.
 Ability to manage perimeter security solutions.
 Ability to manage endpoint security solutions.
 Good understanding of cybersecurity and NERC CIP Compliance Standards.
 Good knowledge across IT disciplines, including multiple operating systems and IP networking.
 Strong skills with Microsoft Office products, i.e., Outlook, Word, Excel & PowerPoint.
 Strong communication and presentation skills. Is self-motivated, goal oriented, & an innovative thinker.
 Ability to explain technical material in non-technical terms.
 Ability to communicate across the organization and to include outside counterparts in other businesses industry-wide.
 Effective oral and written communication skills are necessary, especially the ability to present technical information to an audience with a broad range of information technology experience.
 Quickly adapts to the demands inherent in managing multiple customer needs and requirements simultaneously.
 Ability to prioritize tasks based on criticality & meet deadlines.
 Ability to apply common sense, understand & carry out instructions furnished in written, oral or diagram form & to deal with problems using a logical problem- solving approach.
 Current with knowledge of new technologies and corporate information systems as they affect information security.
 Skills in Windows or Unix operating systems, technical aptitude, and the ability to learn and utilize new operating systems is required.
 Required to function independently to analyze information and report variances.
 Ability to lift/move/carry between 10 - 50 pounds if required to perform the essential job functions.
 Ability to sit for extended periods of time.
 Occasional overnight travel.




