07 Aug
|
Eetdbuyersguide
|
Ottawa
07 Aug
Eetdbuyersguide
Ottawa
OverviewNOTE: This role is hybrid requiring 3 days a week onsite at one of our local offices in: Allentown, PA; Louisville, KY or Providence, RI. #LI-HybridThe IT Security Systems Analyst will leverage tools to perform vulnerability and threat monitoring. Investigates, responds to, and reports on network and security risks to PPL EU tools which include but are not limited to SIEM, NIDS/NIPS, and HIDS/HIPS suites. This position is required to do shift work. The Senior level performs assigned tasks under minimal guidance from supervisor. Additionally, this role is responsible for supporting firewall security operations, including interpreting, reviewing, and assessing firewall rules for security risk, ensuring alignment with cybersecurity standards, and least privilege principles.ResponsibilitiesEssential Functions:Performs a variety of complex assignments (may lead some projects) and analyzes and solves complex problems in the below areas.Network and Cyber Threat Monitoring:Conduct ongoing review of multiple systems and sources to detect network access, network intrusion, information integrity, and NERC CIP compliance risksInvestigate network security events, conducting root-cause analysis to identify threats for recurring incidentsMonitor and track incidents related to network access, network intrusion, cybersecurity, and NERC CIP regulatory complianceCorrective Actions:Troubleshoot, diagnose network problems, and implement corrective action within prescribed guidelines to mitigate impact to business continuitySupport restoration of secure network services as quickly as possible while limiting business impactReport network incidents, cybersecurity incidents,
and NERC CIP compliance risksAssist in minor network or system configuration changes to improve system security and meet NERC CIP compliance requirementsRecommend and implement firewall rule tuning or configuration changes to mitigate identified risks and improve security postureAssist in firewall policy remediation efforts to address audit findings, compliance gaps, or identified vulnerabilitiesInterpret, review, and analyze firewall rules to identify security risks, misconfigurations, overly permissive access, and compliance gapsPerform risk-based reviews of firewall rule requests and existing rule sets to ensure adherence to security standards and least privilege accessSupport firewall governance processes, including intake validation, rule lifecycle management (create/modify/remove), and periodic recertification activitiesConduct firewall rule reviews to identify redundant, shadowed, or unused rules and recommend remediation actionsAssess firewall configurations against security baselines and hardening standards to reduce attack surfaceCollaborate with network, infrastructure, and OT teams to ensure firewall changes are properly designed, tested, and implemented with minimal business riskUtilize firewall management and policy analysis tools (e.G., FireMon, AlgoSec) to evaluate rule effectiveness, policy compliance,
and risk exposureSupport incident response efforts by analyzing firewall logs and rule behavior to determine potential threat activity or unauthorized access pathsDevelop and maintain documentation related to firewall policies, standards, and review proceduresPerforms other duties as assignedComplies with all policies and standardsQualificationsRequired Experience:Bachelor's degree and 5+ years of related work experience.Deep knowledge and hands‐on experience with enterprise firewall platforms, including Cisco ASA and Palo Alto Networks firewallsExperience administering and managing Palo Alto Panorama for centralized firewall policy managementFamiliarity with DLP, SIEM, NIDS/NIPS, HIDS/HIPS, and endpoint protection suiteExperience with firewall management, including rule lifecycle management, governance processes, and access control designStrong understanding of firewall hardening practices, segmentation strategies, and least privilege network designAbility to interpret complex firewall rule sets and translate findings into actionable security recommendationsEasily adapts to changing circumstancesUnderstands business goals and strategic prioritiesPreferred Qualifications:NERC CIP Compliance Analysis Certification, System Operator Certification, GIAC Critical Infrastructure Protection Security CertificationPossesses knowledge and understanding of specific testing tools (e.G., Windows automation tool)Ability to establish and maintain the appropriate programs to recover the systems in the event of a disaster or security threatPresents a creative approach to problemsExperience supporting rapid‐changing business organizations #J-18808-Ljbffr
📌 Senior It Security Systems Analyst (Ottawa)
🏢 Eetdbuyersguide
📍 Ottawa