Talent.com
Senior Information Assurance Analyst - Oahu (Honolulu, Hawaii
Senior Information Assurance Analyst - Oahu (Honolulu, HawaiiHawaiian Electric Company • Honolulu, HI, United States
Senior Information Assurance Analyst - Oahu (Honolulu, Hawaii

Senior Information Assurance Analyst - Oahu (Honolulu, Hawaii

Hawaiian Electric Company • Honolulu, HI, United States
1 day ago
Job type
  • Full-time
Job description

We recognize our competitive advantage our people. We believe in our people, who share our vision of meeting the needs of our employees, customers, and communities and who carry out the continued success of the company.

Our employees are committed to the company's foundational values : integrity, excellence, teamwork, environmental stewardship, and community commitment. In turn, we invest in our employees, providing opportunities for challenge and advancement and offering a competitive compensation package.

Posting End Date : This position will remain open until filled. Early applications are encouraged.

BRIEF POSTING DESCRIPTION :

The P EJ INFORMATION ASSURANCE Department of the P INFORMATION ASSURANCE Division at Hawaiian Electric Company has 1 Management vacancy available. (Role : Professional)

JOB FUNCTION :

Oversees or performs the assessments of Company systems and networks and identifies where those systems / networks deviate from cybersecurity policies, acceptable configurations, or guidance. Provides consulting-level knowledge and expertise for the Information Assurance (IA) division, which includes development and enforcement of cybersecurity policies & standards, cybersecurity risk management activities, information technology (IT) and operational technology (OT) compliance, and secure integration of grid technologies and cloud services. Supports development of detailed plans and provides requirements for information systems' security controls and security monitoring solutions. Performs security control reviews to validate the security controls as designed are operating effectively. Develops policies, standards, and procedures to ensure that security controls are adequately designed.

ESSENTIAL FUNCTIONS :

  • Performs cybersecurity assessments and provides security control requirements for IT and OT projects, including externally hosted applications and grid technology projects.
  • Develops and manages programs and processes for privacy, e-discovery, security awareness training, digital forensics, patch management, vulnerability remediation, and other security and compliance programs.
  • Supports detailed review and approval processing for various policies, processes, and procedures necessary to support the Company's cybersecurity security and compliance requirements.
  • Ensures that adequate and proper internal controls, processes, practices, and standards are developed, maintained, and tested in order to meet the Company's policy and compliance requirements.
  • Supports the business continuity planning, disaster recovery planning, and the Company's Cybersecurity Incident Management Team (CS-IMT), with occasional on-call support.
  • Participates in Company emergency response activities as assigned, including any activities required to prepare for such emergency response.

BASIC QUALIFICATIONS :

Knowledge Requirements

  • Computer networking concepts and protocols, and network security methodologies.
  • Risk management processes (e.g., methods for assessing and mitigating risk).
  • Cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
  • Laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Cyber threats and vulnerabilities.
  • Cryptography and cryptographic key management concepts.
  • Data backup and recovery concepts.
  • Host / network access control mechanisms (e.g., access control list, capabilities list).
  • Network access, identity, and access management (e.g., public key infrastructure, Oauth, OpenID, SAML, SPML).
  • Traffic flows across the network (e.g., Transmission Control Protocol [TCP] and Internet Protocol [IP], Open System Interconnection Model [OSI], Information Technology Infrastructure Library, current version [ITIL]).
  • Programming language structures and logic.
  • System and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language / Structured Query Language [PL / SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code).
  • Network attacks and a network attack's relationship to both threats and vulnerabilities.
  • System administration, network, and operating system hardening techniques.
  • Different classes of attacks (e.g., passive, active, insider, close-in, distribution attacks),
  • Different cyber attackers (e.g., script kiddies, insider threat, non-nation state sponsored, and nation sponsored).
  • Different cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks, etc.).
  • Network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
  • Specific operational impacts of cybersecurity lapses.
  • Security models (e.g., Bell-LaPadula model, Biba integrity model, Clark-Wilson integrity model).
  • Ethical hacking principles and techniques.
  • Penetration testing principles, tools, and techniques.
  • Conceptual knowledge of National Institute and Standards and Technology (NIST) Standards, ISO 27000 series, OWASP, and other security related frameworks and standards.
  • Conceptual knowledge of utility business and related Operational Technology Systems (SCADA, DCS
  • Skills Requirements

  • Conducting vulnerability scans and recognizing vulnerabilities in security systems.
  • Assessing the robustness of security systems and designs.
  • Detecting host and network-based intrusions via intrusion detection technologies (e.g., Snort).
  • Mimicking threat behaviors.
  • Use of penetration testing tools and techniques.
  • Use of social engineering techniques (e.g., phishing, baiting, tailgating, etc.).
  • Use of network analysis tools to identify vulnerabilities (e.g., fuzzing, nmap, etc.).
  • Reviewing logs to identify evidence of past intrusions.
  • Conducting application vulnerability assessments.
  • Performing impact / risk assessments.
  • Developing insights about the context of an organization's threat environment.
  • Collaborating with teammates and other employees.
  • Communicating effectively in writing and verbally.
  • Proven ability to analyze highly complex systems, demonstrating critical thinking skills, independent judgment, and the ability to work toward consensus in a complex business environment.
  • Must demonstrate analytical skills and the ability to communicate effectively (oral and written) and work with a variety of individuals throughout the organization including managers and executives.
  • Ability to operate autonomously with only general direction and guidance.
  • Experience Requirements

  • Advanced (7-10 years) analysis and / or leadership experience in a multi-level service or consulting organization, preferably in an information technology, application security, network security or quality assurance capacity. Information security experience is required.
  • One or more of the following certifications (others will be considered) :
  • Certified Information Systems Security Professional (CISSP)

  • Certified Information Security Manager (CISM)
  • Certified Information Security Auditor (CISA)
  • GIAC Security Leadership (GSLC)
  • Certified Cloud Security Professional (CCSP)
  • Security +
  • Systems Security Certified Professional (SSCP)
  • Role : Professional

    Number of Vacancies : 1

    Location : Honolulu - Oahu

    Hiring Range : The hiring range for the Senior Information Assurance Analyst [Req ID 9985] position is $107,700.00 to $139,800.00. The person selected will be placed according to his / her skills and qualifications.

    About Hawaiian Electric Companies

    Hawaiian Electric Companies provide electricity and services to 95 percent of the state's 1.4 million residents. The company is also one of the state's leading employers and a major contributor and supporter of community and educational programs.

    The demand for power that has fueled the growth of the Hawaiian Islands has been met by Hawaiian Electric Companies for well over a century. And as the next millennium unfolds, the company is committed to providing quality service and seeking clean local energy sources to power generations of Hawaii families and businesses to come. Visit us at

    Interested individuals should apply online. The application must clearly indicate the demonstrated experience / knowledge / skills / abilities the candidate possesses which specifically qualifies him / her for the position.

    Applicant Certification

    By submitting an application for the position, candidates :

  • 1. Authorize the Hawaiian Electric Companies to confirm all statements contained in the application and / or any materials submitted and made a part of the application as they relate to the position and to the extent permitted by law;
  • 2. Authorize and consent to, without reservation, the Hawaiian Electric Companies sharing any and all information regarding previous or present employment, educational training or personal information from their records and from any other source with the hiring department or subsidiary company;
  • 3. Release, discharge, and hold harmless, Hawaiian Electric Companies, from any and all liability for any damage which may be claimed as a result of furnishing such information to the hiring department or subsidiary company;
  • 4. Authorizes release and transfer of all personnel records to be maintained by the hiring company in the event of an inter-company transfer; and

    5. Authorize, direct, and consent to Hawaiian Electric Companies and / or its authorized agents to conduct investigations into candidates' background. These investigations may include, but are not limited to searches for information about applicants; record of criminal convictions to the extent permitted by law, education records, professional certifications, personal character references, and employment history.

    EEO Statement Hawaiian Electric Companies is an equal opportunity employer, including disability and protected veteran status. Hawaiian Electric Companies complies with all applicable laws, including Title I of the Americans with Disabilities Act. Any request for reasonable accommodation needed during the application process should be communicated by the candidate to the HR Service Center at (808) 543-4848.

    Affiliate Disclaimer

    Hawaiian Electric Company, Inc., Maui Electric Company, and Hawaii Electric Light ("Company") are Hawaii Public Utilities Commission ("PUC") regulated companies. The disclosure relating to Affiliate Transaction Requirements that follows is made pursuant to the PUC's Decision and Order No. 35962, issued on December 19, 2018, and subsequently modified by Order No. 36112, issued on January 24, 2019 in Docket No. 2018-0065.

    By submitting your application, you understand and acknowledge that, if you are hired by the Company and subsequently transferred, assigned or otherwise employed by an Affiliate, said Affiliate will be required to make a one-time payment to the Company in an amount up to twenty-five percent (25%) of your base annual compensation.

    In addition, if you are hired by the Company and subsequently transferred, assigned or otherwise employed by an Affiliate or an Affiliate-Related Entity, for a period of one year, you cannot appear in negotiations or otherwise interact directly with the Company or work on the same matter that you worked on while with the Company.

    Affiliate is defined as "any person or entity that possesses an 'affiliate interest' in a utility as defined by section 269-19.5, Hawaii Revised Statutes ("HRS"), including a utility's parent holding company, except as otherwise provided by HRS section 269-19.5(h)."

    Affiliate-Related Entity is defined as "a third party that provides electricity-related services in a regulated utility's service territory that has a material financial, operational, or ownership interest with an unregulated affiliate of the utility and of whom the utility has reasonable knowledge."

    For a current list of all Affiliates and Affiliate-Related Entities, please see :

    This list may be amended, updated or revised from time to time without notice.

    Create a job alert for this search

    Information Assurance Analyst • Honolulu, HI, United States

    Related jobs
    Information Assurance (IA) Specialist

    Information Assurance (IA) Specialist

    Dunhill • Pearl City, HI, United States
    Permanent
    Information Assurance (IA) professional.Information Technology in Pearl City, Hawaii.The ideal candidate will hold a Bachelors degree and be passionate about information technology work.Responsibil...Show more
    Last updated: 1 day ago • Promoted
    Real Time Cyber Analyst

    Real Time Cyber Analyst

    The Newberry Group • Ford Island, HI, US
    Temporary
    Quick Apply
    Who We Are… Newberry Group is a performance-driven government services and solutions firm that provides security compliance, program governance, consulting, and customized solutions for publi...Show more
    Last updated: 30+ days ago
    Palo Alto Cybersecurity Engineer

    Palo Alto Cybersecurity Engineer

    Phase2 Technology • Honolulu, HI, United States
    Full-time
    Palo Alto Cybersecurity Engineer.Are you looking for a career-defining opportunity to share your expertise in designing, developing, and implementing innovative network security solutions to suppor...Show more
    Last updated: 30+ days ago • Promoted
    TMS Compliance QA Analyst IV

    TMS Compliance QA Analyst IV

    Hawaii Staffing • Honolulu, HI, US
    Full-time
    Join Coinbase's Compliance Operations Quality Assurance Team.Ready to be pushed beyond what you think you're capable of? At Coinbase, our mission is to increase economic freedom in the world.It's a...Show more
    Last updated: 6 days ago • Promoted
    Cyber Warfare Technician

    Cyber Warfare Technician

    U.S. Navy • Honolulu, HI, US
    Full-time +1
    To be eligible to enlist in the U.Navy, candidates must be between the ages of 18-34.As a Cryptologic Technician, you are one of the worlds greatest problem-solvers. Were looking for people with sha...Show more
    Last updated: 1 day ago • Promoted
    Countermeasures Detection Engineer

    Countermeasures Detection Engineer

    Leidos Inc • Pearl Harbor, HI, United States
    Full-time
    Leidos' Digital Modernization sector has a current job opportunity for a Defensive Cyber Operations (DCO) Counter-Measures Detection Engineer at Pearl Harbor JBPHH, HI. This position will support th...Show more
    Last updated: 4 days ago • Promoted
    37F PsyOp Specialist

    37F PsyOp Specialist

    US Army • Honolulu, Hawaii, US
    Permanent
    F PsyOp Specialist As a Psychological Operations Specialist, youll be an expert at persuasion.All potential candidates should read through the following details of this job with care before making ...Show more
    Last updated: 29 days ago • Promoted
    Forescout Cybersecurity Engineer

    Forescout Cybersecurity Engineer

    Phase2 Technology • Honolulu, HI, United States
    Full-time
    As a Forescout Cybersecurity Engineer on our team, you will work with an expert team focused on implementing and operating next-generation security solutions for government and commercial clients.Y...Show more
    Last updated: 30+ days ago • Promoted
    IT Auditor

    IT Auditor

    TEKsystems • Honolulu, HI, United States
    Full-time
    Under the direction of the Manager, this position is responsible for planning, directing, organizing and executing audits of Information Technology (IT) and Information Security (IS) functions of o...Show more
    Last updated: 6 days ago • Promoted
    BSD Fraud Analyst

    BSD Fraud Analyst

    First Hawaiian Bank • Honolulu, HI, United States
    Full-time
    Join the First Hawaiian Bank 'ohana, where our culture flourishes with purpose.We prioritize the 3 C's - Caring, Character and Collaboration - ensuring a workplace that is not only rewarding, but d...Show more
    Last updated: 1 day ago • Promoted
    Cybersecurity Engineer

    Cybersecurity Engineer

    Vets Hired • Honolulu, Hawaii, United States
    Full-time
    Quick Apply
    Experience preparing, implementing, and ensuring compliance with cybersecurity policy, including Assessment and Authorization requirements. Planning, implementing, upgrading, and / or monitoring cyber...Show more
    Last updated: 30+ days ago
    Cyber Warfare Technician

    Cyber Warfare Technician

    US Navy • Honolulu, Hawai, United States
    Part-time
    Languages are more than just communication-they're cultural codes that need to be analyzed and in some cases, broken.As a Cryptologic Technician Interpretive (CTI) you're more than a linguist-you'r...Show more
    Last updated: 30+ days ago • Promoted
    Cyber Intrusion Analyst

    Cyber Intrusion Analyst

    Leidos Inc • Pearl Harbor, HI, United States
    Full-time
    Leidos has several career opportunities for Cyber Intrusion Analysts who will be members of the Network Assurance (NA) Team (DISA GSM-O program) in Pearl Harbor, Hawaii. We support 24 / 7 operations a...Show more
    Last updated: 30+ days ago • Promoted
    CI-HUMINT Analyst

    CI-HUMINT Analyst

    Core One • Honolulu, HI, US
    Full-time
    Join our team at Core One! Our mission is to be at the forefront of devising analytical, operational and technical solutions to our Nation's most complex national security challenges.In order to ac...Show more
    Last updated: 30+ days ago • Promoted
    Military Intelligence Officer

    Military Intelligence Officer

    U.S. Navy • Kailua, HI, US
    Full-time +1
    To be eligible to enlist in the U.Navy, candidates must be between the ages of 18-34.These careers bring the expertise in all facets of Information Operations, making sure our fleet is capitalizing...Show more
    Last updated: 1 day ago • Promoted
    Bomb Technical

    Bomb Technical

    U.S. Navy • Waimanalo, HI, US
    Full-time +1
    To be eligible to enlist in the U.Navy, candidates must be between the ages of 18-34.Americans live for fireworks on the Fourth of July. The other 364 days of the year, Explosive Ordnance Disposal (...Show more
    Last updated: 1 day ago • Promoted
    37F PsyOp Specialist

    37F PsyOp Specialist

    U.S. Army • Honolulu, Hawaii, US
    Permanent
    F PsyOp Specialist As a Psychological Operations Specialist, you'll be an expert at persuasion.You'll assess and develop the information needed to influence and engage specific audiences.You'll bro...Show more
    Last updated: 30+ days ago • Promoted
    Splunk Cybersecurity Engineer

    Splunk Cybersecurity Engineer

    Phase2 Technology • Honolulu, HI, United States
    Full-time
    The Opportunity : Warnings about cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to the intelligence community.In all ...Show more
    Last updated: 30+ days ago • Promoted