The primary responsibility of the Information Security Specialist is to develop, monitor, audit and improve information security compliance programs to maintain the integrity of enterprise systems, files and data elements.
Specific Responsibilities:
- Designs and delivers security awareness and compliance training programs to NYISO employees
- Recognize and identify potential areas where existing information security policies and procedures require change and where new ones need to be developed, especially regarding business process changes
- Provide management with risk assessments and security briefings to advise them of critical issues that may affect customer or corporate security objectives
- Act on security violations; participate as a member or leader of Security Incident Response Team.
- Participate in information system auditing.
- Analyze and interpret regulatory compliance standards
- Develop and revise policies to ensure compliance with NYISO Security Policy, NERC Critical Infrastructure Protection (CIP) Standards and other security policy-setting organizations such as Department of Energy (DOE) and Department of Homeland Security (DHS); Participate on external committees such as NERC CIP Standards Committee and FBI InfraGuard.
Experience/Skills:
- 5+ years experience progressively more responsible IT Security experience with 3 years of policy and/or compliance experience
- Experience with the complex IT and infrastructure systems and IT-dependent enterprises required
- Experience in the energy, utility industries or government information assurance compliance initiatives
- Experience as an analyst or auditor on regulatory compliance such as CIP, SAS 70, SOX or other regulatory compliance systems
- Understanding of host and network intrusion detection and monitoring principles. Demonstrated ability to troubleshoot and affect minor repairs to Integrated Security Management Systems
- CISSP, CISA or CISM certification preferred
- Secret Clearance or above preferred
Education:
Bachelor's Degree (BS) Information Systems, Law, Law Enforcement, Criminal Justice or similar field
Candidates with an equivalent combination of education, training and experience will be considered
Position may be filled at various levels depending on candidate qualifications such as experience and technical skills.
NYISO is an equal opportunity employer