IT Security Analyst I, II
TEP Tucson Electric Power Company · Tucson, AZ, United States
About The Role
We are looking for talented individuals who are passionate about making an impact in the company and the community. Apply now and become part of the dynamic energy industry!
Help protect the systems that power our communities.
At TEP, cybersecurity is more than protecting technology. It's about safeguarding the critical infrastructure that delivers safe, reliable energy to homes, businesses, and essential services across Arizona. As an IT Security Analyst, you'll play a key role in defending our networks, systems, and information assets against evolving cyber threats while helping ensure the reliability of services our customers depend on every day.
What You Will Do
- Protect critical infrastructure by administering and securing enterprise systems, applications, databases, networks, and user access.
- Monitor security events, investigate suspicious activity, and respond to cybersecurity incidents and forensic investigations.
- Conduct vulnerability, risk, and security assessments to identify threats and strengthen our security posture.
- Evaluate and implement emerging security technologies that improve the protection of company assets and operations.
- Support compliance and regulatory initiatives, including NERC CIP, SOX, HIPAA, PCI DSS, and other security requirements.
- Partner with IT teams, business leaders, vendors, and project teams to embed security into technology solutions across the organization.
What You Bring
- High school diploma or GED required; Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field preferred.
- Experience supporting information security, network administration, systems administration, or a related IT discipline.
- Knowledge of security technologies such as identity and access management, SIEM, firewalls, malware protection, encryption, and vulnerability management.
- Understanding of incident response, threat detection, risk assessment, and security best practices.
- Strong problem-solving, communication, and teamwork skills with the ability to thrive in a rapidly evolving environment.
- For Level II consideration: 3-5 years of relevant security or network experience and industry certifications such as CISSP, GSEC, or equivalent experience.
Position Description
Responsible for the design, planning, testing, implementation, and administration of regulatory requirements and industry-wide accepted information security principles, practices, and information systems to ensure the protection of information assets processed, stored, or transmitted at UniSource. Evaluate the effectiveness of information security solutions and processes in place, keeping in mind the state of world events. Monitor for and identify security risks and exposures, determine the causes of security violations, assess, and implement procedures to halt future incidents. Understand and provide assistance to system users relative to information systems security matters. Participates in a team environment that provides cost-effective IT security services to the various business units. Works closely with other areas to insure optimum reliability and cohesiveness.
Position-Related Responsibilities
- Responsible for day-to-day security administration of company databases (e.g. Oracle and MSSQL), e-mail applications, key business applications and networks
- Responsible for provisioning and de-provisioning users
- Performs security incident response and forensic investigations
- Evaluates new and emerging security technologies, features, and products to determine their application in the protection of company information assets
- Performs security analysis, including architecture review, baselines, vulnerability assessments, and risk assessments to proactively identify security risks and exposures
- Monitors security events across the network and ensures alerting and resolution of security issues and threats.
- Provides anti-virus, spam, and malware administration and management.
- Provides second-level support for the IT Help Desk. Performs 24 x7 support on a rotating basis.
- Ensures change control processes are followed and service levels affected by those changes are maintained.
- Works with internal and external project managers to complete projects and efforts on time.
- Leads or participates in IT projects to provide information security expertise, guidance, or training.
- Works with internal and external auditors to implement technical aspects of regulatory/compliance/privacy controls, such as Sarbanes-Oxley, NERC CIP, HIPAA, and PCI DSS.
- Works with Human Resources or Legal to provide sensitive investigative or litigation hold support.
- This position may provide services to affiliates of the Company subject to the UNS Energy Code of Conduct and the related Policies and Procedures.
- Knowledge is expected in the following disciplines:
- Authentication and Access Control Tools, Management and Administration
- Anti-Virus, Spam and Malware Tools, Management and Administration
- Application Security Architecture & Cloud Computing Concepts
- Change & Security Configuration Audit and Control
- Encryption Processes, Management and Administration
- Firewall Management and Administration
- Hardware/software Security Testing and Evaluation
- Intrusion Detection/Prevention
- Incident Response Practices and Procedures
- Computer Forensic Practices and Procedures
- Layer 2 and 3 routing and switching protocols (TCP/UDP, IPv4, IPv6, OSPF, etc.)
- Security Information & Event Management (SIEM) and Logging
- Scripting Languages, such as PowerShell
- VOIP Technology Security
- VPN’s (Virtual Private Networks) and SSL
- Vulnerability Assessment Practices/Technology (i.e. Operating Systems, Network, Application, Database, and Web)
- Wireless Security Infrastructure
- Security Industry Standards, such as ISO, NIST & FISMA
- Regulatory Requirements of NERC CIP, SOX, HIPAA, PCI DSS and other applicable regulations
- Information Security Awareness Programs and Communications
- Information Security Policy and Standards
- Information Security Risk Assessment
Knowledge, Skills & Abilities
(Equivalent combination of education and experience will be considered.)
Level I - Minimum Qualifications
- High school diploma or GED.
- Effective written and oral communication skills are required plus a willingness to learn in a rapidly changing environment.
- Demonstrated ability to work both independently and as part of a team.
Preferred Qualifications
- Bachelor’s degree in Management Information Systems, Computer Science or related discipline is preferred.
- Two or more years in an IT related discipline is preferred.
Level II - Minimum Qualifications
- Requires the qualifications for an IT Security I plus experience with day to day security administration.
- Requires self-direction and the ability to work with vendors on creating statements of work and completing that work.
- Requires Industry certifications (i.e. GSEC or CISSP) or equivalent experience of 3-5 years in an information security or network discipline.
Preferred Qualifications
- Assists more experienced administrators on projects and deals with day to day support.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
