Information Security Analyst Senior

Entergy Corporation
The Woodlands, TX, United States
3 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Information Leak Prevention Linux Perl (Programming Language) Supervisory Control and Data Acquisition (SCADA)
+20 more
Identity and Access Management Python (Programming Language) Open Web Application Security Cloud Services Secure Coding Software Vulnerability Management Web Applications Scripting Software Security Test Scripts Cyber Threat Analysis HybridCloud Information Technology Graphql CIS Benchmarks Static Application Security Testing Vulnerability Analysis Web Api Microservices Dynamic Application Security Testing

Job description

As a Senior Threat and Vulnerability Management (TVM) Analyst, you will design, configure, and support the TVM Team in identifying, assessing, and remediating technical vulnerabilities across a global enterprise IT and OT infrastructure. You will be responsible for executing automated scans, prioritizing risks based on business impact, and collaborating with owners to track the timely patching of assets and applications. This role offers an advanced opportunity to exercise your expertise in risk analysis and security tooling within a complex, high-scale environment., * Scan All Assets : Run vulnerability scans across corporate networks, OT environments, web applications, APIs, and public/hybrid cloud infrastructure.

  • Audit Cloud Security : Continuous assessment of cloud workloads, identities, storage buckets, and configurations to detect security drift and misconfigurations.
  • Test Code & APIs : Perform Static (SAST) and Dynamic (DAST) application security testing, and audit API endpoints for data leakage and authentication flaws.
  • Filter Flaws : Eliminate false positives to isolate true risks threatening energy delivery systems, customer portals, and critical cloud infrastructure.
  • Assess Risk : Prioritize vulnerabilities using Threat Intelligence, CVSS scores, OWASP Top 10, OWASP API Security Top 10, and cloud-specific threat matrices.
  • Guide Remediation : Provide clear mitigation steps to IT engineers, substation OT technicians, software developers, and cloud infrastructure teams.
  • Ensure Compliance : Map vulnerability data directly to NERC CIP (including cloud-hosted BCSI requirements) and the NIST Cybersecurity Framework.
  • Report Risks : Draft executive risk reports, secure software metrics, and cloud compliance posture charts for leadership and federal regulatory auditors.

Requirements

  • Industry Experience : 5+ years in cybersecurity, with a preferred 2 years protecting a large enterprise with exposure to energy, utility, or industrial environments.
  • Technical Knowledge : Strong understanding of traditional Windows and Linux enterprise deployments, SCADA networks, PLC systems, microservices architectures, REST/GraphQL APIs, Cloud Security Posture Management (CSPM), Infrastructure as Code (IaC) security, and cloud identity management (IAM).
  • Tool Proficiency : Mastery of vulnerability management tools, application security tools, and native cloud security CNAPP tools. Experience with scripting languages such as Perl or Python. Ability to leverage Artificial Intelligence (AI) to solve problems or automate work processes.
  • Regulatory Compliance : Practical knowledge of NERC CIP, NIST CSF, CIS Benchmarks, and secure coding standards.
  • Clear Communication : Ability to bridge the gap between corporate IT security, cloud architects, software developers, and field-level engineering constraints.
  • Certifications : Preferred credentials include CISSP, GICSP, GRID, CSSLP, CCSP, AWS Certified Security, or Microsoft Certified: Azure Security Engineer.
  • Proficiency : Capable of managing multiple tasks and meeting deadlines. Ability to work well independently or with a team.

Education required

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent practical experience).

About the company

Additional Responsibilities: As a provider of essential services, Entergy expects its employees to be available to work additional hours, to work in alternate locations, and/or to perform additional duties in connection with storms, outages, emergencies, or other situations as deemed necessary by the company. Exempt employees may not be paid overtime associated with such duties., As a provider of essential services, Entergy expects its employees to be available to work additional hours, to work in alternate locations, and/or to perform additional duties in connection with storms, outages, emergencies, or other situations as deemed necessary by the company. Exempt employees may not be paid overtime associated with such duties.

Please note: Authorization to work in the United States is a precondition to employment in this position. Entergy will not sponsor candidates for work visas for this position.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

9:56 min

Expanding browser capabilities with modern web APIs

Ire Aderinokun · JS Congress

2:52 min

Generating APIs with the Neo4j GraphQL library

William Lyon · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all