ISO New England Inc logo

Senior Cybersecurity Analyst

ISO New England Inc
  • Holyoke, MA
  • $135,000–$168,000 Per Year
6 days ago

Job Description

ISO New England is the independent system operator responsible for ensuring the safe and reliable flow of electricity in our region and planning for the future of the electric grid. We are at the forefront of New England's ongoing transition to clean energy.

ISO New England is seeking an experienced Cybersecurity Analyst to support and enhance enterprise cloud, infrastructure, AI, and DevSecOps security initiatives. This role is responsible for advancing the organization's cybersecurity strategy by facilitating cross-functional collaboration to strengthen technical security, governance, risk management, and regulatory compliance. The position provides technical leadership and cybersecurity expertise to support evolving business objectives while addressing emerging cyber threats across enterprise, cloud, AI, DevSecOps, and regulated environments. Working closely with internal stakeholders, the role drives security initiatives, influences technical decisions, and promotes a culture of security, resilience, and continuous improvement.

The ideal candidate will have strong experience in cloud security, vulnerability management, DevSecOps, AI security, network security and security compliance, with the ability to collaborate across technical teams to implement and maintain enterprise security standards

What we offer you:

  • A stable, mission-driven workplace where your impact truly matters

  • A highly engaged work environment that values inclusion, collaboration, and employee safety and wellbeing

  • Competitive compensation with a base salary + performance bonus

  • Robust benefits package, including:

  • Enhanced 401(k) and financial planning support

  • Tuition reimbursement and professional development

  • Wellness programs, including an onsite gym

  • Flexible work hours

  • Employee Business Networks

  • Free coffee at our onsite café

  • Hybrid work environment (3 days/week onsite)

  • Distance-based relocation assistance available

How you will make an Impact

  • Develop and implement enterprise cybersecurity strategies aligned with business objectives, regulatory requirements, and industry best practices.
  • Ensure compliance with cybersecurity frameworks and regulations including NERC CIP, NIST frameworks, CIS controls, FERC regulations, and SOC1/SOC2 requirements.
  • Implement enterprise security controls across cloud, infrastructure, applications, AI/ML environments, and regulated operational technology (OT) systems.
  • Conduct cloud security assessments across AWS and Azure environments, including IAM, CSPM, CIEM, container security, and configuration management.
  • Integrate security controls throughout CI/CD pipelines and DevSecOps processes, including automated vulnerability scanning, Infrastructure-as-Code (IaC) validation, and policy enforcement.
  • Assess and secure AI/ML systems, Generative AI applications, and Large Language Model (LLM) integrations through governance, access controls, data protection, prompt security, and AI threat modeling.
  • Perform vulnerability assessments, network security assessments, configuration reviews, compliance validation, risk assessments, and remediation tracking across enterprise and cloud environments.
  • Support enterprise security monitoring, logging, threat detection, incident response, and audit evidence collection using SIEM, EDR/XDR, CNAPP, DSPM, vulnerability management, and related security platforms.
  • Collaborate with cloud, infrastructure, application development, enterprise architecture, IAM, network, compliance, and business teams to integrate security into system design and operational processes.
  • Identify, assess, prioritize, and communicate cybersecurity risks while developing effective mitigation strategies.
  • Develop and maintain security policies, standards, governance documentation, compliance reporting, and security best practices.
  • Monitor emerging cybersecurity threats, AI security risks, industry trends, and regulatory changes to continuously enhance the organization's security posture.
  • Provide technical mentorship, and cross-functional guidance while promoting cybersecurity awareness, operational excellence, and secure technology adoption.

What we are looking for

  • 5+ years of experience in cybersecurity, security engineering, or AI security roles.
  • 3+ years of security experience in AWS and/or Azure cloud platforms.
  • Experience designing and implementing enterprise security solutions across cloud, infrastructure, applications, and hybrid environments.
  • Hands-on experience with AWS and/or Azure cloud platforms, including IAM, CSPM, CIEM, container security, and cloud security best practices.
  • Experience integrating security controls into CI/CD pipelines and DevSecOps environments.
  • Knowledge of AI security concepts, including Generative AI, LLM security, AI governance, and AI risk management.
  • Experience performing vulnerability management, security assessments, configuration reviews, threat modeling, and cybersecurity risk assessments.
  • Knowledge of enterprise security technologies including SIEM, EDR/XDR, CNAPP, DSPM, vulnerability management, identity and access management, encryption, and security monitoring platforms.
  • Familiarity with cybersecurity frameworks and regulatory standards including NERC CIP, NIST Cybersecurity Framework, NIST Special Publication 800 Series, ISO 27001, CIS Controls, and applicable regulatory requirements.
  • Strong analytical, troubleshooting, communication, documentation, and cross-functional collaboration skills.
  • Ability to manage multiple priorities independently while providing technical leadership and driving continuous security improvements.
  • Experience with API security practices, including secure API design, authentication and authorization mechanisms, access control, encryption, and protection against API-based threats.

Desired not required

  • 5+ years of cybersecurity experience.
  • Bachelor's degree in information technology, Cybersecurity, Computer Science, or related field.
  • Advanced degree such as a Master's in Cybersecurity Management, Information Assurance, Artificial Intelligence, or related field.
  • Industry cybersecurity, cloud security, and AI security certifications, including:
  • ISC2 Certified Information Systems Security Professional (CISSP)
  • ISACA Certified Information Security Manager (CISM)
  • Amazon Web Services Certified Security - Specialty
  • Microsoft Azure Security Engineer Associate (AZ-500)
  • ISC2 Certified in AI Security (when available)
  • OWASP AI Security and LLM Security knowledge/training

This employer will not sponsor applicants for work visas for this position (ex: H-1B, F-1/CPT/OPT, O-1, E-3, TN, J, etc.).

The expected salary range for this position is $135,000 - $168,000 per year. This role is also eligible for an annual performance bonus, comprehensive health insurance (medical, dental and vision), flexible spending and health savings accounts, a 401(k) plan with generous employer contributions and a student debt benefit, life and AD&D insurance, disability insurance, critical illness and hospital indemnity benefits, paid time off, paid leave, a wellness program, an employee assistance program and other great company perks.

#LI-HYBRID

This is a U.S. based role. If the successful candidate resides outside of the U.S., relocation will be required.

Equal Opportunity: We are proud to be an EEO employer. Applicants for employment are considered without regard to race, color, religion, creed, sex (including pregnancy, childbirth, and related medical conditions), gender identity or expression, sexual orientation, citizenship, national origin, age, ancestry, marital status, disability (including learning, mental, intellectual, and physical), service in the uniformed services, genetic information, or any other status protected by applicable law.

Drug Free Environment: We maintain a drug-free workplace and perform pre-employment substance abuse testing.

Numbers & Facts

LocationHolyoke, MA
IndustryEnergy and Utilities
Salary$135,000–$168,000 Per Year
Company Size1,000 to 1,499 employees
Year Founded1996
Websitehttps://www.iso-ne.com/

About Company

ISO New England helps protect the health of New England's economy and the well-being of its people by ensuring the constant availability of electricity, today and for future generations. ISO New England meets this obligation in three ways: by ensuring the day-to-day reliable operation of New England's bulk power generation and transmission system, by overseeing and ensuring the fair administration of the region's wholesale electricity markets, and by managing comprehensive, regional planning processes.

Skills

  • Access Authorizationunmatched
  • Access Controlunmatched
  • Alternative Energyunmatched
  • Amazon Web Services (AWS)unmatched
  • Analysis Skillsunmatched
  • Application Programming Interface (API)unmatched
  • Artificial Intelligence (AI)unmatched
  • Authenticationunmatched
  • Best Practicesunmatched
  • Business Supportunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Computingunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Configuration Managementunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Improvementunmatched
  • Continuous Integrationunmatched
  • Cross-Functionalunmatched
  • Cryptographyunmatched
  • Documentationunmatched
  • Electricityunmatched
  • Enterprise Architectureunmatched
  • Enterprise Protectionunmatched
  • Establish Prioritiesunmatched
  • Financial Planningunmatched
  • ISACA (Information Systems Audit and Control Association)unmatched
  • ISO (International Organization for Standardization)unmatched
  • Identify Issuesunmatched
  • Identity Data Managementunmatched
  • Incident Responseunmatched
  • Industry/Trade Analysisunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • International Information Systems Security Certification Consortium (ISC)2unmatched
  • Internet Securityunmatched
  • Maintain Complianceunmatched
  • Mentoringunmatched
  • Microsoft Windows Azureunmatched
  • Model Reviewunmatched
  • Modeling Languagesunmatched
  • Multitaskingunmatched
  • Network Performance/Analysisunmatched
  • Network Securityunmatched
  • Operations Processesunmatched
  • Process Improvementunmatched
  • Publicationsunmatched
  • Regulationsunmatched
  • Regulatory Complianceunmatched
  • Regulatory Requirementsunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Security Analysisunmatched
  • Security Attacksunmatched
  • Security Complianceunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Infrastructureunmatched
  • Security Monitoringunmatched
  • Security System Designunmatched
  • Software Developmentunmatched
  • Strategic Planningunmatched
  • System Integration (SI)unmatched
  • System Operationsunmatched
  • Team Playerunmatched
  • Technical Leadershipunmatched
  • Threat Modelingunmatched
  • Threat and risk analysis (TRA)unmatched
  • Tuition Reimbursementunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Vulnerability Scannersunmatched
  • WS-Security (Web Services Security)unmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder