Sr Cyber Security Vulnerability Management Analyst

Constellation Energy Generation, LLC.
  • Baltimore, Maryland
  • Full-time
2 days ago

Job Description

Overview:

Who We Are

As the largest private-sector power producer in the world and the nation's largest producer of clean and reliable energy, Constellation is focused on our purpose: lighting the way to a brilliant tomorrow for all. We have been the leader in clean energy production for more than a decade, and we are cultivating a workplace where our employees can grow, thrive, and contribute. Now integrated with Calpine, our portfolio includes 55 gigawatts of capacity from nuclear, natural gas, geothermal, hydro, wind and solar facilities, with the generating capacity to power the equivalent of 27 million homes.

Our culture and employee experience make it clear: We are powered by passion and purpose. Together, we're creating healthier communities and a cleaner planet, and our people are the driving force behind our success. At Constellation, you can build a fulfilling career with opportunities to learn, grow and make an impact. By doing our best work and meeting new challenges, we can accomplish great things. Join us in meeting the country's energy needs today and tomorrow.


Total Rewards

Constellation offers an extensive selection of benefits and rewards to help our employees thrive professionally and personally. We provide competitive compensation and a wide-range of benefits that support both employees and their families, helping them prepare for the future. In addition to highly competitive salaries, eligible employees are offered a bonus program, 401(k) with company match, employee stock purchase program; comprehensive medical, dental and vision benefits, including robust wellbeing programs; disability and life insurance benefits; paid time off for vacation, holidays, and sick days; and much more.

Expected salary range of $123,300 to $137,000, varies based on experience, along with comprehensive benefits package that includes bonus and 401(k).

Responsibilities:

Primary Purpose of Position

The Senior Cyber Security Vulnerability Management Analyst will be expected to conduct formal tests on web-based applications, networks, and other types of computer systems on a regular basis and determines/documents deviations from approved configuration standards and/or policies. This role will also be expected to work on physical security assessments of servers, computer systems, and networks. Along with these tests and assessments, this role will conduct regular security vulnerability assessments, scans from both a logical/theoretical standpoint and a technical/hands-on standpoint and recommend appropriate mitigations and/or remediation efforts. This role will enhance security services provided by the Cyber Vulnerability Detection and Management team. This is a hands-on role requiring expert technical skills across a wide range of IT/OT systems, applications, and infrastructure.

 

Primary Duties and Accountabilities

  • Performing security architecture reviews of applications in design and production phases.
  • Identifying security recommendations, potential threats and attacks to applications systems through threat modeling and vulnerability assessment.
  • Consulting with developers on integrating security processes and tools into DevOps processes
  • Working with application development teams to develop solutions to remediate security vulnerabilities.
  • Improving secure coding practices, application security requirements, automation, training and metrics.
  • Maintaining an active understanding of industry practices for secure software development.
  • Play an active role in counseling and mentoring junior Cybersecurity team members.
  • Understanding of or experience in Agile Development Environment.
  • Problem solving and troubleshooting with eye for details
  • Good communication and presentation skills
  • Ability to work in a diverse environment (internal/external).
  • Proven ability to work as DevSecOps practioner
  • Design automation workflows and capabilities in support of data collection, investigation and incident response
  • Develop threat hunting and data analysis strategy and capabilities
  • Identify and propose new technologies, methodologies and/or approaches to detecting malicious activity
  • Utilizes appropriate OD models, resources, and systematic approaches to facilitate initiatives that enhance organizational effectiveness.
  • Design, build, configure, maintain and monitor cybersecurity threat defense capabilities and user access management

Minimum Qualifications

  • Bachelor's degree in Information Systems with 5-years' experience, in lieu of degree 9-years' experience
  • Experience in performing application security vulnerability assessment using either manual penetration testing and source code techniques or automated commercial SAST/DAST/IAST/SCA/OSA tools.
  • Proven skill in data architecture, modeling, and solution implementation
  • Experience in evaluating application security programs for clients and developing key elements of the program as part of the enhancement process and developing internal vulnerability assessment and management processes
  • Ability to learn and adapt to integrate application security to different CI/CD systems and apply automation as needed
  • 2-years of experience working in Agile development, application security, or DevOps role, with experience in the following technologies:
  • Containers (Docker, Kubernetes, etc.)
  • Infrastructure as code (Chef, Terraform, etc.)
  • Continuous integration (Jenkins, Github, TeamCity etc.)
  • Integration of Security testing tools like Fortify, ShiftLeft, Check Marx, Invicti, WhietSource into pipeline
  • Defect tracking (Jira, ServiceNow etc.)
  • Source code management (GitLab, GitHub, BitBucket, etc.)
  • Developing enterprise applications or scripts for security testing (security as code)
  • Cloud environment (AWS, Azure, GCP) and various Unix-like distributions
  • Knowledge of networking, infrastructure and applications from a DevOps perspective with a security focus
  • Experience with scripting languages
  • Broad knowledge of security control techniques and how they can be applied in a traditional IT environment as well as cloud-based systems
  • Good technical knowledge of Microservice oriented solutions, APIs, Azure AD and common cloud authentication patterns
  • Security Cert (Sec +, CEH, CCSP, GSEC)

 

Qualifications:

Preferred Qualifications

  • Cloud DevOps Certification (Azure, GCP, AWS)
  • Graduate degree in cyber security or related area of expertise.
  • Relevant security certifications (CISSP, CISM, OSCP, GIAC).
  • Demonstrated technical skills with various penetration testing technologies and tools.
  • Demonstrated experience and subject matter knowledge in cyber security for applications, web architectures, operating systems, databases, and networks.
  • Demonstrated experience and subject matter knowledge of SCADA, ICS, Distribution Automation, Smart Grid, DMS, and ECS systems architecture
  • Demonstrated experience and proven capabilities in network vulnerability assessment, application vulnerability assessment, application security architecture development, web application security, and application security testing
  • Demonstrated experience in addressing regulatory compliance for the security requirements in applicable laws and regulations, such as NERC CIP, SOX, PCI DSS, and HIPAA
  • Solid understanding and experience with security development lifecycle (SDL) processes for internally developed applications, including the web based and Internet facing components.
  • Knowledge and experience in application security standards, methodologies, and technologies
  • Solid capability to assess network architectures and operating systems for vulnerabilities and develop appropriate security countermeasures.
  • Solid knowledge and experience with IT security aspects of operating systems, Active Directory, database (SQL) access, LDAP, Microsoft SharePoint, and web server configurations
  • Demonstrated experience in assessing and testing security applications and systems, such as Cisco firewalls, security appliances, IDS/IPS, SSL or TLS, IPSec, and web services security
  • Ability to demonstrate analytical skills, technical knowledge, and practical application of cyber and information security principles to business leaders and technical staff

Numbers & Facts

LocationBaltimore, Maryland
Job TypeFull-time

Skills

  • Agile Programming Methodologiesunmatched
  • Alternative Energyunmatched
  • Amazon Web Services (AWS)unmatched
  • Analysis Skillsunmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • Architectural Analysisunmatched
  • Atlassian JIRAunmatched
  • Authenticationunmatched
  • Automationunmatched
  • Bug Tracking/Defect Managementunmatched
  • CCSP - Cisco Certified Security Professionalunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cisco Network Systemsunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Computer Hackingunmatched
  • Computer Networksunmatched
  • Computer Securityunmatched
  • Computer Serversunmatched
  • Computer Systemsunmatched
  • Consultingunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Integrationunmatched
  • Cook Dishesunmatched
  • Data Analysisunmatched
  • Data Collectionunmatched
  • Data Modelingunmatched
  • DevOpsunmatched
  • Digital Certificatesunmatched
  • Dockerunmatched
  • Enterprise Applicationsunmatched
  • Firewall Appliancesunmatched
  • GCP (Good Clinical Practices)unmatched
  • GIAC - Global Information Assurance Certificationunmatched
  • GSEC - GIAC Security Essentials Certificationunmatched
  • GitHubunmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • Huntingunmatched
  • IPsec (IP Security)unmatched
  • Identify Issuesunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internet Applicationunmatched
  • Internet Securityunmatched
  • Intrusion Detection Systemsunmatched
  • Intrusion Prevention Systemsunmatched
  • Jenkinsunmatched
  • LDAP (Lightweight Directory Access Protocol)unmatched
  • Mentoringunmatched
  • Microservicesunmatched
  • Microsoft Access Databaseunmatched
  • Microsoft Active Directoryunmatched
  • Microsoft SharePointunmatched
  • Microsoft Windows Azureunmatched
  • Natural Gasunmatched
  • Network Architecture/Engineeringunmatched
  • Network Performance/Analysisunmatched
  • Network Securityunmatched
  • Operating Systemsunmatched
  • Organizational Development/Managementunmatched
  • PCI-DSSunmatched
  • Penetration Testingunmatched
  • Physical Securityunmatched
  • Power Generationunmatched
  • Presentation/Verbal Skillsunmatched
  • Problem Solving Skillsunmatched
  • Product Lifecycleunmatched
  • Program Evaluationunmatched
  • Protective Servicesunmatched
  • Regulationsunmatched
  • Regulatory Complianceunmatched
  • SDL (Specification and Description Language)unmatched
  • SQL (Structured Query Language)unmatched
  • SSL-TLS (Secure Socket Layer - Transport Layer Security)unmatched
  • Sarbanes-Oxley Act (SOX)unmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Complianceunmatched
  • ServiceNowunmatched
  • Smart Gridunmatched
  • Software Designunmatched
  • Software Developmentunmatched
  • Software Testingunmatched
  • Source Code/Configuration Management (SCM)unmatched
  • Supervisory Control and Data Acquisition (SCADA)unmatched
  • System Architectureunmatched
  • Systems Administration/Managementunmatched
  • Team Playerunmatched
  • TeamCityunmatched
  • Test Scriptsunmatched
  • Test Toolsunmatched
  • Testingunmatched
  • Threat Modelingunmatched
  • Vulnerability Scannersunmatched
  • WS-Security (Web Services Security)unmatched
  • Web Programmingunmatched
  • Web Serverunmatched
  • Web Testingunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder