Share this Job

Threat Intelligence - Senior Cybersecurity Analyst

Apply now »

Date: Jul 23, 2022

Location(s): West Palm Beach, FL, US, 33407

Company: NextEra Energy

Requisition ID:  63435 

 

Our reliability is one of the best in the nation, and we’re working to make it even better. We live here too. That’s why we’re committed to making Florida a better place. Join our team today Learn more

 

Position Specific Description

As a Senior Cybersecurity Analyst, team members work for NextEra’s Threat Defense Services (TDS) team.  Team members are expected to provide daily support related to the collection and analysis of prioritized and commodity threats that may pose a risk to NextEra Energy. The Senior CTI position is primarily responsible for the daily scoping of threats to the Energy and Critical Infrastructure sector, including, but not limited to, performing tasks such as malware review and classification, daily reporting to the company’s senior leaders and executives, infrastructure enumeration, and creating rulesets to identify new activity. 

 
Team members work closely with fellow threat analysts and researchers across NextEra’s Advanced Cyberdefense Center (ACC) to analyze and attribute malicious cyber activity to known or suspected cyber threat actors and malware variants. Team members participate in monthly and ad-hoc operations meetings of threat actor activity to inform broader stakeholders of observed trends. Team members are strongly encouraged to execute due diligence of all TDS operations. For example, team members should identify areas for process improvement and collaborate with other cross-functional teams to automate and streamline new or existing workflows.  


TDS needs someone who is always ready to get involved in any challenge and work to build solutions.


Responsibilities

  • Perform day-to-day functions of the Cyber Threat Intelligence team to monitor, track and analyze Threat Actor Groups and emerging threats in service of the defense of the enterprise.
  • Understand the sophisticated threats that NextEra Energy may be exposed to and lead dissemination of that information, in a pragmatic way          
  • Maintain team resources to support business & operational needs
  • Establish and sustain service level goals with key business partners while seeking opportunities to improve upon them
  • Raise issues to leadership in a timely manner with appropriate information regarding risk, action times, and root cause analysis
  • Develops program metrics and reporting frameworks, compiles, and analyzes data for accurately timely reporting of activity
  • Drive prioritization and focus across various cross-functional service areas to provide useful intelligence
  • Establish and maintain relationships with industry partners to continuously improve NextEra’s defensive posture
  • Define strengths you'll need from intelligence and hunt practitioners to ensure continuous development of internal resources
  • Build technical briefs, reports, and single-source of record
     

Requirements

  • At least 5 years’ experience developing and/or operating on a threat intelligence, incident response, or similar team (4-year degree or equivalent experience)
  • Highly effective and proven in engaged with senior leaders and executives, successfully translating technical and ambiguous matters to business applicable 
  • Ability to build positive relationships internally and externally, in-person and virtually
  • Understanding of the analytical mapping methods (MITRE ATT&CK Framework and/or the Cyber Kill Chain, Diamond, ACH)
  • Demonstrated ability to identify, coordinate and respond to security incidents using commercial and/or open-source technologies.
  • Experience with Incident Response methodology in investigations, and the groups behind targeted attacks and tactics, techniques, and procedures (TTPs)
  • Strong ability to summarize events/incidents effectively to different constituencies such as legal counsel, executive management, and technical staff, both in written and verbal forms.
  • Experience using various digital investigation tools (e.g. VirusTotal, RiskiQ, Team Cymru, TITAN, RecordedFuture)
  • Refined and tested problem-solving skills and experience
  • Ability to persuade and/or negotiate desired outcomes
  • Strong technical understanding of IT fundamentals and core cybersecurity related principals (e.g., networking, OSI model, operating system internals, malware, attack chains, etc.)
  • Ability to leverage NetFlow and other network-related telemetry to identify and track potential threats.
  • Demonstrated analytical and critical thinking skills, ability to analyze a wide source of disparate data and extract meaningful relationships and conclusions based on the data. 

Job Overview

This job performs ongoing cybersecurity risk reviews for new and existing technologies and services and supports ongoing and new cybersecurity projects.  Individuals develop requirements for and implement technical security projects and tools, as well as define the company’s cybersecurity policies and control framework.  This position collaborates with the company’s IT department and business units to identify the need for, select, and deploy technical controls to meet specific security requirements. Employees in this role build processes and standards to ensure security requirements continue to be met.

Job Duties & Responsibilities

  • Administers, operates and monitors NextEra Energy (NEE) information security sensors, logging, alerting and other detection mechanisms to identify and respond to threats
  • Acts as subject matter expert for one or multiple assigned cybersecurity technology stacks (e.g., identity and access management, network intrusion detection and prevention, host based security tools)
  • Collaborates with security architecture to identify, evaluate and recommend new security technologies for suitability within NEE’s environment and security posture
  • Communicates ongoing cybersecurity activities, priorities and risk measurements or mitigations at multiple organizational levels
  • Provides guidance for security activities and requirements in the system development life cycle (SDLC) and application development efforts. Participates in organizational projects, as required
  • Performs other job-related duties as assigned
     

Required Qualifications

  • High School Grad / GED
  • Bachelor's or Equivalent Experience
  • Experience: 4+ years

Preferred Qualifications

  • Certified Information Systems Aud (CISA) certification

 

Employee Group:  Exempt
Employee Type:  Full Time
Job Category:  Information Technology
Organization:  Florida Power & Light Company 
Relocation Provided:  Yes, if applicable

 

Where permitted by applicable law, NextEra Energy requires all employees and new hires to be fully vaccinated for COVID-19 or be willing to receive the COVID-19 vaccination on or before the first day of employment.

 

NextEra Energy is an Equal Opportunity Employer. Qualified applicants are considered for employment without regard to race, color, age, national origin, religion, marital status, sex, sexual orientation, gender identity, gender expression, genetics, disability, protected veteran status or any other basis prohibited by law. We are committed to a diverse and inclusive workplace.

 

NextEra Energy provides reasonable accommodation in its application and selection process for qualified individuals, including accommodations related to compliance with conditional job offer requirements, consistent with federal, state, and local laws. Supporting medical or religious documentation will be required where applicable and permitted by applicable law. To request a reasonable accommodation, please send an e-mail to recruiting-coordinator.sharedmailbox@nexteraenergy.com, providing your name, telephone number and the best time for us to reach you. Alternatively, you may call 1-844-694-4748. Please do not use this line to inquire about your application status.

 

NextEra Energy will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information.

 

NextEra Energy does not accept any unsolicited resumes or referrals from any third-party recruiting firms or agencies. Please see our policy for more information.

#LI-WS1 


Nearest Major Market: Palm Beach
Nearest Secondary Market: Miami