Edison International-posted about 1 month ago
Full-time • Mid Level
Hybrid • Rosemead, CA
5,001-10,000 employees
Utilities

Become a Cybersecurity Incident Response Advisor at Southern California Edison (SCE) and help strengthen our security posture to build a better tomorrow. In this role, you'll be responsible for developing, curating, and tuning detection capabilities within Microsoft Sentinel, Splunk, and other security toolsets to support cybersecurity operations. You will create and manage advanced security use cases, refine detection logic, and provide expert technical guidance to incident response teams. Additionally, you will play a critical role in CSOC triage and investigation efforts ensuring timely threat detection and response. You will collaborate with key stakeholders to enhance security monitoring, improve incident detection efforts, and maintain a high level of cybersecurity expertise. In this role, you will: Develop, curate, and tune detection rules, use cases, and alerts in Microsoft Sentinel, Splunk, and other security toolsets. This includes analyzing log data, creating custom queries, and refining alert thresholds to reduce false positives and improve detection accuracy. Support CSOC triage and investigations, correlating security logs, analyzing alerts, and escalating incidents as necessary. Provide deep technical guidance during security events, identifying root causes, refining detections based on emerging threats, and supporting post-incident analysis. Monitor and stay up to date with the latest cybersecurity threats, vulnerabilities, and detection technologies, incorporating this knowledge into improved detection strategies. Develop, document, and maintain SOPs and runbooks for detection use cases and security alert responses to ensure best practices and continuous improvement. As a Cybersecurity Incident Response Advisor, your work will help power our planet, reduce carbon emissions and create cleaner air for everyone. Are you ready to take on the challenge to help us build the future?

  • Manages cyber security project delivery by ensuring the cyber security team delivers on success criteria
  • Delivers project reporting for assigned projects, conducts critical analysis of project status, potential risks, and continual process improvement
  • Coordinates and performs appropriate maintenance to ensure reliable and secure performance of the security systems, including applying security patches, implementing version upgrades, modifying, and improving services and performing ongoing operational management tasks
  • Contributes to an overall cyber security governance strategy, standards, and operational procedures
  • Ensures technology risk impacting the business is effectively identified, quantified, communicated and managed, including recommendations for resolution and identifying the root cause/key themes
  • Prepares and updates Plan of Actions & Milestones (POA&M) that identify security weaknesses and establishes milestones and compensates controls for remediating these weaknesses and tracking the progress and effectiveness of the remediation
  • Oversees the production of evidence to support internal and external audits
  • Provides Cyber Security and risk assessments for new networks, services and devices as the need arises
  • Drives periodic monitoring of audit logs in accordance with requirements, and reports findings and concerns for further analysis and action, inclusive of breach notification and initiation of incident response, in accordance with protocols and procedures
  • Delivers programs and processes to reduce information security risk and strengthen SCE's security posture
  • A material job duty of all positions within the Company is ensuring the protection of all its physical, financial and cybersecurity assets, and properly accessing and managing private customer data, proprietary information, confidential medical records, and other types of highly sensitive information and data with the highest standards of conduct and integrity.
  • Seven or more years of experience in information technology, information security and/or cybersecurity.
  • US Citizenship Required.
  • Bachelor's degree or higher, in a technical discipline.
  • Certifications: CISSP, GISF, GSEC
  • Experience working in a Security Operation Center or Incident Response team.
  • Comfortable working in multiple, diverse IT environments and eco-systems
  • Strong written and verbal communications skills
  • Experience leading and collaborating with cross-functional teams
  • Ability to think critically and maintain thorough and comprehensive documentation
  • Visit our Candidate Resource page to get meaningful information related to benefits, perks, resources, testing information, hiring process, and more!
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service