Hawaiian Electric Company-posted 3 months ago
$105,600 - $134,400/Yr
Full-time • Manager
Honolulu, HI
Utilities

The PEJ INFORMATION ASSURANCE Department of the P INFORMATION ASSURANCE Division at Hawaiian Electric Company has 1 Management vacancy available. This position reports directly to the Information Assurance Manager and serves as a mentor to others in the department on Information Security Architecture and Technology reviews, including development of detailed proposals and plans for new information security systems and controls. The role provides consulting-level knowledge and expertise for the ITS Information Assurance (IA) department functions, which includes development of information security policies & standards, information risk management, information technology (IT) and operational technology (OT) compliance, and secure integration of smart grid technologies. The position also coordinates ongoing compliance reviews with Process Area representatives and assists in developing practices and procedures to ensure that cost-effective information security and IT controls are in place.

  • Supports information security risk assessments and recommends mitigating controls and solutions for IT and OT projects and applications.
  • Assists with program development and management for privacy, e-discovery, security awareness training, digital forensics, patch management, vulnerability remediation, and other security and compliance programs.
  • Supports the detailed review and approval processing for various IT policies, processes, and procedures necessary to support the Company's information security and compliance requirements.
  • Ensures that adequate and proper internal controls and CobiT framework-based IT policies, processes, practices, and standards are developed, maintained, and tested for quality assurance.
  • Supports the IT business continuity planning, IT disaster recovery planning, and the Company's Computer Security Incident Response Team (CSIRT).
  • Participates in Company emergency response activities as assigned.
  • Working knowledge of IT risk management frameworks and principles, network security architecture, cryptography, Intrusion Detection/Prevention Systems (IDS/IPS), and other IT security best practices.
  • Conceptual knowledge of Sarbanes-Oxley (SOX), National Institute of Standards and Technology (NIST) SP-800 series, ISO 27000 series, Privacy Laws (Hawaii Revised Statute 487N), Open Web Application Security Project (OWASP), and other security related frameworks, standards, and laws.
  • Conceptual knowledge of business administration, IT Audit, programming and digital forensics.
  • Conceptual knowledge of utility business and related Operations Technology Systems (SCADA, DCS, etc).
  • Conceptual knowledge of TCP/IP networking principles, the OSI reference model, and IEEE 802.11 and 802.1x standards.
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified Authorization Professional (CAP)
  • GIAC Security Leadership (GSLC)
  • Competitive compensation package
  • Opportunities for challenge and advancement
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service