Job Description
Work Place Flexibility: Hybrid Legal Entity: Entergy Services, LLC This position may be filled in Little Rock AR, The Woodlands TX, or New Orleans LA. Relocation assistance and sponsorship is not provided. The official title for this position is Info Sec Engineer Sr Lead. Brief Position Description: The Senior Information Security Engineer is responsible for proactively improving and evolving a successful security engineering function within Information Security. The Security Engineering team owns the deployment and operation of security monitoring tools and processes designed for real-time analysis, triage, and response to events and alerts generated across the enterprise to protect the company’s assets, solutions, and services by reducing time to respond to and if necessary, remediate security incidents and risks. This role is focused on interpreting cyber security event data, security validation tests, user behavior analytics, third party threat intel, and XDR data to develop security detection and response use cases as well as tune the systems that support the development of alert, response, and forensic data creation. Key responsibilities include: Act as Sr Lead Security Engineer, liaison with Cloud Implementation Partners, focus on assisting Leadership with developing cloud security implementation strategy and own/act as SME for cloud security engineering technology(s). Participate in the identification and implementation of detection and response use cases in partnership with the security operations center utilizing telemetry provided by or stored in one or more of the following sources: SIEM, XDR, Security Validation, External Threat Intelligence, User Behavior Analytics, and any additionally identified sources of security event data. Implement necessary monitoring policies, reference architectures, and procedures in compliance with statutory and regulatory requirements covering internal and external parties, regulated and non-regulated physical, operational, and business systems throughout the enterprise Act as knowledgeable resource in securing AI utilization and development, participate in the development AI security implementation and protection strategy. Represent Security Engineering organization in AI working groups. Assist in satisfying specific requirements to ensure security of the environment in compliance with North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) and Nuclear Regulatory Commission (NRC) Nuclear Cyber (10 CFR 73.54) Execute on strategy & technology roadmap for the Security Information Event Management (SIEM) platform Drive process excellence and maturity to push the envelope on delivering a world-class Cyber Security function to protect Entergy against cyber threats Support life-cycle management of the SIEM platform, and other interconnected or related monitoring platforms including assistance with coordination and planning of upgrades, new deployments, and maintenance of current operational systems Execute on world-class cyber defense capability for all information technology and operational technology assets including power generation units, nuclear plants, electric substations, SCADA, distribution automation, advanced metering infrastructure (AMI), email, and networks. Work closely with Consolidated Security Operations Center (CSOC), Threat & Vulnerability Management (TVM), other internal/external teams and management in a 24x7 operational environment Execute the processes to monitor, analyze, and correlate logs and alerts across multiple platforms to identify advanced threats or incidents affecting the enterprise and aiding in the development of security monitoring use cases. This includes any potential source of security relevant logs and/or data. Assist in maintaining documentation and evidence to be used for after action reporting and/or legal evidence Monitor and respond to regulatory developments and industry best practices, with manager direction Accountable for execution of security engineering support of all device classes (server, desktop, mobile, etc.), hosting models (on-premises, external, cloud) and applications to which security platforms apply Work closely with all teams in Information Security to implement use cases for monitoring or SOAR Deliver on KPIs to measure effectiveness of security engineering and report trends Support security orchestration and automation efforts and help to identify opportunities to improve security response and precision. Collaborate and work across other IT and Information Security areas to design and onboard new systems to fo