ISO New England Inc.

Senior Cybersecurity Analyst

ISO New England Inc. Holyoke, Massachusetts, United States · $135K–$168K/yr

Utilities · 501-1,000 employees

23 h ago
security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Senior Cybersecurity Analyst will develop and implement enterprise security strategies across cloud, AI, and infrastructure environments while ensuring regulatory compliance. They will drive security initiatives, conduct risk assessments, and collaborate with cross-functional teams to integrate security controls into CI/CD pipelines.

What they look for

Cybersecurity Cloud security Vulnerability management DevSecOps AI security Network security Security compliance AWS Azure IAM Risk management Incident response Threat modeling Governance Regulatory compliance Infrastructure security

Requirements

Candidates must have 5+ years of experience in cybersecurity and 3+ years of specific experience with AWS or Azure cloud platforms. A strong background in security frameworks, vulnerability management, and DevSecOps practices is required, with relevant industry certifications preferred.

Benefits

401(k) Financial planning support Tuition reimbursement Professional development Wellness programs Onsite gym Flexible work hours Employee business networks Health insurance Dental insurance Vision insurance Life insurance Disability insurance Student debt benefit Paid time off

Full description

ISO New England is the independent system operator responsible for ensuring the safe and reliable flow of electricity in our region and planning for the future of the electric grid. We are at the forefront of New England’s ongoing transition to clean energy.

ISO New England is seeking an experienced Cybersecurity Analyst to support and enhance enterprise cloud, infrastructure, AI, and DevSecOps security initiatives. This role is responsible for advancing the organization’s cybersecurity strategy by facilitating cross-functional collaboration to strengthen technical security, governance, risk management, and regulatory compliance. The position provides technical leadership and cybersecurity expertise to support evolving business objectives while addressing emerging cyber threats across enterprise, cloud, AI, DevSecOps, and regulated environments. Working closely with internal stakeholders, the role drives security initiatives, influences technical decisions, and promotes a culture of security, resilience, and continuous improvement.

The ideal candidate will have strong experience in cloud security, vulnerability management, DevSecOps, AI security, network security and security compliance, with the ability to collaborate across technical teams to implement and maintain enterprise security standards

What we offer you:

  • A stable, mission-driven workplace where your impact truly matters
  • A highly engaged work environment that values inclusion, collaboration, and employee safety and wellbeing
  • Competitive compensation with a base salary + performance bonus
  • Robust benefits package, including:
  • Enhanced 401(k) and financial planning support
  • Tuition reimbursement and professional development
  • Wellness programs, including an onsite gym
  • Flexible work hours
  • Employee Business Networks

  • Free coffee at our onsite café
  • Hybrid work environment (3 days/week onsite)
  • Distance-based relocation assistance available

How you will make an Impact

  • Develop and implement enterprise cybersecurity strategies aligned with business objectives, regulatory requirements, and industry best practices.
  • Ensure compliance with cybersecurity frameworks and regulations including NERC CIP, NIST frameworks, CIS controls, FERC regulations, and SOC1/SOC2 requirements.
  • Implement enterprise security controls across cloud, infrastructure, applications, AI/ML environments, and regulated operational technology (OT) systems.
  • Conduct cloud security assessments across AWS and Azure environments, including IAM, CSPM, CIEM, container security, and configuration management.
  • Integrate security controls throughout CI/CD pipelines and DevSecOps processes, including automated vulnerability scanning, Infrastructure-as-Code (IaC) validation, and policy enforcement.
  • Assess and secure AI/ML systems, Generative AI applications, and Large Language Model (LLM) integrations through governance, access controls, data protection, prompt security, and AI threat modeling.
  • Perform vulnerability assessments, network security assessments, configuration reviews, compliance validation, risk assessments, and remediation tracking across enterprise and cloud environments.
  • Support enterprise security monitoring, logging, threat detection, incident response, and audit evidence collection using SIEM, EDR/XDR, CNAPP, DSPM, vulnerability management, and related security platforms.
  • Collaborate with cloud, infrastructure, application development, enterprise architecture, IAM, network, compliance, and business teams to integrate security into system design and operational processes.
  • Identify, assess, prioritize, and communicate cybersecurity risks while developing effective mitigation strategies.
  • Develop and maintain security policies, standards, governance documentation, compliance reporting, and security best practices.
  • Monitor emerging cybersecurity threats, AI security risks, industry trends, and regulatory changes to continuously enhance the organization’s security posture.
  • Provide technical mentorship, and cross-functional guidance while promoting cybersecurity awareness, operational excellence, and secure technology adoption.

What we are looking for

  • 5+ years of experience in cybersecurity, security engineering, or AI security roles.
  • 3+ years of security experience in AWS and/or Azure cloud platforms.
  • Experience designing and implementing enterprise security solutions across cloud, infrastructure, applications, and hybrid environments.
  • Hands-on experience with AWS and/or Azure cloud platforms, including IAM, CSPM, CIEM, container security, and cloud security best practices.
  • Experience integrating security controls into CI/CD pipelines and DevSecOps environments.
  • Knowledge of AI security concepts, including Generative AI, LLM security, AI governance, and AI risk management.
  • Experience performing vulnerability management, security assessments, configuration reviews, threat modeling, and cybersecurity risk assessments.
  • Knowledge of enterprise security technologies including SIEM, EDR/XDR, CNAPP, DSPM, vulnerability management, identity and access management, encryption, and security monitoring platforms.
  • Familiarity with cybersecurity frameworks and regulatory standards including NERC CIP, NIST Cybersecurity Framework, NIST Special Publication 800 Series, ISO 27001, CIS Controls, and applicable regulatory requirements.
  • Strong analytical, troubleshooting, communication, documentation, and cross-functional collaboration skills.
  • Ability to manage multiple priorities independently while providing technical leadership and driving continuous security improvements.
  • Experience with API security practices, including secure API design, authentication and authorization mechanisms, access control, encryption, and protection against API-based threats.

Desired not required

  • 5+ years of cybersecurity experience.
  • Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related field.
  • Advanced degree such as a Master’s in Cybersecurity Management, Information Assurance, Artificial Intelligence, or related field.
  • Industry cybersecurity, cloud security, and AI security certifications, including:
  • ISC2 Certified Information Systems Security Professional (CISSP)
  • ISACA Certified Information Security Manager (CISM)
  • Amazon Web Services Certified Security – Specialty
  • Microsoft Azure Security Engineer Associate (AZ-500)
  • ISC2 Certified in AI Security (when available)
  • OWASP AI Security and LLM Security knowledge/training

This employer will not sponsor applicants for work visas for this position (ex: H-1B, F-1/CPT/OPT, O-1, E-3, TN, J, etc.).

The expected salary range for this position is $135,000 - $168,000 per year. This role is also eligible for an annual performance bonus, comprehensive health insurance (medical, dental and vision), flexible spending and health savings accounts, a 401(k) plan with generous employer contributions and a student debt benefit, life and AD&D insurance, disability insurance, critical illness and hospital indemnity benefits, paid time off, paid leave, a wellness program, an employee assistance program and other great company perks.

#LI-HYBRID

This is a U.S. based role. If the successful candidate resides outside of the U.S., relocation will be required.

Equal Opportunity: We are proud to be an EEO employer. Applicants for employment are considered without regard to race, color, religion, creed, sex (including pregnancy, childbirth, and related medical conditions), gender identity or expression, sexual orientation, citizenship, national origin, age, ancestry, marital status, disability (including learning, mental, intellectual, and physical), service in the uniformed services, genetic information, or any other status protected by applicable law.

Drug Free Environment: We maintain a drug-free workplace and perform pre-employment substance abuse testing.

Similar roles