The intent of this job description is to provide a representative summary of the major duties, locations, and responsibilities performed by incumbent(s) in this job. Incumbent(s) may not be required to perform all duties in this description, and incumbent(s) may be required to perform work-related tasks other than those specifically listed in this description. This job description is not a “contract” between the employee and the Authority. The job duties and essential functions may be changed at the discretion of the General Manager.
Who We Are & What We Do:
At DC Water, we provide more than 700,000 District of Columbia residents and 24.6 million annual visitors with essential water, wastewater, and stormwater services. DC Water also provides wholesale wastewater treatment services for 1.8 million people in Montgomery and Prince George's counties in Maryland, and Fairfax and Loudoun counties in Virginia. We aspire to be known for superior service, ingenuity, and stewardship to advance the health and well-being of our diverse workforce and communities. To achieve this vision, we commit to our shared mission every day—exceeding expectations by providing high quality water services in a safe, environmentally friendly, and efficient manner.
The Senior Cyber Security Analyst is responsible for the administration of deployed cyber control technologies. The role is part of the Security Operation Center (SOC) which monitors, analyzes, detects, and responds to cyber incidents on both traditional IT and Operational Technology (OT) networks. The role coordinates with both the Information Technology (IT) team and Operational Team (OT) to ensure individuals have the appropriate access to DC Water Resources, monitors vulnerabilities and threats, collects intelligence, assists in disaster recovery operations, and in updating cyber controls with intelligence obtained from third-party providers. This role is also responsible for the identification of IT assets supporting DC Water’s business processes.
Key Working Relationships: Works with the Information Technology Solution Center (ITSC) and Infrastructure teams to enable the delivery and disposal of computing and network assets. Maintains and manages Role-Based Access to the Information Technology Asset Management Database. Partners with internal stakeholders to understand and logically document current and future processes.
The qualifications listed below are representative of the knowledge, skill, and ability necessary for an individual to perform each essential responsibility satisfactorily. Reasonable amounts of training are provided.
Minimum 5 years of experience in Information Systems.
Strong understanding of the key functions of cybersecurity, cyber risk mitigation strategies, and event and incident flows within a Security Event and Incident (SEIM) system.
Ability to define the problem, generate and select alternatives, and implement solutions.
Intermediate understanding of MITRE and Adversarial Tactics, Techniques and Common Knowledge (ATT&CK) framework for Information Technology and Operational Technology Networks.
Strong understanding of one or more computer programming and/or scripting languages (PowerShell, KQL, Python, etc.).
Intermediate understanding of network ports, protocols, and services, host and network-based Intrusion Prevention Systems (IPS).
Advanced understanding of system and network logging events.
Familiarity with the National Institute of Standards and Technology NIST 800-53 Control Families and the NIST Cyber Incident Response steps.
A Bachelor’s degree in Information Systems, Computer Science, or a related technical field from an accredited college or university.
Experience in cybersecurity incident response and network security monitoring and must be proficient in using technology tools such as CheckPoint, Azure, Microsoft Entra, Defender, and Purview.
Master’s degree in cybersecurity, information technology security, computer engineering, computer information systems, computer science or related field from an accredited college or university.
Certifications in cybersecurity, such as a CompTIA Security+, GIAC Certifications, or similar.
The work environment characteristics described in the physical requirements section of the required skills & qualifications table are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential responsibilities.*
At DC Water, our people make us an industry leader. Join a group of thinkers, innovators, and problem solvers focused on protecting life’s most precious resource in the nation’s capital.
We are proud to be an EEO/AA employer M/F/D/V.
We maintain a drug-free workplace and perform pre-employment substance abuse testing
The Americans with Disabilities Act prohibits discrimination against “qualified individuals with disabilities”.
If a reasonable accommodation is needed to participate in the job application or interview process, to
perform essential job functions, and/or to receive other benefits and privileges of employment, please
Notice: The inclusion of job postings or company information on our platform does not imply endorsement, partnership, or affiliation. Listings may include publicly available roles from various sources, and companies shown may not have a direct relationship with Energy Hire.