Con Edison · 8 hours ago
Cyber Incident Response System Analyst
Con Edison is seeking a Cyber Incident Response System Analyst to support and strengthen their Incident Response capabilities. The role involves monitoring security alerts, investigating incidents, and collaborating with senior analysts to enhance the organization's security posture.
Utilities
Responsibilities
Monitor and analyze security alerts from multiple sources (SIEM, EDR, network tools) to identify potential incidents
Assist in investigating and responding to cybersecurity incidents, following established playbooks and procedures
Escalate complex incidents to senior analysts and work with them to coordinate containment, eradication, and recovery actions
Maintain accurate incident records, timelines, and evidence for each investigation
Contribute to updating incident response procedures and playbooks as threats evolve
Support investigations in cloud and network environments using logs, packet captures, and threat intelligence sources
Identify potential indicators of compromise and collaborate with other teams to validate findings
Participate in postincident reviews to capture lessons learned and suggest improvements to detection and response processes
Assist in implementing recommendations to strengthen security controls
Work closely with SOC analysts, threat hunters, and engineers to build investigative and analytical skills
Stay current with emerging threats, attack techniques, and industry best practices to enhance response capabilities
Qualification
Required
Bachelor's Degree in computer Science or related field and 2 years of work experience in Cyber or in an IT related field
Associate's Degree in computer science or related field and 4 years of relevant work experience, with at least 2 years of work experience in an IT field
High School Diploma/GED and 5 years of relevant work experience, with at least 3 years of work experience in an IT field
Prior Cybersecurity experience, required
Knowledge in using known commercial and/or open-source cyber tools, required
Understanding of industry standard policies, processes, and procedures, required
Understanding of chain of custody, required
Previous experience creating timelines and completing a root cause analysis, required
Proficiency in collecting, analyzing the evidence collected and creating reports based on the findings to different stakeholders: (Technical, Executive, etc.), required
Knowledge of current and evolving cyber threat landscape, required
Ability to remain agile and work in a fast-paced environment, required
Ability to handle multiple priorities effectively, required
Driver's License Required
Preferred
Understanding of OT systems, protocols, and industrial control systems (ICS), Preferred
Certifications such as CompTIA Security+, CySA+, GSEC, or other entry/midlevel cybersecurity credentials, preferred
Familiarity with SIEM tools, EDR platforms, and network monitoring systems, preferred
Basic experience with scripting languages (Python, PowerShell) to automate simple tasks, preferred
Understanding of cloud environments (AWS, Azure, or GCP) and basic cloud security principles, preferred
Strong analytical thinking, attention to detail, and willingness to learn advanced incident response techniques, preferred
Company
Con Edison
We provide power to more than 10 million people and businesses across NYC and Westchester.