What are the responsibilities and job description for the Security Control Assessor position at CorSource?
*This is a fully onsite role in Vancouver, WA*
OVERVIEW
The Security Controls Assessor 2 supports the implementation of operational technology cybersecurity and compliance practices for Transmission systems used in control of the Bulk Electric System (BES).
- This position will review documentation of mandatory technical or process-based cybersecurity controls and evaluate artifacts and evidence of compliance activities.
- The Security Controls Assessor 2 applies specialized knowledge and experience to Information/Operational Technology (IT/OT) security controls and security programs supporting the Operational Technology (OT) organization.
- The position also participates in processes for incident analysis, identification of potential compliance violations, and causal analysis, as well as administering program processes and procedures. Additionally, the position will provide support and assistance to junior Security Control Assessors, Cybersecurity personnel, and co-workers on a variety of ad hoc and standing projects requiring policy/procedure/process analysis.
- This position will work closely with leadership and staff across the organization to collaborate on and facilitate success of assigned cybersecurity and compliance programs.
REQUIREMENTS
Education & Corresponding Experience:
- A bachelor’s degree in computer science, information technology management, Cyber Security, Forensics, or a closely related technical discipline is preferred.
- 4 years of experience is required with an applicable bachelor’s degree.
- 6 years of experience is required with an applicable associate degree.
- 8 years of experience is required without a degree or applicable degree.
- Experience should be consistent with the specific requirements of operations analysis, incident response, and progressively more technical in nature.
Required Technical Skills & Experience:
- Ability to research and maintain proficiency in tools, techniques, countermeasures, and trends in information security, computer and network vulnerabilities, data hiding, network security, and encryption.
- Ability to plan, execute and document compliance evaluations both independently and as a team member.
Preferred Skills & Experience:
- Demonstrated experience with North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) standards, National Institute of Standards and Technology (NIST) Cybersecurity Framework, and/or NIST SP 800-53 Security and Privacy Controls for Information Systems and Organizations.
- Certified Information Systems Security Professional (CISSP) or equivalent.