Talent Apply
Log in
All jobs
E

Information Security Analyst Senior

Entergy
Hybrid
Hybrid

About this role

Entergy - Information Security Analyst Senior

Job Title: Information Security Analyst Senior PS Job Title: Info Sec Analyst Sr Work Place Flexibility: Hybrid Legal Entity: Entergy Services, LLC

Job Summary

As a Senior Threat and Vulnerability Management (TVM) Analyst, you will design, configure, and support the TVM Team in identifying, assessing, and remediating technical vulnerabilities across a global enterprise IT and OT infrastructure. You will be responsible for executing automated scans, prioritizing risks based on business impact, and collaborating with owners to track the timely patching of assets and applications. This role offers an advanced opportunity to exercise your expertise in risk analysis and security tooling within a complex, high-scale environment.

Job Duties

  • Scan All Assets: Run vulnerability scans across corporate networks, OT environments, web applications, APIs, and public/hybrid cloud infrastructure.
  • Audit Cloud Security: Continuous assessment of cloud workloads, identities, storage buckets, and configurations to detect security drift and misconfigurations.
  • Test Code & APIs: Perform Static (SAST) and Dynamic (DAST) application security testing, and audit API endpoints for data leakage and authentication flaws.
  • Filter Flaws: Eliminate false positives to isolate true risks threatening energy delivery systems, customer portals, and critical cloud infrastructure.
  • Assess Risk: Prioritize vulnerabilities using Threat Intelligence, CVSS scores, OWASP Top 10, OWASP API Security Top 10, and cloud-specific threat matrices.
  • Guide Remediation: Provide clear mitigation steps to IT engineers, substation OT technicians, software developers, and cloud infrastructure teams.
  • Ensure Compliance: Map vulnerability data directly to NERC CIP (including cloud-hosted BCSI requirements) and the NIST Cybersecurity Framework.
  • Report Risks: Draft executive risk reports, secure software metrics, and cloud compliance posture charts for leadership and federal regulatory auditors.

Required Skills

  • Industry

Experience

  • 5+ years in cybersecurity, with a preferred 2 years protecting a large enterprise with exposure to energy, utility, or industrial environments.
  • Technical Knowledge: Strong understanding of traditional Windows and Linux enterprise deployments, SCADA networks, PLC systems, microservices architectures, REST/GraphQL APIs, Cloud Security Posture Management (CSPM), Infrastructure as Code (IaC) security, and cloud identity management (IAM).
  • Tool Proficiency: Mastery of vulnerability management tools, application security tools, and native cloud security CNAPP tools. Experience with scripting languages such as Perl or Python. Ability to leverage Artificial Intelligence (AI) to solve problems or automate work processes.
  • Regulatory Compliance: Practical knowledge of NERC CIP, NIST CSF, CIS Benchmarks, and secure coding standards.
  • Clear Communication: Ability to bridge the gap between corporate IT security, cloud architects, software developers, and field-level eng

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →