We are CorSource Technology Group, a locally owned technical staffing and recruiting firm in Portland, Oregon.
19873
Business Systems Analyst 2 (N-IT)
12 months
Portland
This position closes to submittals on September 18th.
Position requires the ability to meet federal background and compliance requirements.
OVERVIEW
Assignment
This contract Business Systems Analyst 2 assignment will support the Company OT Cybersecurity Program Management & Compliance (JSP) organization. OT Cybersecurity Program Management Mgmt & Compliance is responsible for providing centralized program management, reliability standards owner, and program support services for Field Compliance and Security, Asset Management, Business Continuity, Vulnerability Management, Change and Configuration Management, and Security Management Programs.
This assignment will serve as primary analyst for the Change and Configuration Management team. The Change and Configuration Management Team identifies, controls, and documents changes to the hardware, software (third-party and company executables), and database schemas for all Control Center information systems that reside in production and/or on production networks. These teams work closely with one another supporting OT’s Change and Configuration Management (CCM) Program, with projects that often overlap and complement.
Organization
JSP operates with a high level of collaboration and transparency. While work is guided by a structured compliance calendar, team members must remain agile to successfully manage emergent, high-priority tasks. This assignment provides an excellent opportunity to gain deep insight into the strict regulatory requirements governing Federal Critical Assets. The ideal candidate is highly adaptable to changing priorities. This assignment is primarily sedentary.
ASSIGNMENT RESPONSIBILITIES
Note: All official drafts, documents and recommendations, as listed below, must be reviewed, finalized and approved / accepted by appropriate manager or other federal personnel with the authority to do so.
- General
- These responsibilities are performed by both teams / areas of focus; some duties will be performed by collaboration of the two teams.
- Perform company management-approved processes and procedures to support NERC (North American Electric Reliability Corporation) Mandatory Reliability standards CIP (Critical Infrastructure Protection) and Department of Energy NIST/FISMA (National Institute of Standards and Technology/Federal Information Security Management Act) security requirements.
- Provide quality data management and stewardship. Maintain filing system(s), files, emails and records in accordance with compliance requirements. File and disperse documents/letters only to appropriate personnel. Maintain all official records in accordance with the Information Governance & Lifecycle Management (IGLM) standards and procedures. Validate official records are accurately maintained for auditing purposes.
- With federal employee oversight, perform review and verification of Control Center (CC) and other applicable GSS compliance with regulations from FISMA, DOE, WECC, NERC, and FERC; as well as performing audit preparation for the aforementioned regulatory bodies and Internal (CG) audits; and Self-Certification data calls.
- Participate in improvement efforts, providing recommendations and hands‑on assistance with position‑related quality, compliance or efficiency improvements.
- Validate TTL items are currently modeled correctly in the ChangeGear (CMDB) database; alert SME or the manager of any issues or concerns.
- Maintain a high‑level overview of the complex inter‑connected data systems that make up the Change and Configuration Management (CCM) Program. (TripWire, SolarWinds, AssetDB, ChangeGear, CMS, etc.).
- Attend meetings, conferences, and seminars to support the customer needs as they related to company’s CCM Program
- IT Change Management:
- Monitor the Request for Change (RFC) Queue; verify pre and post testing has been performed by the appropriate Resource Managers (RM).
- Review specifications, verifying that all essential requirements are documented; alert applicable SME or the manager of results or any issues / concern; make recommendations for corrections / changes.
- Review the logical top‑level design for applications and information systems (including test plans and procedures); provide results, concerns and/or recommendations to the manager.
- Collaborate with other IT CM Specialists to share best practices, provide recommendations and assistance on critical needs, and coordinate Transmission‑wide initiatives.
- Identify and recommend training needs and include major areas of uncertainty in approach, methodology, or interpretation and evaluation processes resulting from such elements as continuing changes in program, technological developments, unknown phenomena, or conflicting requirements.
- Support the program presentations, in‑house and client training, and functional education; arrange, conduct and facilitate management‑approved presentations and training sessions.
- Develop and present recommendations and supporting analysis for management decisions.
- Prepare technical reports, documents, studies, and system documentation as required.
- Confer with system users to document and resolve existing system issues and problems.
- Provide back‑up support and workload assistance for the group’s Process & Control Support Team.
- System modeling and maintain technical configuration baseline documentation
- Detect and correct configuration baseline errors
- Assist in defining, developing and documenting of new processes and procedures as required
- Support process and procedure roll‑out
- Provide support for both the manual and automated software patch program
- Track the Request for Change (RFC) related to each mitigation plan and report status to appropriate system owner.
- Assist the management with developing and documenting system processes and procedures to support NERC (North American Electric Reliability Corporation) Mandatory Reliability standards CIP (Critical Infrastructure Protection) and Department of Energy NIST/FISMA (National Institute of Standards and Technology/Federal Information Security Management Act) security requirements.
- Support the development of necessary documentation to support reporting and audit requirements.
- Provide quality assurance for organization to verify compliance to regulatory standards and guidelines.
- Provide support, including gathering & formatting information/data, to NERC annual certification process, WECC audit, and any other spot audit or compliance data request.
- Assist with data stewardship for the configuration management program.
- Attend meetings to support the customer needs. Attendance assists in maintaining currency of technical, procedural and acquisition knowledge.
REQUIREMENTS
Education & Corresponding Experience
- An Associate’s or Bachelor’s degree in Computer/Information Technology, Business Systems, Engineering or a directly‑related technical field is preferred.
- With an applicable Associates degree, 7 years of experience is required.
- With an applicable Bachelor’s degree, 5 years of experience is required.
- Without an applicable degree, 9 years of experience is required.
- Experience should include demonstrated analyst work experience in Computer/Information Technology, Business Systems and requirements engineering, operations management or other closely related field.
Required Technical Skills & Experience
- 3 years’ experience working with the following:
- Configuration Change management concepts and practices for secure/reliable technology systems
- Compliance standards and best practices frameworks as applied to systems development and program management
- Process and procedure development
- 1 year experience in the use of configuration change management tools/systems
- 1 year previous compliance and/or audit support experience.
All qualified applicants at CorSource Technology Group will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.