Turn this role into an interview — a resume and cover letter built around what this employer wants.
Tucson Electric Power Company is seeking an IT Security Analyst to defend networks, systems and data critical to powering communities. You will administer enterprise systems, monitor events, and respond to incidents while aligning with regulatory requirements.
Ideal candidates have a HS diploma with cybersecurity/IT background; bachelor’s preferred, with 3–5 years for Level II and relevant certifications. Join a team protecting assets supporting customers and operations.
Protect critical infrastructure by administering and securing enterprise systems, applications, databases, networks, and user access. Monitor security events, investigate suspicious activity, and respond to cybersecurity incidents and forensic investigations. Conduct vulnerability, risk, and security assessments to identify threats and strengthen our security posture. Evaluate and implement emerging security technologies that improve the protection of company assets and operations. Support compliance and regulatory initiatives, including NERC CIP, SOX, HIPAA, PCI DSS, and other security requirements. Partner with IT teams, business leaders, vendors, and project teams to embed security into technology solutions across the organization.
High school diploma or GED required; Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field preferred. Experience supporting information security, network administration, systems administration, or a related IT discipline. Knowledge of security technologies such as identity and access management, SIEM, firewalls, malware protection, encryption, and vulnerability management. Understanding of incident response, threat detection, risk assessment, and security best practices. Strong problem-solving, communication, and teamwork skills with the ability to thrive in a rapidly evolving environment. For Level II consideration: 3-5 years of relevant security or network experience and industry certifications such as CISSP, GSEC, or equivalent experience.
Responsible for the design, planning, testing, implementation, and administration of regulatory requirements and industry‑wide accepted information security principles, practices, and information systems to ensure the protection of information assets processed, stored, or transmitted at UniSource. Evaluate the effectiveness of information security solutions and processes in place, keeping in mind the state of world events. Monitor for and identify security risks and exposures, determine the causes of security violations, assess, and implement procedures to halt future incidents. Understand and provide assistance to system users relative to information systems security matters. Participate in a team environment that provides cost‑effective IT security services to the various business units. Work closely with other areas to insure optimum reliability and cohesiveness.
Responsible for day‑to‑day security administration of company databases (e.g. Oracle and MSSQL), e‑mail applications, key business applications and networks. Responsible for provisioning and de‑provisioning users. Perform security incident response and forensic investigations. Evaluate new and emerging security technologies, features, and products to determine their application in the protection of company information assets. Perform security analysis, including architecture review, baselines, vulnerability assessments, and risk assessments to proactively identify security risks and exposures. Monitor security events across the network and ensure alerting and resolution of security issues and threats. Provide anti‑virus, spam, and malware administration and management. Provide second‑level support for the IT Help Desk. Perform 24 x 7 support on a rotating basis. Ensure change control processes are followed and service levels affected by those changes are maintained. Work with internal and external project managers to complete projects and efforts on time. Lead or participate in IT projects to provide information security expertise, guidance, or training. Work with internal and external auditors to implement technical aspects of regulatory/compliance/privacy controls, such as Sarbanes‑Oxley, NERC CIP, HIPAA, and PCI DSS. Work with Human Resources or Legal to provide sensitive investigative or litigation hold support. This position may provide services to affiliates of the Company subject to the UNS Energy Code of Conduct and the related Policies and Procedures.
Authentication and Access Control Tools, Management and Administration Anti‑Virus, Spam and Malware Tools, Management and Administration Application Security Architecture & Cloud Computing Concepts, Change & Security Configuration Audit and Control, Encryption Processes, Management and Administration, Firewall Management and Administration, Hardware/software Security Testing and Evaluation, Intrusion Detection/Prevention Incident Response Practices and Procedures, Computer Forensic Practices and Procedures, Layer 2 and 3 routing and switching protocols (TCP/UDP, IPv4, IPv6, OSPF, etc.), Security Information & Event Management (SIEM) and Logging, Scripting Languages such as PowerShell, VOIP Technology Security, VPN’s (Virtual Private Networks) and SSL, Vulnerability Assessment Practices/Technology (i.e. Operating Systems, Network, Application, Database, and Web), Wireless Security Infrastructure, Security Industry Standards such as ISO, NIST & FISMA, Regulatory Requirements of NERC CIP, SOX, HIPAA, PCI DSS and other applicable regulations, Information Security Awareness Programs and Communications, Information Security Policy and Standards, Information Security Risk Assessment.
(Equivalent combination of education and experience will be considered.)
High school diploma or GED. Effective written and oral communication skills are required plus a willingness to learn in a rapidly changing environment. Demonstrated ability to work both independently and as part of a team. Preferred Qualifications: Bachelor’s degree in Management Information Systems, Computer Science or related discipline is preferred. Two or more years in an IT related discipline is preferred.
Requires the qualifications for an IT Security I plus experience with day‑to‑day security administration. Requires self‑direction and the ability to work with vendors on creating statements of work and completing that work. Requires industry certifications (i.e. GSEC or CISSP) or equivalent experience of 3-5 years in an information security or network discipline. Preferred Qualifications: Assists more experienced administrators on projects and deals with day‑to‑day support.
Tucson Electric Power provides safe, reliable power to more than 447,000 customers in the Tucson metropolitan area. We’re also a local leader in community service, volunteerism and economic development efforts. TEP and its sister company, UniSource Energy Services, are among a family of utilities owned by Fortis, Canada’s largest investor‑owned gas and electric utility holding company.