M

IT CyberSecurity Administrator

Muscatine Power and Water
Full-time
On-site
Muscatine, Iowa, United States

Job Purpose

Responsible for the review and implementation of IT’s security and internal cybersecurity infrastructure to protect MPW’s digital assets and data. The position is also responsible for remediation efforts and security patching for all corporate networking devices and services.

Specific Responsibilities

  1. Responsible for assisting IT with all aspects of the Utility’s internal security and cybersecurity, ensuring that activities are aligned with Utility goals and objectives, and complying with all applicable regulations and policies to protect digital assets and data, including:
    • Maintain network security and firewall security, including user accounts and access rights, spam and spyware filtering, and network intrusion assessment, prevention, and detection.
    • Administer virus protection including installation, configuration, upgrades, troubleshooting, and remediation of infected systems and applications.
    • Conduct vulnerability assessments, including the identification and investigation of potential security threats and vulnerabilities in our network. Implement necessary configurations to ensure a secure network.
    • Identify current security environment improvement opportunities and research, plan, and propose possible solutions. Work with other Utility network owners to implement security measures as appropriate.
    • Assist in coordinating  and implementing the Information Technology security/cybersecurity incident response plan; provide analysis and remediation/prevention measures regarding imminent security breaches.
    • Recommend the use and deployment of existing security monitoring software.
    • Assist with methods and practices to develop a secure network and the protection of IT assets.
    • Review and manage MPW’s IDS/IPS systems.
  2. Act as the Information Technology primary network security engineer ensuring remediation efforts and security patching for all corporate networking devices and services, including:
    • Monitor digital security systems, note anomalies, and research potential security issues and/or breaches.
    • Assist in all aspects of network configurations, monitoring, and support.
    • Ensure daily monitoring of event logs on servers and network hardware is carried out.
    • Configure, implement, and maintain sensors for all IT infrastructure devices within the existing monitoring system.
    • Perform security patch deployment and testing.
    • Troubleshoot and configure client-side VPN connections.
    • Perform vulnerabilities assessment and internal/external penetration testin
    • Review network security reports and react to anomalies and errors.
    • Revise, monitor, and configure Microsoft 365 security controls.
    • Monitor network security alerting and provide daily and weekly reporting as needed.
    • Support user access and user security access for data and Microsoft Windows Services.
    • Provide support and assistance in security upgrades and Server operating security system upgrades.
    • Maintain all required documentation, such as hardware and software error logs, updates on projects, backup logs, procedures, etc.
    • Provide support for various projects/tasks involving IT security services.
  3. Support and development of Utility-wide security programs as part of the MPW’s Cybersecurity Committee and Cybersecurity Strategic Plan.

Other Responsibilities

  1. Draft and review/approve documentation of security policies and procedures.
  2. Present security training as needed.
  3. Participate, as directed, in appropriate committees for the Utility.
  4. Administer digital certificates for MISO and/or outside marketing partner.
  5. Other duties as assigned.