Entergy

Information Security Analyst Senior Lead - Threat Hunter

Information Security Analyst Senior Lead - Threat Hunter
Notice info
LocationThe Woodlands, TX
On-site
Utilities

About This Job

Job Title: Information Security Analyst Senior Lead - Threat Hunter


Work Place Flexibility: Hybrid


Legal Entity: Entergy Services, Inc.-ESI (OLD)

*This is a hybrid position that can be filled in The Woodlands, TX, Little Rock, AR, Jackson, MS, New Orleans, LA.*


Job Summary/Purpose:

The Cyber Threat Hunter will work proactively to detect and respond to advanced threats that evade

traditional and modern security tools. Threat Hunters will leverage threat intelligence, behavioral

analytics, and advanced threat detection tools to uncover hidden risks and ensure the security of

our systems and data.

The Cyber Threat Hunter will coordinate the results of threat hunts with the Entergy Consolidated

Security Operations Center (CSOC) which is responsible for preventing, identifying, containing and

eradicating threats through monitoring, intrusion detection and preventive measures to assets

including LAN/WAN, IT-OT and cloud infrastructure. The CSOC is responsible for continuous

improvement to detection of threats, rapid response, and reports of suspected or confirmed

security incidents.

The role will report to the Manager of the CSOC and will manage day-to-day tasks as noted below,

with additional projects as they arise. We are looking for a skilled information security professional

having the experience in identifying, isolating and resolving advanced threats within the

organization. The threat hunter will play a prominent role in combating threats using foundational

and advanced detection techniques as well as implement deception capabilities. This position will

actively search for vulnerabilities and help to mitigate risks that could affect the organization. The

Information Security Analyst Sr Lead will be responsible for assisting in investigating and responding to

more advanced security incidents, understanding, and mitigating attack vectors, and staying

abreast of the evolving threat landscape.


Primary Responsibilities:

- Create threat models to better understand the Entergy IT enterprise, identify gaps to

improve defensive controls, expand offensive security capabilities and prioritize mitigations

- Utilize Threat Models along with Threat Intelligence to create threat hypothesis

- Plan and scope threat hunt missions to verify threat hypothesis

- Develop and maintain work instructions, SOPs, playbooks

- Assist in expanding and maintaining the Forensics program

- Proactively and iteratively search through systems and networks to detect advanced threats

- Analyze network, host, and application logs

- Analyze malware and code

- Have an understanding and knowledge of deception capabilities against advanced threats

- Experience implementing, deploying and/or operating deception technologies and tactics

- Prepare and report risk analysis and threat findings to appropriate stakeholders

- Able to lead hunt missions with minimal to no supervision or guidance

- Recommend course of actions, best practices and mitigating actions to improve security


practices

- Experience briefing senior level leaders and executives as well as the ability to translate

technical topics into non-technical terms for decision making

- Develop queries for the CSOC for new detections to new attacks

- Ability to stay up to date for maintaining and understanding the cyber threat landscape,

threat actors and activity to enhance Entergy’s cybersecurity posture.

- Identify, track and investigate high priority threat campaigns, malicious actors of interest,


capabilities and TTPs

- Create workflows and automation within the security tools

- Collaborate and coordinate with business units to improve threat detection, response and


improve the overall security posture

- Participate in post-incident reviews to identify lessons learned and best practices.

- Knowledgeable in Industrial Control Systems (ICS) and Operational Technology (OT) to


protect critical infrastructure and operational assets.


- Available to travel up to 25%


Will be responsible for:

- Reviewing current and emerging cyber threat intelligence to maintain situational awareness


and initiate hunts

- Maintaining threat hunts along with providing support to the CSOC as needed during


advanced incident escalations

- Creating and providing weekly briefings of reports

- Collecting, aggregating and reporting on metrics from threat hunts and security cases

- Conducting in-depth technical analysis on host-based, network-based, cloud-focused, and

mobile systems to identify advanced threats that evade traditional detection systems and

signatures

MINIMUM REQUIREMENTS

Minimum education required of the position.

Bachelor’s degree (i.e. Cybersecurity, Information security, IT, computer science, etc.) or 5-10 years

of prior relevant experience. Additional experience and certifications may be considered in lieu of a

degree.


Minimum experience required of the position

- 5+ years recent experience in a technical role in the areas of Security Operations, incident

response, detection engineering, offensive security/red team, or cyber threat intelligence

- Experience performing threat hunting in an active corporate environment

- Experience with host-based and network-based security monitoring using cybersecurity


capabilities

- Experience with offensive security strategies and assessment methodology

- Ability to see the larger picture when dealing with competing requirements and needs

- Ability to navigate and work effectively across a complex organization

- Experience with more than one or more enterprise EDR and SIEM tool

- Experience with digital forensics or incident response on major security incidents

- Ability to apply Cyber Threat Intelligence through enrichment, correlation and attribution

- Experience consuming and analyzing Cyber Threat Intelligence for actionable takeaways

- Experience working with log analysis tools

- Experienced developing scripts to support cyber threat detection

- Ability to work independently with minimal direction; self-starter / self-motivated

Minimum knowledge, skills and abilities required of the position

- Good planning, organizational and time management skills; detail and process-oriented;


able to juggle multiple priorities.

- Understanding of MITRE ATT&CK Framework

- Good problem-solving/decision making ability

- Good written and verbal communication skills.

- Good interpersonal skills, including teamwork.

- Highly collaborative, able to work cross-functionally; possessing the ability to forge


relationships and partner effectively

- Resourceful and self-motivated, able to work independently when required

- Good analytical, critical thinking and decision-making skills

- Cloud, IT-OT understanding of secure monitoring and incident response

- Understanding of systems (including industrial control systems)

- Good report writing and communication and ability to effectively communicate across the


organization

- Demonstrated commitment to customer service with excellent oral and written


communication skills

- Self-motivated, with ability to work independently and in a team setting while following up

on multiple tasks

Any certificates, licenses, etc. required for the position

One or more technical or InfoSec certifications are a plus, i.e., CompTIA, ISACA, EC-Council, or

ISC2.

- GIAC Certified Incident Handler

- GIAC Certified Forensic Analyst

- CISSP

- SANS GCIA – Intrusion Analyst

- SANS GMON – Continuous Monitoring Certification

- CCSP – Certified Cloud Security Professional

- GIAC Penetration Tester

- Kali Linux Offensive Security Certified Professional (OSCP)


Technical Competencies

- Hands-on technical engineering and process management skills and the ability to advocate


positive transformation

- Knowledgeable about security operations, cyber security monitoring, intrusion detection,


and secured networks

- In-depth knowledge of common networking protocols

- Understanding of complex Enterprise networks to include routing, switching, firewalls,


proxies, load balancers

- Expertise in network and host-based analysis and investigation

- Proficient with scripting languages such as PowerShell or Python

- Master knowledge of multiple UNIX OS platforms and Windows-based operating systems

- Master knowledge of current IT Security trends and best practices in technology, as well as


monitoring best practices and tools

- Master knowledge of security, risk, and control frameworks and standards such as ISO

27001 and 27002, SANS-CAG, NIST, FISMA, COBIT, COSO and ITIL

Work Conditions

Office environment with minimal physical requirements. As a provider of essential services, Entergy

expects its employees to be available to work additional hours, to work in alternate locations,

and/or to perform additional duties in connection with storms, outages, emergencies, or other

situations as deemed necessary by the company. Exempt employees may not be paid overtime

associated with such duties



#LI-DG1 #LI-HYBRID

Primary Location: Texas-The Woodlands Texas : Woodlands || Arkansas : Little Rock || Louisiana : New Orleans || Mississippi : Jackson

Job Function: Engineering FLSA Status: Professional Relocation Option:

Union description/code: NON BARGAINING UNIT Number of Openings: 1 Req ID: 122320 Travel Percentage:Up to 25%

An Equal Opportunity Employer, Minority/Female/Disability/Vets. Please click here to view the EEO page, or see statements below.

EEO Statement: The Entergy System of Companies provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a protected veteran in accordance with applicable federal, state and local laws. The Entergy System of Companies complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment including, but not limited to, recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

The Entergy System of Companies expressly prohibits any form of unlawful employee harassment based on race, color, religion, sex, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status. Improper interference with the ability of the Entergy System of Company employees to perform their expected job duties is absolutely not tolerated.

Accessibility: Entergy provides reasonable accommodations for online applicants. Requests for a reasonable accommodation may be made orally or in writing by an applicant, employee, or third party on his or her behalf. If you are an individual with a disability and you are in need of an accommodation for the recruiting process please click here and provide your name, contact number, the accommodation requested and the requisition number that you are requesting the accommodation for. Employee Services will contact you regarding your request.

Additional Responsibilities: As a provider of essential services, Entergy expects its employees to be available to work additional hours, to work in alternate locations, and/or to perform additional duties in connection with storms, outages, emergencies, or other situations as deemed necessary by the company. Exempt employees may not be paid overtime associated with such duties.

Know Your Rights: Workplace Discrimination is Illegal

The non-confidential portions of the affirmative action program for individuals with disabilities and protected veterans shall be available for inspection upon request by any employee or applicant for employment. Please contact HRCompliance@entergy.com to schedule a time to review the affirmative action plan during regular office hours.

WORKING CONDITIONS:

As a provider of essential services, Entergy expects its employees to be available to work additional hours, to work in alternate locations, and/or to perform additional duties in connection with storms, outages, emergencies, or other situations as deemed necessary by the company. Exempt employees may not be paid overtime associated with such duties.

Please note: Authorization to work in the United States is a precondition to employment in this position. Entergy will not sponsor candidates for work visas for this position.

Similar Jobs

company-logo

Lead Software Engineer

logo
Energy Hire
Job TypeFull time
Salary
$120000 - $180000
Dallas, Texas
7 months ago
company-logo

Information Security Analyst Senior Lead - Threat Hunter

Entergy
 
The Woodlands, TX
28 days ago
company-logo

Senior/Information Security Analyst

Western Farmers Electric Cooperative
Job Typefull time
Salary
$89710 - $155088
Moore, OK
about 2 months ago
company-logo

Senior Cyber Active Threat Analyst

The Nuclear Company
Job Typefull time
Salary
$121000 - $143000
Seattle, WA
3 months ago
company-logo

Senior Security Analyst

VoltaGrid, LLC
Job Typefull time
 
Cypress, TX
3 months ago
company-logo

Senior Cybersecurity Risk Analyst

PPL Corporation
Job Typefull time
 
Providence, RI
2 months ago
company-logo

Threat Intelligence Analyst

NW Natural
Job Typefull time
Salary
$95150 - $153200
Portland, OR
22 days ago
company-logo

Information Security Analyst

PNM
Job Typefull time
Salary
$82463 - $140187
Albuquerque, NM
22 days ago
E

Senior Cybersecurity Analyst

Evrecruit.io
Job Typefull time
 
Columbus, OH
2 months ago
company-logo

Senior Cybersecurity Analyst

Precision Drilling
Job Typefull time
 
Calgary, AB
3 months ago
company-logo

Cyber Security Architect Lead

ERCOT
Job Typefull time
Salary
$132078 - $224536
Austin, TX
2 months ago
company-logo

Security Analyst

SANTEE COOPER
Job Typefull time
Salary
$66390 - $82980
Moncks Corner, SC
2 months ago
company-logo

Security Analyst

Santee Cooper
Job Typefull time
Salary
$66390 - $128200
Moncks Corner, SC
2 months ago
company-logo

Information Security Specialist (Risk Management)

Itron, Inc.
Job Typefull time
 
Austin, TX
28 days ago
company-logo

Information Security Specialist (Risk Management)

Itron
Job Typefull time
 
Austin, TX
28 days ago
company-logo

Lead specialist - cybersecurity

Parkland Corporation
Job Typefull time
 
Calgary, AB
about 2 months ago
company-logo

Senior Manager of Information Security

Pattern Energy
Job Typefull time
 
Houston, TX
about 2 months ago
company-logo

Senior Manager, Cyber Security Risk Management

Irving Oil
Job Typefull time
 
Saint John, NB
22 days ago
company-logo

CyberSecurity Analyst

NiSource
Job Typefull time
Salary
$82200 - $123200
Columbus, OH
24 days ago
company-logo

Cybersecurity Analyst

ProEnergy Services
 
Houston, TX
27 days ago

Trending Jobs

company-logo

Lead Software Engineer

Energy Hire
Job TypeFull time
Salary
$120000 - $180000
Dallas, Texas
7 months ago
company-logo

Industrial Craft Electricians for 2026 Start– Kennecott Copper

Rio Tinto
Job Typefull time
 
Salt Lake City, UT
2 months ago
company-logo

Record Management Associate

Dream Home Inspection LLC
Job TypeFull time
Salary
$32932 - $40932
Los Angeles, California
about 2 months ago
company-logo

Oil & Gas Landman

Petroso Land Services
Job TypeContract
 
Bryan, Texas
3 months ago
company-logo

Deckhand 3

Marathon Petroleum Corporation
Job Typefull time
 
Catlettsburg, KY
about 2 months ago
company-logo

Title Landman

Norwood Land Services, LLC
Job Typecontract
 
00
2 months ago
company-logo

Data Engineer

Dream Home Inspection LLC
Job TypeFull time
Salary
$20 - $49
Baldwin, Florida
2 months ago
HE

Accounting Clerk II - Oahu

Hawaiian Electric Company, Inc.
Salary
$47840 - $47840
Honolulu, HI
2 months ago
company-logo

STOREKEEPER

Manitoba Hydro
 
Winnipeg, MB
about 2 months ago
PR

Executive Coordinator

Perpetua Resources
Job Typefull time
Salary
$55000 - $75000
Boise, ID
2 months ago
company-logo

Chemical Engineering Student - May and September 2026

Suncor
Job Typetemporary
 
Fort McMurray, AB
2 months ago
company-logo

Intern - High School - Des Moines, IA

Berkshire Hathaway Energy
Job Typeinternship
 
Des Moines, IA
2 months ago
company-logo

Nuclear Operations Technician I or Nuclear Operations Technician II - Harris Nuclear Plant

Duke Energy Corporation
Job Typefull time
 
New Hill, NC
28 days ago
company-logo

Business Line Manager

Nikkiso Clean Energy & Industrial Gases
Job Typefull time
Salary
$107614 - $158003
Seal Beach, CA
2 months ago
company-logo

Senior Engineer Nuclear Development

SRP
Job Typefull time
 
Tempe, AZ
about 2 months ago
company-logo

Power Line Technician - Fort St. John

BC Hydro
Job Typefull time
 
Fort St. John, BC
2 months ago
company-logo

Civil Engineering Summer Student - Starting Spring 2026

New Gold Inc.
Job Typeinternship
 
Emo, ON
about 2 months ago
company-logo

2026 Summer Intern: Investor Relations and Corporate Development

AltaGas
Job Typefull time
 
Calgary, AB
about 2 months ago
company-logo

Principal Land Agent

Pacific Gas and Electric
Job Typefull time, contract
Salary
$139848 - $174384
Oakland, CA
3 months ago
company-logo

Inventory Manager - Magnolia, Texas

Nabors Industries
Job Typefull time
 
Magnolia, TX
2 months ago