Share this Job

Cyber Security Analyst -Vulnerability

Date: Nov 20, 2022

Location: Newark, NJ, US

Company: PSEG

Requisition: 72287

PSEG Company: PSEG Services Corp.    

Salary Range: $ 76,700 - $ 145,700 

Incentive: PIP 10%   

Work Location Category: Remote Non-Local  


PSEG operates under a Flexible Work Model where flexible work is offered when job requirements allow. In support of this model, roles have been categorized into one of four work location categories: onsite roles, hybrid roles that are a blend of onsite and remote work, remote local roles that are primarily home-based but require some level of purpose-driven in-person interaction and living within a commutable distance, and remote non-local roles that can be effectively performed remotely with the ability to work in approved states.


PSEG offers a unique experience to our more than 12,000 employees – we provide the resources and opportunities for career development that come with being a Fortune 500 company, as well as the attention, camaraderie and care for one another you might typically associate with a small business. Our focus on combatting climate change through clean energy technology, our new net zero climate vision for 2030 and enhanced commitment to diversity, equity and inclusion; and supporting the communities we serve make this a particularly exciting time to join PSEG.


Consistent with our core commitment of safety, PSEG has made the decision to require all new hires to be fully COVID-19 vaccinated as a condition of hire.  "Full vaccination" is defined as two weeks after both doses of a two-dose vaccine or two weeks since a single-dose vaccine has been administered. Anyone unable to be vaccinated, either because of a sincerely held religious belief or a disability can request a reasonable accommodation.

Job Summary

A cyber security analyst is a hands-on practitioner and representative of the cybersecurity defense team. The role is technical, and candidates must possess a solid understanding of information security and preferably have held positions in cybersecurity and systems administration. The role also requires an understanding of business and governance process. Vulnerability management analysts are responsible for the overall management lifecycle of the program. They must understand applications, operating systems, networking, cloud infrastructure and basic attacker tactics, techniques and procedures (TTPs). Additionally, analysts are expected to maintain a high level of rigor to stay up-to-date with advancements in technology, while also retaining knowledge of older systems and applications in use. 

Please note this position is hybrid, comprised of remote and in office work.  PSEG reserves the right to amend the hybrid model at any time.

Job Responsibilities

Job Responsibilities include:

  • Provides technical expertise and support to clients, IT management and staff in cybersecurity threat risk assessments, development, testing and the implementation and operation of appropriate information security plans, procedures, and control techniques designed to prevent, minimize or quickly recover from cyber-attacks or other serious events.
  • Reviews complex architecture design diagrams and documents for new technologies and changes to existing technologies to determine risks and provide recommendations and mitigations
  • Utilizes information security technologies
  • Conduct continuous discovery and vulnerability assessment of enterprise-wide assets.
  • Document, prioritize and formally report asset and vulnerability state, along with remediation recommendations and validation.
  • Follows cyber security news and alerts, understands complex attack vectors and risks, and identifies and evaluates emergent cyber security threats and vulnerabilities. Recommends appropriate corrective actions for information security incidents and provides risk mitigation recommendations to management and team.
  • Experience with cloud computing and can implement strong security to protect cloud first environment.
  • Designs process flows to be implemented in security automation tools to automatically respond to threats quickly and effectively.
  • Provides technical expertise in threat/risk assessments
  • Defines, designs, and implements strategies to protect against emerging threats using security tools
  • Responds to security incidents

Job Specific Qualifications


  • Bachelor Degree in Computer Science, Information Systems, Cyber Security, Engineering or related discipline
  • 4 or more years of experience in Information Security
  • Hands-on technical individual, performing IT security functions and maintaining systems, while providing technical guidance to the team.
  • Proficient with vulnerability management solutions such as Qualys, Nexpose, Nessus, Kenna Security, Tanium and open source
  • Understanding of Windows and *nix operating systems, endpoint applications, networking protocols and devices
  • Works independently with little or no supervision.
  • Experience conducting organization-wide vulnerability scanning and remediation processes.
  • Understanding of OWASP, CVSS, the MITRE ATT&CK framework and the software development lifecycle. 
  • Experience with cloud computing and can implement strong security to protect cloud first environment.
  • Works independently with little or no supervision.
  • Excellent oral and written communication skills.
  • Excellent leadership, technical teamwork, and interpersonal skills.
  • Demonstrated ability to work in strong team environment, constantly teaching and learning from other team members.
  • Demonstrated ability to foster working relationships with the team, IT Management and Client departments.
  • Technical experience includes: information / data / network / computer security design, administration and/or assessment.
  • Broad knowledge of information systems including Windows security, network security, systems development, communication networks, security software/hardware and operating systems.
  • Experience with key information security technologies such as SIEM, firewalls, intrusion detection/prevention systems, vulnerability assessment, encryption, identity and access control systems, anti-malware, and security event analysis.
  • Leadership, planning and organizing, results orientation, technical/professional knowledge.


  • Experience in Operational Technology (OT) Security is a plus
  • Preferably some experience with vulnerability management across Amazon Web Services (AWS), Microsoft Azure, IBM Cloud, or Google Cloud Platform (GCP).
  • Experience with cyber investigations and/or threat hunting, or using information security technologies such as antivirus, IDS/IPS, SIEM, endpoint detection & response, DLP, data encryption, proxies, and network access control, as well as security policies and procedures, and incident response

Minimum Years of Experience

4 years of experience


Bachelors in Computer Science or Information Technology
Bachelor in Engineering


None Noted


Certain positions at the Company may require you to have access to Part 810-Controlled Information.  Under the law, the Company is limited in who it can share this information with and in certain circumstances it is necessary to obtain specific authorization before the Company can share this information.  Accordingly, if the position does require access to this information, you must complete a 10 CFR Part 810 Export Control Compliance Nationality Request Form, a copy of which will be provided to you by Talent Acquisition if an offer is made.  If there is a need for specific authorization, due to the time it takes to obtain authorization from the government, we will likely not be able to further proceed with an offer.

Candidates must foster an inclusive work environment and respect all aspects of diversity. Successful candidates must demonstrate and value differences in others' strengths, perspectives, approaches, and personal choices.


As an employee of PSE&G or PSEG LI, you should be aware that during storm restoration efforts, you may be required to perform functions outside of your routine duties and on a schedule that may be different from normal operations.


Certain positions at the Company may require you to have access to 10 CFR Part 810 controlled information.  If the position does require access to this information, the Talent Acquisition representative will provide further details upon making an offer.


PSEG is an equal opportunity employer, dedicated to a policy of non-discrimination in employment, including the hiring process, based on any legally protected characteristic. Legally protected characteristics include race, color, religion, national origin, sex, age, marital status, sexual orientation, disability or veteran status or any other characteristic protected by federal, state, or local law in locations where PSEG employs individuals.


Business needs may cause PSEG to cancel or delay filling position at any time during the selection process.


This site ( is strictly for candidates who are not currently PSEG employees. PSEG employees must apply for jobs internally through emPower which can be accessed through by clicking on the emPower icon, then selecting careers.



PSEG is committed to providing reasonable accommodations to individuals with disabilities.  If you have a disability and need assistance applying for a position, please call 973-430-3845 or email  If you need to request a reasonable accommodation to perform the essential functions of the job, email Any information provided regarding a disability will be kept strictly confidential and will not be shared with anyone involved in making a hiring decision.



Know your Rights: Workplace Discrimination is Illegal

Pay Transparency Nondiscrimination Provision

Nearest Major Market: Newark
Nearest Secondary Market: New York City

Job Segment: Cloud, Recruiting, Testing, Computer Science, Information Security, Technology, Human Resources