Senior Security Analyst – Cybersecurity Operations

City of Tacoma
Tacoma, WA


Are you passionate about safeguarding critical infrastructure and operational systems from cyber threats? Are you looking to join a mission-driven team that values collaboration, technical excellence, and public service? If so, Tacoma Power invites you to explore this exciting opportunity!

We are seeking a highly skilled Senior Security Analyst to join our Cybersecurity Operations team within the Utility Technology Services (UTS) section. In this pivotal role, you will help ensure the confidentiality, integrity, and availability of Tacoma Public Utilities' (TPU) digital assets and operational technology (OT) systems. Your leadership in threat detection, incident response, and security operations will directly support TPU’s ability to deliver safe, reliable, and resilient utility services to the communities we serve.

Job Responsibilities:

  • Monitor and Analyze Security Events: Lead daily threat monitoring, triage, and analysis using SIEM tools to detect and assess cybersecurity threats across TPU’s systems.
  • Investigate and Respond to Incidents: Conduct end-to-end incident response and root cause investigations, correlating data from tools such as SIEM, EDR, and threat intelligence platforms to contain and resolve security events.
  • Enhance Detection Capabilities: Develop, tune, and refine detection logic and correlation rules in collaboration with engineering teams to improve alert quality and reduce false positives.
  • Proactively Hunt for Threats: Perform threat hunting using behavioral analysis, anomaly detection, and intelligence sources to identify threats not captured by automated systems.
  • Manage Endpoint Security Tools: Administer and optimize endpoint detection and response (EDR) solutions and OT network visibility, detection, and alerting platforms, ensuring accurate alerting, reliable functionality, and strong platform performance.
  • Collaborate with Stakeholders: Communicate with internal teams and business units during investigations to gather context, validate findings, and coordinate incident resolution.
  • Support Regulatory Compliance (CIP): Maintain assigned CIP responsibilities by supporting documentation, audit readiness, and evidence gathering to ensure compliance with security standards.

Minimum Education*
Bachelor's degree in information technology, cybersecurity or directly related field

Minimum Experience*
4 years of progressively responsible information technology experience related to assignment

Licensing, Certifications and Other Requirements
Security+ or related certification (GIAC GCIA, GIAC GCIH, CISSP)

As Assigned:
Washington State Driver's License

Depending on assignment, some positions may require the ability to pass additional background checks and / or obtain additional certifications, with maintenance thereafter

*Equivalency: 1 year of experience = 1 year of education
Physical Requirements & Working ConditionsPositions in this class typically require:
  • remaining in a stationary position for 90% of the time with occasional movement to access office files, machinery and similar productivity tools (standing, sitting, walking).
  • constant operation of a computer, as well as use of a calculator, printer and similar office tools (fingering, grasping, feeling, repetitive motions).
  • communication and the exchange of information with others (hearing, seeing, talking).
  • occasionally exerting up to 10 pounds of force to move, transport or position objects (sedentary work).
Work may also occasionally require:
  • movement around the workplace to pick up objects (stooping, walking, reaching).
  • traversing, ascending or descending stairs, sloped terrain, or similar environments (climbing, balancing, walking).
  • exerting up to 20 pounds of force to move, transport or position objects (light work).

Knowledge & Skills

The ideal candidate would thrive in an environment that requires the ability to both collaborate/work with a team on large work efforts. Additionally, they would have the following skills/certification:

  • Expertise with SEIM platforms (e.g., LogRhythm, Splunk).
  • Experience managing EDR platforms (e.g., Carbon Black, CrowdStrike).
  • Experience managing OT network visibility & detection platforms (e.g., Nozomi, ClarOTY, Dragos).
  • Experience in conducting security investigations and incident response activities.
  • Strong understanding of MITRE ATTACK, threat modeling, and TTP analysis.
  • Familiarity with scripting for automation (e.g., Python, PowerShell).
  • Strong soft skills and customer service experience.
  • Incident response leadership in enterprise environments.
  • Certifications: Security+, GIAC GCIA, GIAC GCIH, or equivalent.
  • Experience with NERC-CIP regulatory standards.

***Studies have shown that people of color and women are less likely to apply for jobs unless they meet all listed qualifications. We are most interested in finding the best candidate for the job, and that candidate may be one from a less traditional background. If you have transferable skills and experience, please tell us about them.***

Pay Details:
Annual Salary $118,560.00 - $166,920.00This recruitment is being managed by Kye Merritt. If you would like to be notified of similar opportunities or stay connected with things going on at Tacoma Public Utilities and the City of Tacoma, connect with her on LinkedIn.

City of Tacoma Commitment to Diversity and Inclusion
At the City of Tacoma, we're on a mission to make our workforce as diverse and inclusive as the community we serve. We're committed to eliminating racial and other disparities, and we actively seek out candidates from a wide range of backgrounds and cultures. Join our team at the City of Tacoma and help us build a more vibrant, inclusive, and equitable community for all.


Tacoma Power
Tacoma Power is an almost 100% hydroelectric, municipally-owned public power utility, located in Tacoma. We serve approximately 180,000 customers as one of the three operating divisions of Tacoma Public Utilities, alongside Tacoma Water and Tacoma Rail. As one of the most livable, walkable cities in the country, you'll find that Tacoma is a great fit for all interests with places to bike, run, hike, and explore, the perks of a big city, and the charm of a small town. We welcome you to take a look at our website and discover how the City of Tacoma can make your next career move part of our combined destiny:
http://www.cityoftacoma.org/
https://www.mytpu.org/
http://www.traveltacoma.com/

Apply
Interested individuals shouldapply online. Please attach a detailed resumethat includes job experience, major responsibilities and accomplishments related to this position.

Reference checks will be conducted on final candidates and appointment is subject to passing a background check.

Communication from the City of Tacoma:
We primarily communicate via email during the application process. Emails from cityoftacoma.org and/or governmentjobs.com must be placed on your safe domain list to ensure that you receive notifications in a timely manner. As a precaution, you may also want to check your junk email folders.

In order for your application materials to be considered, all information must be submitted by the closing date and time listed on this job announcement.

For assistance with the NEOGOV application process, questions regarding this job announcement, or if you are experiencing complications while applying, please contact the Human Resources office at (253) 591.5400 by 4:00 pm of the closing date of the job announcement. This will allow us to assist you before the job announcement closes.

// // //