| Title: | Cybersecurity Analyst |
|---|---|
| ID: | 1684 |
| Department: | ITS |
| Bonus: | N/A |
About Elizabeth River Crossings (ERC)
Elizabeth River Crossings (ERC) operates and maintains critical transportation infrastructure serving Hampton Roads. Technology and cybersecurity are essential to our mission of providing safe, reliable, and secure transportation services to the communities we serve.
We are seeking a Cybersecurity Analyst to join our Technology team and play a key role in protecting ERC's information systems, operational technologies, data, and cloud environments. This position combines hands-on cybersecurity operations with risk management, compliance oversight, vendor security management, and strategic security improvement initiatives.
This is an exciting opportunity for a cybersecurity professional who enjoys solving complex challenges, staying ahead of emerging threats, and working across the organization to strengthen security posture.
Position Summary
The Cybersecurity Analyst is responsible for monitoring, protecting, and continuously improving ERC's cybersecurity environment. This role leads security operations, vulnerability management, compliance activities, security awareness initiatives, and third-party cybersecurity oversight.
The successful candidate will work closely with internal technology teams, business stakeholders, vendors, and ERC's parent organization to ensure security controls effectively protect systems, networks, applications, and data from evolving threats.
Key Responsibilities
Security Operations & Incident Response
- Monitor security events, alerts, and indicators of compromise across enterprise systems and cloud environments.
- Investigate security incidents and coordinate response and remediation activities.
- Lead day-to-day cybersecurity monitoring and incident management efforts.
- Proactively identify emerging threats and recommend protective measures.
- Maintain and improve security monitoring, detection, and response capabilities.
Risk Management & Vulnerability Management
- Conduct vulnerability assessments and coordinate remediation efforts.
- Perform risk analyses and develop mitigation strategies.
- Review system configurations and security controls to identify weaknesses and opportunities for improvement.
- Assist with cybersecurity insurance requirements and risk reporting activities.
Security Engineering & Administration
- Support the secure configuration and management of:
- Endpoint protection platforms
- Firewalls and network security technologies
- Cloud services and infrastructure
- Identity and access management systems
- Security monitoring and logging solutions
- Manage user access controls and privileged account security.
- Collaborate with IT teams to implement security best practices across all technology platforms.
Governance, Compliance & Vendor Security
- Lead cybersecurity compliance activities, including PCI DSS and other regulatory or contractual requirements.
- Develop, maintain, and improve cybersecurity policies, standards, procedures, and controls.
- Coordinate cybersecurity audits and assessments.
- Manage third-party cybersecurity reviews and vendor risk assessments.
- Serve as the primary liaison for cybersecurity matters involving contractors, service providers, and ERC's parent organization.
Security Awareness & Training
- Help develop and deliver security awareness training programs.
- Coordinate phishing simulations and employee education initiatives.
- Promote a strong culture of cybersecurity throughout the organization.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience.
- 3+ years of experience in cybersecurity, information security, network security, or related technology roles.
- Experience with security monitoring, incident response, vulnerability management, and risk assessment.
- Familiarity with cybersecurity frameworks and standards such as:
- NIST Cybersecurity Framework
- CIS Controls
- ISO 27001
- PCI DSS
- Working knowledge of:
- Endpoint security solutions
- Firewalls and network security technologies
- Microsoft 365 security tools
- Cloud security principles
- Identity and access management
Preferred Qualifications
- Industry certifications such as:
- CISSP
- Security+
- CySA+
- CEH
- CISM
- GIAC certifications
- Experience with security information and event management (SIEM) platforms.
- Experience supporting cloud environments such as Microsoft Azure or AWS.
- Experience conducting vendor risk assessments and compliance audits.
What Makes This Role Unique
- Protect critical transportation infrastructure serving the Hampton Roads region.
- Work across enterprise IT, cloud services, operational technology, and vendor ecosystems.
- Lead meaningful security initiatives with visible impact on organizational risk reduction.
- Collaborate directly with executive leadership, technology teams, and industry partners.
- Help shape the future cybersecurity strategy of a growing organization.

