EMS Security Analyst
Southern Company
- Location
- Birmingham, AL, United States
- Work model
- On-Site
- Level
- Mid
- Posted
- Sep 17, 2026
Skills
About this role
EMS Security Analyst (Energy Management Systems) Birmingham, Alabama Summary of Position Duties The successful candidate will serve as a key contributor to Identity and Access Management (IAM) functions supporting critical Energy Management System (EMS) environments. Responsibilities include the administration and governance of user identities, authentication platforms, privileged access controls, directory services, and access compliance requirements within a highly regulated NERC CIP environment.
Education and Experience
Degree in computer science, MIS, electrical engineering, or equivalent experience Industry certification preferred (CISSP, CISA, CISM) or equivalent experience. Minimum of five (5) years of cybersecurity experience, including at least three (3) years of hands-on experience in Identity and Access Management (IAM), authentication services, access control administration, or related security functions.
Major Responsibilities
Manage and support identity and authentication services, including Windows domain authentication, Cisco ISE, RSA two-factor authentication, and related access control technologies. Support Windows domain administration, group policy management, and system administration for Windows and Linux platforms. Develop and maintain automation and operational efficiencies through scripting and tools utilizing Python, PowerShell, Perl, or shell scripting. Administer and support cybersecurity technologies and infrastructure used within the EMS/SCADA environment, including authentication, vulnerability management, logging, monitoring, and remote access solutions. Support cybersecurity monitoring, reporting, and analytics through platforms such as ArcSight, Tenable, BMC CMDB, Zenoss, and other enterprise security tools. Partner with subject matter experts to harden systems, reduce security risk, eliminate unnecessary network traffic, and improve overall security posture. Investigate, troubleshoot, and resolve security-related production issues while minimizing operational impact to EMS and SCADA environments. Evaluate emerging security technologies and provide recommendations that support EMS cybersecurity strategy and operational objectives. Support compliance initiatives and audits related to NERC CIP, FERC, SERC, Sarbanes-Oxley, and other applicable regulatory requirements. Develop, maintain, and implement security policies, standards, procedures, and technical controls required for the secure operation of critical infrastructure systems. Maintain current knowledge of cybersecurity threats, industry best practices, and evolving technologies applicable to operational technology (OT) and critical infrastructure environments. Knowledge, Skills, and Abilities Understanding of cybersecurity principles, operational technology (OT) environments, and business objectives to support secure and reliable operations. Excellent verbal and written communication skills with the ability to effectively communicate technical concepts to both technical and non-technical audiences. Strong analytical, critical thinking, problem-solving, and troubleshooting skills. Ability to manage multiple priorities and adapt to changing operational requirements in a high-availability environment. Strong organizational skills with the ability to quickly learn, evaluate, and apply new technologies. Ability to work effectively in a collaborative team environment while building productive relationships across departments. Behavioral Attributes Demonstrate behaviors consistent with Southern Company's Values and commitment to customer service. Be proactive, self-motivated, and accountable, with a strong sense of ownership and follow-through. Build and maintain effective working relationships with team members, customers, and stakeholders across the organization. Exhibit initiative, adaptability, and a collaborative approach to achieving team and organizational objectives. This position falls under the company’s Insider Threat Program and