Manager, Crisis Management & Resilience in Albuquerque, New Mexico at PNM Resources
Explore Related Opportunities
Job Description
POSTING DEADLINE
This position is posted until filled. This role can sit out of Albuquerque, NM or out Texas locations in Lewisville & Texas City
DEPARTMENT
Department: Crisis Management and Resilience
PREFERENCES
JOB DESCRIPTION
Manager, Crisis Management & Resilience
Salary Grade: G04
Minimum Midpoint Maximum
$110,004 - $148,506 - $187,007
This position is covered by NERC CIP cyber security standards. Prior to being hired, promoted, or transferred into the position, the candidate must successfully pass a Personnel Risk Assessment, which includes identity verification and a criminal background check. Prior to being granted unescorted access to cyber secure areas, the candidate must attend cyber security training. Annual cyber security training is also required.
SUMMARY:
Leads, plans, coordinates, trains, & manages Incident Response, Business Continuity, Emergency Management/Operations programs. Coordinates a wide array of stakeholders in affected departments & business units to effectively enhance organizational resiliency, prepare for, maintain continuity & respond to a wide variety of crises, incidents, disasters, and events, and establish and oversee implementation of corrective actions, develop policies, plans, & program activities.
ESSENTIAL DUTIES AND RESPONSIBILITIES:
Oversees the Business Continuity, Emergency Management/Operations, Incident Response Programs
Designs and/or coordinates Incident Response, Business Continuity, and Disaster Recovery exercises and drills with internal and external groups and participates as an active member of other regional and national training exercises
Develops, implements, presents, maintains, and coordinates the appropriate training programs in conjunction with the corporate training department regarding incident response, business continuity, and disaster recovery
Establishes and maintains relationships with federal, state, and local government representatives, comparable private sector colleagues, business operating units and internal stakeholders responsible for related business continuity plans and specific aspects of business continuity, disaster recovery, and incident response such as Corporate Security, Facilities, Risk Management, Human Resources, Legal, Operations, and Compliance
Maintains and ensures timely updates of all appropriate documentation including Incident Response and Business Continuity policies, plans, on-call lists, regulatory compliance evidence, and after-action reviews
Leads and manages all aspects of incidents, disasters, emergencies, and crises from identification, containment, investigation, eradication, reporting, recovery, and all necessary follow-up activities
Assembles, leads, and collaborates with cross-functional matrixed response teams and actively commands incidents/crises to achieve successful outcomes while maintaining continuity/resilience to the greatest extent possible
Acts as primary subject matter expert for cyber security incident response and associated emergency operations regulatory compliance
Maintains personal competency in related technology applications, engages in constant improvement by taking advantage of available cost-effective training opportunities
Develops and presents information to promote incident response preparedness & resiliency as core values
Regularly consumes and communicates relevant threat intelligence
Other duties as assigned
COMPETENCIES:
In-depth management, negotiation, technical skills, and demonstrated leadership and customer service skills
Ability to utilize working knowledge of information security best practices such as: NIST 800 series, ISO 27000 series, ISA, or COBIT
Excellent skills in risk assessment processes, policy development, proposals, work statements, product evaluations, and delivery of technology
Ability to understand enterprise business computing operations/requirements, and fundamental power generation operations
Knowledge of crisis management, business continuity, emergency management, incident analysis, and incident response management
Demonstrated skills in personnel management, budget management, and conflict management
Be an action-oriented, detail-oriented, goal-oriented self-starter with the ability to multi-task, effectively manage time, manage shifting priorities, and thrive in a complex, dynamic, fast-paced, ambiguous, and sometimes chaotic environment
Ability to organize and distill complex technical concepts into simple and easy to understand instructions and action items during an incident
QUALIFICATIONS
MINIMUM EDUCATION AND/OR EXPERIENCE:
Bachelor's degree in a related field with seven to nine years related experience, or equivalent combination of education and/or experience related to the discipline.
Related professional certification preferred (e.g., CISSP, CISA, Business Continuity Professional, Certified Incident Handler, etc.).
Master's degree preferred.
SUPERVISORY RESPONSIBILITIES:
Hires, trains, evaluates, rewards, and terminates employees. Designs, organizes, prioritizes, schedules, and leads work assignments. Fosters good working relationships with various groups. Appraises performance, rewards and disciplines employees, addresses complaints, and resolves problems. Indirectly supervises and guides enterprise employees, contractors, and electronic system users for performance of job functions in accordance with incident response & disaster recovery scope.
COMMUNICATION SKILLS:
Ability to respond effectively to highly sensitive inquiries or complaints
Ability to effectively give persuasive speeches and presentations on controversial or complex topics to various audiences
Ability to read and interpret complex documents such as safety rules, operating and maintenance instructions, and procedure manuals
Ability to write complex reports, regulatory documents, policies and correspondence
Ability to speak effectively before a broad range of groups of stakeholders, business partners, and employees in all areas of the organization
Read, analyze, interpret, and gather relevant technical procedures, confidential information, threat intelligence, business periodicals, professional journals, cooperative directives, procedures, or governmental regulations
MATHEMATICAL SKILLS:
Ability to calculate figures and amounts such as discounts, interest, commissions, proportions, percentages, area, circumference, and volume
COMPUTER SKILLS:
In-depth knowledge and experience with mainframe and client/server applications, computer networks, and information security concepts and issues
Strong working knowledge of current marketed security tools and technologies
Strong working knowledge of industry regulations (NERC CIP, Sarbanes Oxley, PCI) and industry security standards (NIST, ISO)
Strong working knowledge of malware and network analysis and investigation preferred
Strong, working knowledge of the latest Microsoft Office Suite
ANALYSIS AND PROBLEM-SOLVING ABILITY:
Ability to strategically approach issues. Ability to be proactive, adept at working with cross-functional teams and stakeholder groups. Ability to synthesize complex information. Ability to apply creativity to problem solving and utilize analytic skills and modeling capabilities to provide ongoing insight into the business and to make recommendations and decisions. Ability to identify and develop remediation or mitigation plans as necessary. Ability to coordinate with, and lead, cross-functional team of technical experts.
DECISION MAKING:
Conducts and guides enterprise incident response and disaster recovery project and operations activities and practices within the bound of approved security programs and policies, and in accordance with generally accepted security standards.
SCOPE AND IMPACT:
Protects all enterprise computing and operational platforms for the purpose of providing and preserving confidentiality, integrity, and availability of all enterprise systems, applications, and data. Protection and recovery of systems is intended to minimize potential costs directly related to operational, legal, regulatory, and reputation risk from loss of enterprise system operation or confidential or proprietary information. Failure to protect and recover systems in a timely manner from an incident exposes company to heightened regulatory oversight, monetary sanctions, increased expense, and loss of production revenue.
PHYSICAL DEMANDS:
While performing the duties of this job, the employee is frequently required to stand, sit, and/or walk up to 2/3 of the time. The employee must occasionally lift and/or move up to 30 pounds.
Ability to stoop, kneel, crouch, or crawl. Manual dexterity is required to perform computer applications and good vision is required to perform all aspects of the job. May require long periods of time in conference or meeting when one is required to talk and/or listen. Required to be on call 24-hours a day for emergencies.
Out-of-state travel is occasionally required.
WORK ENVIRONMENT:
Office environment or remote as needed.
SAFETY AND ADA STATEMENT
Safety Statement:
Safety is a core value at (TXNM Energy/PNM/TNMP) and our vision, "everyone goes home safe", reflects our commitment to promoting an environment conducive to learning, improving and building safety practices. Our safety value is built upon the belief that every employee deserves to work in an environment free from harm.
Americans with Disabilities Act (ADA) Statement:
If you require assistance with the job application process due to a disability, please contact HR ADA Analyst, at 505-241-4627.