Sr Cyber Security Engineer
Overview
Who We Are
As the largest private-sector power producer in the world and the nation's largest producer of clean and reliable energy, Constellation is focused on our purpose: lighting the way to a brilliant tomorrow for all. We have been the leader in clean energy production for more than a decade, and we are cultivating a workplace where our employees can grow, thrive, and contribute. Now integrated with Calpine, our portfolio includes 55 gigawatts of capacity from nuclear, natural gas, geothermal, hydro, wind and solar facilities, with the generating capacity to power the equivalent of 27 million homes.Our culture and employee experience make it clear: We are powered by passion and purpose. Together, we're creating healthier communities and a cleaner planet, and our people are the driving force behind our success. At Constellation, you can build a fulfilling career with opportunities to learn, grow and make an impact. By doing our best work and meeting new challenges, we can accomplish great things. Join us in meeting the country's energy needs today and tomorrow.
Total Rewards
Constellation offers an extensive selection of benefits and rewards to help our employees thrive professionally and personally. We provide competitive compensation and a wide-range of benefits that support both employees and their families, helping them prepare for the future. In addition to highly competitive salaries, eligible employees are offered a bonus program, 401(k) with company match, employee stock purchase program; comprehensive medical, dental and vision benefits, including robust wellbeing programs; disability and life insurance benefits; paid time off for vacation, holidays, and sick days; and much more.
Expected salary range of $118,800 to $132,000, varies based on experience, along with comprehensive benefits package that includes bonus and 401(k).
Responsibilities
Primary Purpose of Position
The Sr. Cyber Security Engineer (CSE) will execute the highly technical, tactical elements of the cyber security strategy, eliminating a functional cyber security capability gap while providing pro-active cyber security risk management. The CSE will act as a liaison to the Security Architect and Cloud and Infrastructure Operations/Engineering and Utility IT teams to effectively communicate and assist in architecting and implementing effective security solutions to achieve North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) compliance. The CSE will ensure the implementation of system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation, and will perform security reviews to identify gaps in security architecture. The CSE will assist in the development of appropriate security risk management plans. The Sr. Cyber Security Engineer (CSE) will work closely (and primarily) with IT, Physical Security and Power IT to implement effective NERC CIP standards and requirements; provide analytical and technical recommendations where needed. Work with all parties for new standards or requirements for remediation and implementation efforts. Meet the business clients (IT/OT) and management to help specify and negotiate application security requirements; work closely with application teams to ensure secure transition of applications into production. Provide guidance around architecting and implementing effective NERC CIP solutions; develop documentation to support ongoing security systems operations, maintenance, and problem resolution. Ability to mitigate vulnerabilities, remediate incidents, and affect change requests in support NERC CIP remediation efforts.
Primary Duties and Accountabilities
- Provide analytical and technical security recommendations to other team members, technical teams, and business clients, including: (25%) Provide technical guidance regarding NERC CIP Standard and Requirement changes and implementations as well as other stakeholders and experts. Work with stakeholders to resolve issues around NERC CIP compliance. Provide input to implementation plans and standard operating procedures as they relate to information systems security. Develop specific risk mitigation strategies for systems and/or applications related to NERC CIP.
- Work closely with technical teams to implement effective security configurations/requirements, including: (25%) Verify security measures are implemented to resolve vulnerabilities, mitigate risks, and recommend security changes to system or system components as needed meeting NERC CIP requirements. Verify and update documentation reflecting the application/system security design features related to NERC CIP for implementation team. Verify security requirements are in place for all applications related to NERC CIP.
- Work closely with all teams to ensure secure transition of new requirements into production. (25%)
- Excellent communication skills and the proven ability to work effectively with all levels of IT and business management.
- All other job assignments and/or duties pursuant to company policy or as directed by management to include but not limited to: (Emergency Response duties and/or coverage, Department duty coverage and/or call out, and positions outside of department in support of outage activities etc.)
Minimum Qualifications
- Bachelor's degree in Computer Science, Information Technology (IT), or a related discipline with 7 years of experience in cyber security
- Associate's degree in Computer Science or Engineering related discipline with 9 years of experience in IT or engineering
- High school diploma/GED with 11 years of experience in IT or engineering
- Nuclear or related industry experience
- Experience in change management techniques with new technology implementation
- Maintain minimum access requirement or unescorted access requirements, as applicable, and favorable medical examination and/or testing in accordance with position duties
Qualifications
Preferred Qualifications
- Graduate degree in cyber security or related area of expertise.
- Relevant security certifications (Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Global Information Assurance Certification (GIAC), Microsoft Certified Systems Engineer (MCSE), Red Hat Certified Engineer (RHCE), Cisco Certified Network Professional (CCNP), Certified Cloud Security Professional (CCSP))
- Extensive technical NERC CIP experience and application across multiple requirements
- Strong understanding of enterprise, network, system, and application level security engineering principles
- Demonstrable, Hands-on expertise in the following technical disciplines: Operating Systems (Microsoft, Linux, UNIX) Networking (Cisco, RuggedCom and Palo Alto), Cryptography (PKI, lifecycle management, symmetric) Network Security Engineering (secure network design, IDS/IPS, monitoring, firewalls) Virtualization (VMware, Hyper-V) Remote Access Methods (VPN, Citrix, MFA) ICS / SCADA System Security (design, controls) Compliance Tools (Tripwire, Splunk, AssurX/CATSWeb)