Talent.com
Sr OT Systems Security Engineer
Sr OT Systems Security EngineerExelon • Owings Mills, MD, United States
Sr OT Systems Security Engineer

Sr OT Systems Security Engineer

Exelon • Owings Mills, MD, United States
5 days ago
Job type
  • Full-time
Job description

Who We Are

We're powering a cleaner, brighter future.

Exelon is leading the energy transformation, and we're calling all problem solvers, innovators, community builders and change makers. Work with us to deliver solutions that make our diverse cities and communities stronger, healthier and more resilient.

We're powered by purpose-driven people like you who believe in being inclusive and creative, and value safety, innovation, integrity and community service. We are a Fortune 200 company, 19,000 colleagues strong serving more than 10 million customers at six energy companies Atlantic City Electric (ACE), Baltimore Gas and Electric (BGE), Commonwealth Edison (ComEd), Delmarva Power & Light (DPL), PECO Energy Company (PECO), and Potomac Electric Power Company (Pepco).

In our relentless pursuit of excellence, we elevate diverse voices, fresh perspectives and bold thinking. And since we know transforming the future of energy is hard work, we provide competitive compensation, incentives, excellent benefits and the opportunity to build a rewarding career.

Are you in?

Primary Purpose

PRIMARY PURPOSE OF POSITION

The Sr OT Systems Security Engineer (OTSSE) will support implementation of the Operational Technology (OT) Security Governance program and provide proactive cyber security risk management. The OTSSE will act as a liaison to OT teams, Security Architects and other CISS teams to effectively communicate and lead OT security engineering design specification, architecting and implementing effective OT security solutions. The OTSSE will also assist with vulnerability mitigation plans, incident response, and security event monitoring engineering support. The OTSSE will ensure the implementation of OT security measures in accordance with established procedures to ensure safety, reliability, confidentiality, integrity, availability, authentication, and non-repudiation, and will perform OT security reviews to identify gaps in security design and architecture.

Note : This is a hybrid position (in-office with remote flexibility). Employees are required to be in office at least three days per week (Tuesday, Wednesday, and Thursday). This position must sit out of our Baltimore, MD, Newark, DE, Owings Mills, MD or Kennett Square, PA office. This position is NOT eligible for relocation assistance.

Primary Duties

PRIMARY DUTIES AND ACCOUNTABILITIES

Provide analytical and technical security recommendations to other team members, technical teams, and business clients, including : Provide OT cyber security guidance to leadership. Work with stakeholders to design OT security design specifications and architectures. Provide input to implementation plans and standard operating procedures as they relate to OT cyber security.

Develop specific OT cyber security countermeasures and risk mitigation strategies for systems and / or applications.

Work closely with technical teams to implement effective security configurations / requirements, including :

Analyze and design security measures to resolve OT vulnerabilities, mitigate risks, and recommend security changes to system or system components as needed.

Mitigate / correct security deficiencies identified during Factory Acceptance Testing, Site Acceptance Testing, and / or recommend risk acceptance for the appropriate senior leadership. Verify and update security engineering documentation reflecting the application / system security design features. Verify minimum security design specifications are in place for OT assets to support security event monitoring and incident response.

Work closely with the R&D and innovation teams to ensure secure implementation of OT systems into production. (

Assist with vulnerability mitigation planning, incident response and security event monitoring engineering activities for security and compliance requirements

Conduct engagement and provide OT cyber security training to OT personnel

Job Scope

JOB SCOPE

The Senior Operational Technology Systems Security Engineer (OTSSE) will work closely (and primarily) with business OT teams, IT / Utility communications, Engineering and OT clients to implement effective security configurations and requirements; provide analytical and technical security recommendations to other team members, technical teams, and business clients; support OT Security Governance efforts; meet with Exelon business clients and management to help specify and negotiate system / network / application security requirements; work with the R&D and innovation teams to ensure secure implementation of OT systems into production; develop OT security solutions to improve security event monitoring and detection with CISS standards; actively participate in relevant industry OT cyber security workgroups and forums; act as a liaison to business OT teams, Security Architect and IT / UComm, and OT stakeholders to effectively communicate and lead OT security engineering design specification, architecting and implementing effective OT security solutions; develop documentation to support ongoing OT security systems operations, maintenance, and problem resolution; advise on vulnerability mitigation plans, and develop security event monitoring solutions to improve incident detection; work with the Security Policy and Risk Office to assist with the identification, analysis, and remediation of Exelon OT cyber security risk

Minimum Qualifications

MINIMUM QUALIFICATIONS

Bachelors Degree in Computer Science, engineering, or a related discipline, and typically 5 or more years of solid, diverse experience in OT / ICS, or equivalent combination of education and work experience.

At least 3 years of demonstrated experience in the energy sector

At least 5 years of demonstrable security engineering or related experience, including :

Knowledge of disaster recovery continuity of operations plans

Knowledge of Risk Management Framework (RMF) requirements

Knowledge of incident response and handling methodologies.

Knowledge of network security architecture concepts including topology, protocols, components, and principles

Knowledge of authentication, authorization, and access control methods.

Knowledge of cryptography and cryptographic key management concepts

Knowledge of database systems

Knowledge of embedded systems

Knowledge of system fault tolerance methodologies

Knowledge of how system components are installed, integrated, and optimized

Knowledge of ICS supply chain security and risk management policies, requirements, and procedure

Knowledge of human-computer interaction principle

Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)

Ability to design architectures and frameworks

Skill in applying cybersecurity methods, such as firewalls, demilitarized zones, and encryption

Knowledge of network access, identity, and access

Knowledge of network protocols such as TCP / IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services

Knowledge of network design processes, to include understanding of security objectives, operational objectives, and tradeoffs

Knowledge of parallel and distributed computing concepts

Knowledge of key concepts in security management (e.g., Release Management, Patch Management)

Knowledge of configuration management techniques

Comprehensive understanding of change management techniques associated with new technology implementation.

Demonstrated experience producing an economic business case.

Demonstrated leadership ability.

Proven analytical, problem solving, and consulting skills.

Excellent communication skills and the proven ability to work effectively with all levels of OT and business management.

Preferred Qualifications

PREFERRED QUALIFICATIONS

Graduate degree in cyber security, engineering, or related area of expertise.

Relevant security certifications (CISSP, CISM, GICSP)

At least 3 years of experience as part of an electric utility

Appropriate technical skills and in-depth knowledge of business unit functions and applications, including :

Demonstrated experience and subject matter knowledge of SCADA, ICS, Distribution Automation, Smart Grid, DMS, and ECS systems architecture.

Demonstrated experience and subject matter knowledge of security vulnerabilities and mitigation strategies for industrial SCADA protocols such as DNP3, IEC-61850, Modbus, Tejas V, CDC 2, Vancomm, etc.

Demonstrated experience in security risk assessments, requirements development, secure design analysis, architecture assessment and development, and security testing of applications and systems.

Extensive experience developing, evaluating, and implementing OT security architectures, technologies, standards, and practices to secure applications and OT.

Demonstrated knowledge and experience in the implementation of governance frameworks and security risk management processes, such as NIST, ISO, ISA99, IEC 62443 guidelines and standards.

Demonstrated experience in addressing regulatory compliance for the security requirements in applicable laws and regulations, such as NERC CIP, CFATS, or API 1164.

Demonstrated experience and subject matter knowledge in cyber security for applications, web architectures, operating systems, databases, and networks.

Knowledge and experience in application security standards, methodologies, and technologies.

Solid capability to assess network architectures and operating systems for vulnerabilities and develop appropriate security countermeasures.

Solid knowledge and experience with OT security aspects of operating systems, embedded operating systems, Programmable Logic Controllers (PLC), Remote Terminal Units (RTU), and Protection and Control relays.

Experience in assessing security applications and systems, such as firewalls, security appliances, IDS / IPS, SSL or TLS, IPSec.

Ability to demonstrate analytical skills, technical knowledge, and practical application of cyber and information security principles to business leaders and technical staff.

Benefits

Benefits

Annual salary will vary based on a candidate's skills, qualifications, experience, and other factors : $102,400.00 / Yr. - $140,800.00 / Yr.

Annual Bonus for eligible positions : 15%

401(k) match and annual company contribution

Medical, dental and vision insurance

Life and disability insurance

Generous paid time off options, including vacation, sick time, floating and fixed holidays, maternity leave and bonding / primary caregiver leave or parental leave

Employee Assistance Program and resources for mental and emotional support

Wellbeing programs such as tuition reimbursement, adoption and surrogacy assistance and fitness reimbursement

Referral bonus program

And much more

Note : Exelon-sponsored compensation and benefit programs may vary or not apply based on length of service, job grade, job classification or represented status. Eligibility will be determined by the written plan or program documents.

Exelon is proud to be an equal opportunity employer and employees or applicants will receive consideration for employment without regard to : age, color, disability, gender, national origin, race, religion, sexual orientation, gender identity, protected veteran status, or any other classification protected by federal, state, or local law. If you are an individual with a disability and need an accommodation to complete the application, please email us at DandI@exeloncorp.com.

Create a job alert for this search

Sr Security Engineer • Owings Mills, MD, United States

Related jobs
SIGN ON BONUS Senior Information Systems Security Engineer (ISSE)

SIGN ON BONUS Senior Information Systems Security Engineer (ISSE)

Power3 Solutions and Partnering Companies • Fort Meade, MD, United States
Full-time
Senior Information Systems Security Engineer (ISSE).Linthicum Heights, MD • Government / Military.Full-Time | Fully Funded | $170,000-$250,000 (Depending on Experience). Engineer Trust in Every System...Show more
Last updated: 5 days ago • Promoted
System Security Engineer

System Security Engineer

ClearEdge IT Solutions • Baltimore, MD, United States
Full-time
Join ClearEdge and be a part of a dynamic team that solves some of the DoD's most complex technical challenges.Every day, ClearEdge empowers our customers in government and industry with innovative...Show more
Last updated: 5 days ago • Promoted
Senior Security Engineer Subject Matter Expert (SME)

Senior Security Engineer Subject Matter Expert (SME)

4A Consulting, LLC • Ellicott City, MD, United States
Full-time
Senior Security Engineer Subject Matter Expert (SME).This position is on-site when required, otherwise remote.Based in Maryland, you will report directly to the Department of Human Services' (DHS) ...Show more
Last updated: 5 days ago • Promoted
Information Systems Security Engineer (ISSE) (TS / SCI with Poly)

Information Systems Security Engineer (ISSE) (TS / SCI with Poly)

Solerity • Fort Meade, MD, United States
Full-time
Take the next steps to your professional success as Solerity is a recognized leader in providing Information Technology, Engineering Services, Program Management and Consulting Services to the U.S ...Show more
Last updated: 30+ days ago • Promoted
SIGN ON BONUS Senior Information Systems Security Engineer (Sr. ISSE)

SIGN ON BONUS Senior Information Systems Security Engineer (Sr. ISSE)

Helm Point Solutions • Baltimore, MD, United States
Full-time
Senior Information Systems Security Engineer (ISSE).Linthicum, MD • Government / Military.Secure the Nation's Most Critical Systems. Helm Point Solutions is a woman-owned cybersecurity and physical se...Show more
Last updated: 5 days ago • Promoted
System Security Engineer - TS / SCI with Polygraph

System Security Engineer - TS / SCI with Polygraph

General Dynamics Information Technology • Elkridge, MD, United States
Full-time
Clearance Level Must Currently Possess : .Clearance Level Must Be Able to Obtain : .IT Infrastructure and Operations.Complex Systems, Splunk Administration, Systems Development.Transform technology int...Show more
Last updated: 5 days ago • Promoted
Information Systems Security Engineer II

Information Systems Security Engineer II

Kavaliro • Fort Meade, MD, United States
Permanent
Information Systems Security Engineer Ii.Kavaliro is seeking an Information Systems Security Engineer II to support a client in Maryland. Participate as a security engineering representative on engi...Show more
Last updated: 5 days ago • Promoted
Information System Security Engineer III (ISSE III)

Information System Security Engineer III (ISSE III)

JASINT Consulting and Technologies, LLC • Annapolis Junction, MD, United States
Full-time
Information System Security Engineer III (ISSE III).This position requires a current and active TS / SCI with Full Scope Poly at the time of application. Review technical security assessments for comp...Show more
Last updated: 5 days ago • Promoted
Information Systems Security Engineer (Skill Level 2-3)

Information Systems Security Engineer (Skill Level 2-3)

Strategic Analytix • Fort Meade, MD, United States
Full-time
Strategic Analytix (SA) is an IT engineering and management consulting firm focuses on mission critical services and solutions to the Federal Government including the Department of Defense (DOD), t...Show more
Last updated: 5 days ago • Promoted
Sr. Security Research Engineer

Sr. Security Research Engineer

Proofpoint • Baltimore, MD, United States
Full-time
We are the leader in human-centric cybersecurity.Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to stay ahead...Show more
Last updated: 5 days ago • Promoted
Information Systems Security Engineer, Senior

Information Systems Security Engineer, Senior

SITEC Consulting LLC • Hanover, MD, United States
Full-time
SITEC is an employee and customer focused Information Technology and Professional Services Firm specializing in design, development, and delivery of state-of-the-art technology solutions, as well a...Show more
Last updated: 5 days ago • Promoted
2543 Information Systems Security Engineer 3

2543 Information Systems Security Engineer 3

InterImage • Fort Meade, MD, United States
Full-time
The minimum qualifications are to posses both the CISSP and ISSEP certifications, 20 years of experience, and a technical bachelors degree. We are also looking for this candidate to have a Zero Trus...Show more
Last updated: 5 days ago • Promoted
Intrusion Detection Systems (IDS) Engineer

Intrusion Detection Systems (IDS) Engineer

Leidos • Gwynn Oak, MD, United States
Full-time
Intrusion Detection Systems (IDS) Engineer,.This role focuses on operating Network IDS platforms such as Snort 3.Security Operations through proactive threat detection and analysis.If this sounds l...Show more
Last updated: 5 days ago • Promoted
Information Systems Security Engineer

Information Systems Security Engineer

Novul Solutions • Annapolis Junction, MD, United States
Full-time
We are currently seeking a Mid-Level Information System Security Engineer to join in supporting a critical mission in Annapolis Junction, MD. This role is essential in a program that delivers a broa...Show more
Last updated: 5 days ago • Promoted
Sr. Systems Engineer (Johns Hopkins Public Safety)

Sr. Systems Engineer (Johns Hopkins Public Safety)

Johns Hopkins University • Baltimore, MD, United States
Full-time
Johns Hopkins Public Safety will provide technical leadership, project management, and task execution for administration, programming, maintenance, and performance implementation of departmental pl...Show more
Last updated: 30+ days ago • Promoted
Information Systems Security Engineer (ISSE) (TS / SCI with Poly)

Information Systems Security Engineer (ISSE) (TS / SCI with Poly)

Solerity, Inc. • Fort Meade, MD, United States
Full-time
Take the next steps to your professional success as Solerity is a recognized leader in providing Information Technology, Engineering Services, Program Management and Consulting Services to the U.S ...Show more
Last updated: 5 days ago • Promoted
Information Systems Security Engineer (ISSE)

Information Systems Security Engineer (ISSE)

WILLCOR • Glen Burnie, MD, United States
Full-time
Information Systems Security Engineer (ISSE).We are seeking a highly skilled Information Systems Security Engineer (ISSE) to support cybersecurity assessments and Risk Management Framework (RMF) ev...Show more
Last updated: 5 days ago • Promoted
Sr. Cloud Security Engineer

Sr. Cloud Security Engineer

Capital Solutions Group LLC • Baltimore, MD, United States
Full-time
TS / SCI with both Polygraphs is required.Join our "Security in the Cloud" team dedicated to enhancing the security posture of our cloud environments. The team is responsible for developing and mainta...Show more
Last updated: 5 days ago • Promoted