Professional Resource Group, LLC · 17 hours ago
Information System Security Engineer 2
Professional Resource Group, LLC is a staffing company that specializes in augmenting workforce with technical and administrative professionals. They are seeking an Information System Security Engineer 2 to assist in implementing and maintaining cybersecurity strategies for critical corporate systems, ensuring compliance with security standards and regulations.
Staffing & Recruiting
Responsibilities
Provide technical expertise on control center and field infrastructure security architecture and management for control center and field infrastructure systems and related matters
Applies a broad knowledge of power system operations and associated control center and field systems including knowledge of security and regulatory (i.e. FISMA and NERC CIP) as it pertains to compliance computer networks, user interfaces, system software, data acquisition, telecommunications, substation field equipment, and related computer hardware areas
Provide Information System Security Officer support and technical expert for the corporate control center and field General Support Systems and programs by providing expert technical advice, guidance, and recommendations to management and other technical and security specialists on critical operational issues relating to control center control and field infrastructure and data systems including the upgrade and enhancement of all systems in the two critical corporate control centers and field locations
Recommend security strategies in the development of system, software and hardware architectures, technical plans and specifications, system designs, software designs, integration plans, test plans, and project plans
Advises other experts and security practitioners throughout the control centers and field on a variety of situations and issues that involve applying or adapting new security technology theories, concepts, applications, standards, and/or practices
As the control center and field infrastructure security architect and expert, serve as the project security/compliance lead, on assigned projects, for an interdisciplinary project team of electrical engineering and operational technology staff assigned to execute on the most complex control center and field system projects
Verifies that the project plans conform to applicable organizational, agency and external security and compliance standards, policies and guidelines
Provide technical expertise and assistance with the recommendation, development and implementation of corporate management-approved operational cyber security and compliance strategies, processes, guidelines, and projects to safeguard critical cyber assets
Provide technical input, recommendations and assistance with the implementation of both higher and granular-level cyber security approaches, methods and solutions that incorporate and maintain compliance to requirements resulting from laws, regulations, or Presidential directives
Assist in developing / drafting, recommend and execute management-approved testing plans, report results and recommendations
Provide security engineering expertise and recommendations
In collaboration with the manager and per established procedures, develop a cyber-security architecture for the corporate control centers to include accurate, comprehensive applicable documentation
Perform detailed and comprehensive security event analysis
Provide guidance and input into technical reviews of proposed projects, and the corporation's system security authorization processes
Provide technical input and support to the Continuous Assessment and Monitoring Program
Assist in drafts and recommend detailed project plans, timelines, milestones and objectives for upgrades, patches and other changes and/or for monitoring security measures for the protection of the division's computer networks and information
Perform risk assessments and execute tests of data processing systems to validate functioning of data processing activities and security measures
Validate appropriate security controls are in place that will safeguard digital files and vital electronic infrastructure
Coordinate, facilitate and assist with general support systems and major applications' security and compliance projects and program changes and initiatives that: Are designed to anticipate, assess, and minimize system vulnerabilities and weaknesses. Integrate across disciplines, platforms and internal organizations; (people, processes, systems). Under the direction and leadership of Management
Recommend the scope and level of detail for system security plans and collaborate and assist with draft policies, processes and procedures that are applicable to and promote Transmission Systems Operations security program
Assist in development / drafting long-range plans and strategies for OT security systems that anticipate, identify, evaluate, mitigate, and minimize risks associated with OT systems vulnerabilities
Keep abreast of current and new security technologies and threats
Identify the need or potential opportunity for changes based on new security technologies and threats, present recommendations and supportive data for consideration
Research and review proposed new systems, networks, and software designs for potential security risks and impacts; recommend mitigation, countermeasures or other options
Identify integration issues related to the implementation of new systems within the existing infrastructure; recommend mitigation and/or resolution options
Provide subject matter expertise, technical guidance and assistance to other Security Control Assessors, and Cyber Security personnel co-workers on a variety of ad hoc and standing projects requiring data / system process analysis
Provide technical expertise, guidance and assistance to organizational co-workers with less experience, including cross-training as requested
Qualification
Required
Bachelor of science in computer science, information technology or a directly related technical discipline is highly preferred
5 years of experience is required with an applicable bachelor's degree
7 years of experience is required with an applicable associate's degree
9 years of experience is required without a degree or an applicable
Experience must include the following: Hands-on technical implementation of networks and systems
Experience evaluating various technical, operational, and management solutions to security problems, using written language and various media to present alternatives and recommendations
Proven ability to develop documentation sufficient to arrive at logical and comprehensive conclusions and recommendations. The documentation must be of a sufficient professional level to stand as an artifact for reuse as part of the security architecture
3+ years previous experience effectively performing security control implementation on networks, servers and systems and/or vulnerability assessments
One or more of the following networking or security certifications: Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM)
2+ years of experience performing security control evaluation and testing
3+ years of experience with North American Electric Reliability Corporation, Critical Infrastructure Protection (NERC CIP) regulatory standards and requirements
5+ years of experience with the Risk Management Framework and the 800 series of National Institute of Standards & Technology (NIST) Special Publications (in particular 800-37, 800-39, 800-53, 800-53A, 800-82 and 800-115)
Preferred
Expert knowledge of FISMA controls
Expert knowledge of NERC-CIP standards
Understanding and experience in Federal electrical utility operations and how it interplays with FISMA/NERC-CIP standards and compliance
Company
Professional Resource Group, LLC
The value-add of any professional, beyond their technical contribution, is their ability to share their experience, to interact, to effectively communicate, to proactively participate, in order to achieve a desired collective goal.
Funding
Current Stage
Growth StageCompany data provided by crunchbase