Responsibilities
- Architect and deploy network segmentation strategies to isolate SCADA, control, and enterprise networks across operational sites.
- Manage secure remote access solutions for internal staff and third parties, including jump servers, multi-factor authentication, session logging, and time-limited access grants.
- Implement and optimize endpoint detection and response tools on OT systems while respecting availability and performance requirements.
- Enforce secure configuration baselines and change management for industrial control servers, HMIs, RTUs, and network infrastructure.
- Conduct regular vulnerability scans and coordinate patching or compensating controls with operational teams.
- Ensure compliance with CIP-003 R2 Attachment 1 requirements, including cybersecurity training, access restrictions, incident response, and media handling for low-impact BES systems.
- Keep accurate records of BES Cyber System components and maintain documentation to support CIP-002 categorization.
- Maintain supply chain risk management documentation per CIP-013 for vendors with electronic access to systems.
- Support incident reporting under CIP-008 and safeguard information per CIP-011 requirements.
- Participate in audits and compliance validations, preparing documented evidence and technical artifacts.
- Define and enforce security standards for OEMs, service providers, and internet-facing systems; evaluate and approve remote access requests based on policy.
- Collaborate with Procurement and Legal to embed security controls in contracts and educate vendor staff on security protocols.
- Integrate industrial telemetry and security logs into centralized monitoring platforms and refine detection rules for ICS protocols like Modbus, DNP3, and SEL.
- Lead investigation and response efforts during OT security incidents, coordinating with operations, compliance, and external security teams.
- Develop and conduct incident simulation exercises; update response playbooks and document lessons from real events.
- Perform on-site assessments at solar and battery energy storage facilities to verify asset inventories and control effectiveness.
- Deliver targeted security awareness training to plant personnel and external partners.
- Support the organization’s overall cybersecurity framework in alignment with CIS Controls v8, NIST CSF v2, IEC 62443, and ISO 27001 initiatives.
Benefits
- 401(k) plan with employer match
- Comprehensive health, vision, and dental insurance
- Generous paid time off and company-observed holidays
- Flexible work-from-home policy
- Salary based on experience level
Compensation
Salary commensurate with experience
Work Arrangement
Hybrid — Bay Area
Other
- Candidates may be located anywhere in the U.S.
- Frequent travel to operational solar and battery storage sites is required.
- Occasional visits to the Bay Area office are expected.
- Ability to perform field work in industrial environments.
- Experience coordinating during planned system outages.
- Willingness to participate in on-call rotations for incident response.
- Valid driver’s license is mandatory.
- Applications from search firms will not be accepted.
- The company supports equal employment opportunity for all candidates.
No mention of visa sponsorship