Exelon

Sr OT Systems Security Engineer

LocationPhiladelphia, PA
Job TypeFull-time

About This Job


Who We Are


We're powering a cleaner, brighter future.

Exelon is leading the energy transformation, and we're calling all problem solvers, innovators, community builders and change makers. Work with us to deliver solutions that make our diverse cities and communities stronger, healthier and more resilient.

We're powered by purpose-driven people like you who believe in being inclusive and creative, and value safety, innovation, integrity and community service. We are a Fortune 200 company, 19,000 colleagues strong serving more than 10 million customers at six energy companies Atlantic City Electric (ACE), Baltimore Gas and Electric (BGE), Commonwealth Edison (ComEd), Delmarva Power & Light (DPL), PECO Energy Company (PECO), and Potomac Electric Power Company (Pepco).

In our relentless pursuit of excellence, we elevate diverse voices, fresh perspectives and bold thinking. And since we know transforming the future of energy is hard work, we provide competitive compensation, incentives, excellent benefits and the opportunity to build a rewarding career.


Are you in?


Primary Purpose


PRIMARY PURPOSE OF POSITION

The Sr OT Systems Security Engineer (OTSSE) will support implementation of the Operational Technology (OT) Security Governance program and provide proactive cyber security risk management. The OTSSE will act as a liaison to OT teams, Security Architects and other CISS teams to effectively communicate and lead OT security engineering design specification, architecting and implementing effective OT security solutions. The OTSSE will also assist with vulnerability mitigation plans, incident response, and security event monitoring engineering support. The OTSSE will ensure the implementation of OT security measures in accordance with established procedures to ensure safety, reliability, confidentiality, integrity, availability, authentication, and non-repudiation, and will perform OT security reviews to identify gaps in security design and architecture.

Note: This is a hybrid position (in-office with remote flexibility). Employees are required to be in office at least three days per week (Tuesday, Wednesday, and Thursday). This position must sit out of our Baltimore, MD, Newark, DE, Owings Mills, MD or Kennett Square, PA office. This position is NOT eligible for relocation assistance.


Primary Duties


PRIMARY DUTIES AND ACCOUNTABILITIES

Provide analytical and technical security recommendations to other team members, technical teams, and business clients, including: Provide OT cyber security guidance to leadership. Work with stakeholders to design OT security design specifications and architectures. Provide input to implementation plans and standard operating procedures as they relate to OT cyber security.
Develop specific OT cyber security countermeasures and risk mitigation strategies for systems and/or applications.
Work closely with technical teams to implement effective security configurations/requirements, including:
Analyze and design security measures to resolve OT vulnerabilities, mitigate risks, and recommend security changes to system or system components as needed.
Mitigate/correct security deficiencies identified during Factory Acceptance Testing, Site Acceptance Testing, and/or recommend risk acceptance for the appropriate senior leadership. Verify and update security engineering documentation reflecting the application/system security design features. Verify minimum security design specifications are in place for OT assets to support security event monitoring and incident response.
Work closely with the R&D and innovation teams to ensure secure implementation of OT systems into production. (
Assist with vulnerability mitigation planning, incident response and security event monitoring engineering activities for security and compliance requirements
Conduct engagement and provide OT cyber security training to OT personnel


Job Scope


JOB SCOPE

The Senior Operational Technology Systems Security Engineer (OTSSE) will work closely (and primarily) with business OT teams, IT/Utility communications, Engineering and OT clients to implement effective security configurations and requirements; provide analytical and technical security recommendations to other team members, technical teams, and business clients; support OT Security Governance efforts; meet with Exelon business clients and management to help specify and negotiate system/network/application security requirements; work with the R&D and innovation teams to ensure secure implementation of OT systems into production; develop OT security solutions to improve security event monitoring and detection with CISS standards; actively participate in relevant industry OT cyber security workgroups and forums; act as a liaison to business OT teams, Security Architect and IT/UComm, and OT stakeholders to effectively communicate and lead OT security engineering design specification, architecting and implementing effective OT security solutions; develop documentation to support ongoing OT security systems operations, maintenance, and problem resolution; advise on vulnerability mitigation plans, and develop security event monitoring solutions to improve incident detection; work with the Security Policy and Risk Office to assist with the identification, analysis, and remediation of Exelon OT cyber security risk


Minimum Qualifications


MINIMUM QUALIFICATIONS

Bachelors Degree in Computer Science, engineering, or a related discipline, and typically 5 or more years of solid, diverse experience in OT/ICS, or equivalent combination of education and work experience.
At least 3 years of demonstrated experience in the energy sector
At least 5 years of demonstrable security engineering or related experience, including:
Knowledge of disaster recovery continuity of operations plans
Knowledge of Risk Management Framework (RMF) requirements
Knowledge of incident response and handling methodologies.
Knowledge of network security architecture concepts including topology, protocols, components, and principles
Knowledge of authentication, authorization, and access control methods.
Knowledge of cryptography and cryptographic key management concepts
Knowledge of database systems
Knowledge of embedded systems
Knowledge of system fault tolerance methodologies
Knowledge of how system components are installed, integrated, and optimized
Knowledge of ICS supply chain security and risk management policies, requirements, and procedure
Knowledge of human-computer interaction principle
Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
Ability to design architectures and frameworks
Skill in applying cybersecurity methods, such as firewalls, demilitarized zones, and encryption
Knowledge of network access, identity, and access
Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services
Knowledge of network design processes, to include understanding of security objectives, operational objectives, and tradeoffs
Knowledge of parallel and distributed computing concepts
Knowledge of key concepts in security management (e.g., Release Management, Patch Management)
Knowledge of configuration management techniques
Comprehensive understanding of change management techniques associated with new technology implementation.
Demonstrated experience producing an economic business case.
Demonstrated leadership ability.
Proven analytical, problem solving, and consulting skills.
Excellent communication skills and the proven ability to work effectively with all levels of OT and business management.


Preferred Qualifications


PREFERRED QUALIFICATIONS

Graduate degree in cyber security, engineering, or related area of expertise.
Relevant security certifications (CISSP, CISM, GICSP)
At least 3 years of experience as part of an electric utility
Appropriate technical skills and in-depth knowledge of business unit functions and applications, including:
Demonstrated experience and subject matter knowledge of SCADA, ICS, Distribution Automation, Smart Grid, DMS, and ECS systems architecture.
Demonstrated experience and subject matter knowledge of security vulnerabilities and mitigation strategies for industrial SCADA protocols such as DNP3, IEC-61850, Modbus, Tejas V, CDC 2, Vancomm, etc.
Demonstrated experience in security risk assessments, requirements development, secure design analysis, architecture assessment and development, and security testing of applications and systems.
Extensive experience developing, evaluating, and implementing OT security architectures, technologies, standards, and practices to secure applications and OT.
Demonstrated knowledge and experience in the implementation of governance frameworks and security risk management processes, such as NIST, ISO, ISA99, IEC 62443 guidelines and standards.
Demonstrated experience in addressing regulatory compliance for the security requirements in applicable laws and regulations, such as NERC CIP, CFATS, or API 1164.
Demonstrated experience and subject matter knowledge in cyber security for applications, web architectures, operating systems, databases, and networks.
Knowledge and experience in application security standards, methodologies, and technologies.
Solid capability to assess network architectures and operating systems for vulnerabilities and develop appropriate security countermeasures.
Solid knowledge and experience with OT security aspects of operating systems, embedded operating systems, Programmable Logic Controllers (PLC), Remote Terminal Units (RTU), and Protection and Control relays.
Experience in assessing security applications and systems, such as firewalls, security appliances, IDS/IPS, SSL or TLS, IPSec.
Ability to demonstrate analytical skills, technical knowledge, and practical application of cyber and information security principles to business leaders and technical staff.


Benefits


Benefits

Annual salary will vary based on a candidate’s skills, qualifications, experience, and other factors: $102,400.00/Yr. – $140,800.00/Yr.
Annual Bonus for eligible positions: 15%
401(k) match and annual company contribution
Medical, dental and vision insurance
Life and disability insurance
Generous paid time off options, including vacation, sick time, floating and fixed holidays, maternity leave and bonding/primary caregiver leave or parental leave
Employee Assistance Program and resources for mental and emotional support
Wellbeing programs such as tuition reimbursement, adoption and surrogacy assistance and fitness reimbursement
Referral bonus program
And much more

Note: Exelon-sponsored compensation and benefit programs may vary or not apply based on length of service, job grade, job classification or represented status. Eligibility will be determined by the written plan or program documents.

Similar Jobs

company-logo

Sr OT Systems Security Engineer

Exelon
Job TypeFull-time
 
Philadelphia, PA
19 days ago
company-logo

Sr OT Systems Security Engineer

Exelon
Job TypeFull-time
 
Owings Mills, MD
19 days ago
company-logo

Sr Cyber Security Engineer

Fluor Federal Petroleum Operations
Job TypeFull-time
 
New Orleans, LA
25 days ago
company-logo

Sr Systems Engineer

Oceaneering
Job TypeFull-time
 
Houston, TX
26 days ago
company-logo

Sr Operations Systems Engineer

Fluor Federal Petroleum Operations
Job Typefull_time
Salary
$130000 - $150000
New Orleans, LA
3 days ago
company-logo

Sr Engineer, Cybersecurity

Spire Energy
 
St. Louis, MO
27 days ago
company-logo

Sr Staff Cyber Security Engineer

GE Vernova
Job TypeFull-time
Salary
$118400 - $197400
Atlanta, GA
about 1 month ago
company-logo

Sr Staff Cyber Security Engineer

GE Vernova
Job TypeFull-time
Salary
$118400 - $197400
Remote
about 1 month ago
company-logo

Sr Staff Cyber Security Engineer

GE Vernova
Job TypeFull-time
Salary
$118400 - $197400
Greenville, SC
about 1 month ago
company-logo

Sr Principal Product Security Engineer

Itron, Inc.
Job Typefull_time
 
Liberty Lake, WA
2 days ago
LP

OT Cyber Security Engineer

LS Power Development, LLC
Job TypeFull-time
 
Austin, TX
11 days ago
company-logo

Sr Operations Engineer

Cenovus Energy
Job TypeFull-time
 
Calgary, AB
11 days ago
company-logo

OT SYSTEM ENGINEER

Delaware Electric Cooperative, Inc.
Job TypeFull-time
 
Greenwood, DE
15 days ago
company-logo

OT Systems Engineer

AltaLink
Job Typefull_time
 
AB
15 days ago
company-logo

Sr. Systems Engineer 2

Exelon
Job Typefull_time
 
19 days ago
company-logo

Sr. IT Security Analyst

Kinross Gold Corporation
 
Ontario, ON
12 days ago
company-logo

Control Systems Engineer Sr.

American Electric Power
Job Typefull_time
 
Columbus, OH
4 days ago
company-logo

Sr Firmware Engineer

Itron
Job TypeFull-time
 
Raleigh, NC
17 days ago
company-logo

Sr Firmware Engineer

Itron, Inc.
Job TypeFull-time
 
North Carolina, United States
17 days ago
company-logo

Sr Platform Engineer

Consumers Energy
Job Typefull_time
 
Jackson, MI
1 day ago

Trending Jobs

company-logo

Assistant General Manager, Navy Yard Electric Utility

Job TypeFull-time
Salary
$108000 - $108000
Philadelphia, Pennsylvania
17 days ago
company-logo

Electrical Engineer

Dudley Staffing
Job TypeFull-time
Salary
$55 - $75
Canonsburg, Pennsylvania
3 months ago
company-logo

Accounts Payable Clerk

Job TypeFull-time
Salary
$65000 - $65000
Dallas, Texas
19 days ago
DM

Apprentice Lineman

Delta Montrose Electric Association
Job TypeFull-time
 
Montrose, CO
22 days ago
company-logo

Division Order Analyst

Job TypeFull-time
 
Dallas, Texas
9 days ago
company-logo

contract landman

HPS Oil & Gas Properties
Job TypeFull-time
 
Lafayette, Louisiana
3 months ago
company-logo

Attorney

Toeppich & Associates
Job TypeFull-time
 
Houston, Texas
about 1 year ago
company-logo

Oil and Gas Land and Title Analyst - SAM Associate II

Bank of America
Job TypeFull-time
 
Dallas, Texas
about 1 month ago
company-logo

Apprentice Lineman I

San Patricio Electric Cooperative, Inc.
Job TypeFull-time
 
Sinton, TX
about 1 month ago
HM

Lineworker Apprentice I

Henderson Municipal Power & Light
Job TypeFull-time
 
Henderson, KY
26 days ago
company-logo

Associate Attorney

Buffalo Biodiesel Inc.
Job TypeFull-time
 
Buffalo, NY
29 days ago
company-logo

Senior Landman

Greenlake Energy
Job TypeFull-time
 
Austin, Texas
about 1 month ago
company-logo

Foundry Professionals

Penticton Foundry
Job TypeFull-time
 
British Columbia, Canada
10 days ago
company-logo

Apprentice Lineman

Southern Pine Electric
Job TypeFull-time
 
Brandon, MS
23 days ago
company-logo

Contracts Administrator

Third Coast
Job TypeFull-time
Salary
$70000 - $85000
Houston, Texas
23 days ago
company-logo

Electrical Designer

Dudley Staffing
Job TypeFull-time
Salary
$45 - $60
Canonsburg, Pennsylvania
3 months ago
company-logo

Deckhand

Ballard Marine Construction
Job TypeFull-time
 
Bradenton, FL
12 days ago
company-logo

Residential Helper

Waste Pro
 
Columbus, MS
26 days ago
company-logo

Floorhand 2

Key Energy Services
Job TypeFull-time
 
Midland, TX
26 days ago
company-logo

Operator Assistant Trainee - Frac Acid

Halliburton
Job TypeFull-time
 
Zanesville, OH
26 days ago