Location(s): CO - Denver; MN - Minneapolis; TX - Amarillo
Are you looking for an exciting job where you can put your skills, talents and education to work at a company you can feel proud to be a part of? Do you want a workplace that will challenge you and offer you opportunities to learn and grow? A professional position at Xcel Energy could be just what you’re looking for.
Xcel Energy’s ESS team is responsible for all aspects of security including Cyber, Physical, Enterprise Resiliency, and Governance and Risk services. This dynamic team is growing and evolving to meet the needs of the enterprise while adjusting to the ever changing world we live in. Come join this high-energy team in building a best-in-class Cyber Security program tasked with protecting the critical infrastructure Xcel Energy’s customers depend on.
We are hiring a Senior Cyber Security Engineer - to be based out of Denver, CO, Amarillo, TX, or Minneapolis, MN.
The successful candidate should have experience working with Advanced Grid Intelligence and Security (AGIS), Operational Technology (OT) projects managing cyber security controls in OT environments (e.g. SCADA, AMI, FAN, DCS, Electric or Gas Distribution/transmission, gas and electric plants); performing network and application security administration in these environments, performing penetration testing and/or threat assessments, working with commercial and open source security applications and technologies, and experience as a cyber security specialist in an electric OT environment.
The Cyber Security Engineer will assist in effectively developing, implementing, communicating, and executing the Xcel Energy Enterprise Security Services cyber security strategy within OT environments. Will work closely with key business partners, internal technology teams and external vendors to research, deploy and configure technologies and processes that strengthen the defenses of the enterprise. The Cyber Security Engineer will remain knowledgeable about security issues, vulnerabilities, regulatory and legal changes, and standards that may impact cyber security at Xcel Energy.
- Work with business units in the planning, designing, implementing, and maintaining of the AGIS/OT infrastructure and associated technologies
- Able to engineer secure solutions in accordance with policies, procedures, standards and best practices
- Recommend specifications and detailed schematics for architecture
- Recommend specific detailed information for hardware, software, and firmware selection, as well as implementation techniques and tools for the most efficient solution to meet business needs including present and future capacity and cyber security feature requirements
- Conduct analysis, testing, troubleshooting, and hardening of AGIS/OT infrastructure and associated technologies to guarantee functionality and optimize system performance
- Work with others to ensure that proper cyber security disciplines are understood and applied
- Educate the ESS team to ensure the capabilities of AGIS/OT equipment and security configurations are documented and appropriately monitored for ongoing threats
- Apply security knowledge, policies, procedures and best practices to identify security solutions for potential use across the enterprise
- Bachelor's degree (preferably with a concentration in Computer Science, Technology, Information Security, Information Systems or Engineering) or the equivalent combination of education, training and professional experience
- Minimum of 8 years’ experience in Cyber Security including 5 years direct experience in Cyber Security Engineering
- Demonstrated verbal/written communication and presentation skills
- Demonstrated leadership
- Proven Problem Solving and business risk analysis skills
- Ability to excel in a team environment
- Strong investigative, conflict resolution and negotiation skills
- Must possess a broad knowledge relating to IT infrastructure and have in-depth and up-to-date experience with multiple operating systems and desk side integration.
- Demonstrated knowledge of cyber security through all layers of the Open Systems Interconnect (OSI) stack
- Demonstrated experience in cyber security engineering principles involving application security, security testing, communications / network security, and computer security
- Experience with connected embedded systems in Industrial and Operational Technologies, Sensor Networks and associated embedded operating systems
- Experience with firewall configuration and architecture, security perimeters and gateways, Virtual Private Networking (VPNs), reverse proxies, web application firewalls and wireless networking security
- Experience using device vulnerability scanning suites
- Experience using Security Incident and Event Management (SIEM) tools, as well as capture tools such as Wireshark
- Advanced understanding of Identity and Access Management principles used for authentication including basics of public key cryptography
- Proven successful experience interacting with internal customers and project co-workers as well as senior leadership
- Effective written and oral communication skills
- Proven ability to interpret security and information protection policies into executable requirements
- Solid understanding of information security policies, standards, industry best practices, and frameworks (ISO 27K, NIST 800-53, FISMA, etc.)
- Experience working with regulatory programs such as NERC-CIP, SOX, HIPAA, etc.
- Understanding of OWASP Top 10 Web Application Security Risks and their countermeasures
- Understanding of the SANS Top 25 Most Dangerous Software Errors and their countermeasures
As a leading combination electricity and natural gas energy company, Xcel Energy offers a comprehensive portfolio of energy-related products and services to 3.4 million electricity and 1.9 million natural gas customers across eight Western and Midwestern states. At Xcel Energy, we strive to be the preferred and trusted provider of the energy our customers need. If you’re ready to be a part of something big, we invite you to join our team.
Posting Notes: CO - Denver || CO - Denver; MN - Minneapolis; TX - Amarillo || United States (US) || Customer And Innovation || 56130:Cyber Security || Full-Time || Non-Bargaining ||
Requisition Number: 18319
Equal Opportunity Employer: Minority/Female/Disability/Veteran
Individuals with a disability who need an accommodation to apply please contact us at [email protected]