Info Security Engineer I
Duquesne Light Company, headquartered in downtown Pittsburgh, is a leader in providing electric energy and has been at the forefront of the electric energy market, with a history rooted in technological innovation and superior customer service. The company provides a secure supply of reliable power to more than half a million customers in southwestern Pennsylvania.
About the Role
The Information Security Engineer I supports and enhances the Company’s cybersecurity program, with a strong emphasis on North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) compliance, security information and event management (SIEM), configuration monitoring, and incident response. This role safeguards critical infrastructure systems, supports regulatory compliance activities, monitors enterprise and operational technology security controls, and provides technical guidance to junior cybersecurity personnel.
Responsibilities
- Conduct risk assessments and gap analyses related to NERC CIP requirements and cybersecurity leading practices.
- Administer, monitor, and optimize SIEM platforms to support threat detection, alerting, log correlation, and incident investigation.
- Develop and tune SIEM use cases, correlation rules, dashboards, and reporting capabilities.
- Provide technical guidance, knowledge sharing, and operational support to junior security analysts and engineers.
- Collaborate with infrastructure, network, application, and operations teams to improve system hardening and secure configuration practices.
- Support and maintain compliance with applicable NERC CIP standards across enterprise and operational technology environments.
- Participate in NERC CIP audits, assessments, evidence collection, remediation tracking, and compliance reporting activities.
- Collaborate with internal stakeholders to implement and maintain cybersecurity controls aligned with regulatory and organizational requirements.
- Assist in the development, review, and maintenance of cybersecurity policies, standards, procedures, and technical documentation.
- Analyze security events and alerts to identify indicators of compromise, suspicious activity, or policy violations.
- Integrate log sources from enterprise and OT systems into centralized monitoring platforms.
- Manage and support configuration monitoring and file integrity monitoring solutions.
- Develop and maintain baselines for critical cyber assets and monitor for unauthorized changes.
- Investigate configuration drift, integrity violations, and security exceptions.
- Participate in cybersecurity incident response activities, including detection, triage, containment, eradication, recovery, and post-incident analysis.
- Support incident investigations involving enterprise and OT/ICS environments.
- Maintain incident response documentation, playbooks, and lessons-learned reports.
- Assist in coordinating tabletop exercises and cybersecurity readiness activities.
- Participate in cross-functional cybersecurity projects and strategic initiatives.
- Participate in an on-call rotation for cybersecurity incidents and operational support.
- Perform other job-related duties as assigned, including storm team duties.
Requirements
- Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field, or equivalent professional experience.
- Seven (7) or more years of experience in cybersecurity engineering, security operations, or compliance-focused security roles.
- Hands-on experience with SIEM technologies, such as Splunk.
- Experience with configuration monitoring and file integrity monitoring tools, including Tripwire Enterprise or equivalent solutions.
Preferred Qualifications
- Experience in electric utility, energy, industrial control system, or operational technology environments.
- Experience supporting or implementing NERC CIP compliance programs.
- Experience supporting regulatory audits and compliance evidence management.
- Experience managing or supporting infrastructure or network systems, such as server or network administration.
- Industry certification such as CISSP, GCIH, GCIA, Security+, CEH, or a Splunk certification.
Skills
- Knowledge of cybersecurity incident response processes and methodologies.
- Understanding of network security, system hardening, vulnerability management, and access control principles.
- Familiarity with cybersecurity frameworks such as the NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, or IEC 62443.
- Experience with endpoint detection and response, vulnerability management, and threat intelligence platforms preferred.
- Strong analytical, troubleshooting, and problem-solving skills.
- Ability to interpret technical and regulatory requirements and translate them into practical cybersecurity controls and documentation.
- Ability to communicate clearly and effectively, verbally and in writing, with technical and nontechnical stakeholders.
- Ability to collaborate across cybersecurity, infrastructure, network, application, operations, and compliance teams.
- Ability to mentor and support junior cybersecurity personnel through technical guidance and knowledge sharing.
Location: Pittsburgh, PA (Hybrid - Nova Place)