Sr Cyber Security Engineer
About Us
As the largest private-sector power producer in the world and the nation's largest producer of clean and reliable energy, Constellation is focused on our purpose: lighting the way to a brilliant tomorrow for all. We have been the leader in clean energy production for more than a decade, and we are cultivating a workplace where our employees can grow, thrive, and contribute. Our portfolio includes 55 gigawatts of capacity from nuclear, natural gas, geothermal, hydro, wind, and solar facilities, with the generating capacity to power the equivalent of 27 million homes. Our culture and employee experience make it clear: We are powered by passion and purpose. Together, we're creating healthier communities and a cleaner planet.
About the Role
The Sr. Cyber Security Engineer (CSE) will execute the highly technical, tactical elements of the cyber security strategy, eliminating a functional cyber security capability gap while providing pro-active cyber security risk management. The CSE will act as a liaison to the Security Architect and Cloud and Infrastructure Operations/Engineering and Utility IT teams to effectively communicate and assist in architecting and implementing effective security solutions to achieve North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) compliance. The role ensures the implementation of system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation, and performs security reviews to identify gaps in security architecture. The CSE will assist in the development of appropriate security risk management plans and work closely with IT, Physical Security, and Power IT to implement effective NERC CIP standards and requirements.
Responsibilities
- Provide analytical and technical security recommendations to other team members, technical teams, and business clients, including:
- Technical guidance regarding NERC CIP Standard and Requirement changes and implementations.
- Collaboration with stakeholders to resolve issues around NERC CIP compliance.
- Input to implementation plans and standard operating procedures related to information systems security.
- Development of specific risk mitigation strategies for systems and/or applications related to NERC CIP.
- Work closely with technical teams to implement effective security configurations/requirements, including:
- Verification of security measures to resolve vulnerabilities, mitigate risks, and recommend security changes to meet NERC CIP requirements.
- Updating documentation reflecting the application/system security design features related to NERC CIP.
- Ensuring security requirements are in place for all applications related to NERC CIP.
- Collaborate with all teams to ensure secure transition of new requirements into production.
- Demonstrate excellent communication skills and the proven ability to work effectively with all levels of IT and business management.
- Perform other job assignments and duties as directed by management, including emergency response, department duty coverage, and support of outage activities.
Requirements
- Bachelor's degree in Computer Science, Information Technology (IT), or a related discipline with 7 years of experience in cyber security.
- Associate's degree in Computer Science or Engineering-related discipline with 9 years of experience in IT or engineering.
- High school diploma/GED with 11 years of experience in IT or engineering.
- Nuclear or related industry experience.
- Experience in change management techniques with new technology implementation.
- Maintain minimum access requirement or unescorted access requirements, as applicable, and favorable medical examination and/or testing in accordance with position duties.
Preferred Qualifications
- Graduate degree in cyber security or related area of expertise.
- Relevant security certifications (CISA, CISSP, GIAC, MCSE, RHCE, CCNP, CCSP).
- Extensive technical NERC CIP experience and application across multiple requirements.
- Strong understanding of enterprise, network, system, and application-level security engineering principles.
- Hands-on expertise in the following technical disciplines:
- Operating Systems (Microsoft, Linux, UNIX).
- Networking (Cisco, RuggedCom, and Palo Alto).
- Cryptography (PKI, lifecycle management, symmetric).
- Network Security Engineering (secure network design, IDS/IPS, monitoring, firewalls).
- Virtualization (VMware, Hyper-V).
- Remote Access Methods (VPN, Citrix, MFA).
- ICS / SCADA System Security (design, controls).
- Compliance Tools (Tripwire, Splunk, AssurX/CATSWeb).
Benefits
Constellation offers an extensive selection of benefits and rewards to help employees thrive professionally and personally, including:
- Competitive compensation and a bonus program.
- 401(k) with company match and employee stock purchase program.
- Comprehensive medical, dental, and vision benefits, including robust wellbeing programs.
- Disability and life insurance benefits.
- Paid time off for vacation, holidays, and sick days.
Pay
Expected salary range of $118,800 to $132,000, varies based on experience, along with a comprehensive benefits package that includes bonus and 401(k).