Senior Cybersecurity Engineer, Operational Technology
Senior
Cybersecurity Tools
Ics Network Segmentation
Industrial Control Systems
Industrial Control Systems Security
Industrial Cybersecurity
Information Security
InfoSec
Operational Technology Security
Ot Security
Risk Management
Scada Security
Security
Security Compliance
Security Compliance Frameworks
Security Standards
Solution Architecture
Job Description
Platte River Power Authority is seeking a Senior Cybersecurity Engineer to serve as the dedicated Operational Technology (OT) cybersecurity subject matter expert. This role focuses on building and improving cybersecurity controls across OT environments, including ICS and SCADA systems, while enabling monitoring, risk management, and incident readiness aligned to enterprise objectives and applicable regulatory requirements.
Responsibilities
- Define and maintain OT cybersecurity standards, reference architectures, and secure design patterns.
- Design and recommend cybersecurity controls for ICS, SCADA, DCS, and OT network environments.
- Establish and guide network segmentation strategies between IT and OT environments using the ISA/IEC 62443 zone-and-conduit model with documented Security Level targets.
- Ensure alignment between enterprise cybersecurity architecture and OT operational requirements.
- Provide security guidance for emerging platforms including DERMS and IIoT.
- Provide cybersecurity design input for new and changing generation assets (including BESS, solar, and wind, as applicable) in coordination with resource planning.
- Perform risk assessments, threat modeling, and security reviews of OT systems and architecture.
- Identify and communicate OT cybersecurity risks to technical and business stakeholders.
- Define security baselines and minimum control requirements for OT environments.
- Support development and continuous improvement of OT cybersecurity policies, standards, and procedures, accounting for safety, reliability, and operational constraints.
- Partner with OT teams to monitor OT environments using specialized detection tools, coordinating with the OT MSSP and enterprise IT security for monitoring coverage and escalation instead of relying on a one-person 24/7 on-call model.
- Establish and tune OT detection use cases and baselines in partnership with the OT MSSP.
- Support investigation and response to OT-related security incidents and support OT incident reporting (CIP-008) in coordination with the CIP Compliance Analyst.
- Contribute to development and testing of OT incident response playbooks and tabletop exercises.
- Triage and act on OT threat-hunting findings and monitoring from the OT MSSP to drive continuous monitoring improvements.
- Identify and assess vulnerabilities in OT systems, firmware, and applications; define risk-based remediation and mitigation strategies with OT stakeholders.
- Guide patching approaches that balance cybersecurity risk with operational uptime.
- Conduct risk assessments for legacy and unsupported systems and define compensating controls.
- Develop and maintain visibility into OT assets, communications, and data flows.
- Establish a roadmap for machine identity, certificate lifecycle, and trust relationships in OT environments.
- Guide implementation of secure authentication mechanisms for users, devices, and remote access.
- Build and maintain OT asset inventory and visibility aligned to current CISA OT asset inventory guidance, supporting BES Cyber System identification (CIP-002).
- Define OT network security requirements including segmentation, zoning, and access controls.
- Review and validate firewall rulesets and architecture for alignment with enterprise standards.
- Analyze OT network traffic patterns and support anomaly detection efforts, including selection, deployment, and tuning of OT-aware monitoring tools (e.g., passive network monitoring and internal network security monitoring).
- Support internal and external audits, assessments, and evidence collection; translate regulatory requirements into practical, risk-based security controls.
- Maintain documentation related to OT cybersecurity controls, risks, and exceptions; evaluate OT security technologies and recommend solutions aligned with enterprise strategy.
- Provide cybersecurity guidance during deployment of OT systems and integrations.
- Define and govern secure remote access requirements for vendors and third parties.
- Assess vendor risk associated with OT systems, software, and managed services, contributing OT-side technical input to vendor security review and the CIP-013 supply-chain process (including vendor security questionnaires, PSIRT/E-ISAC advisory monitoring, and SBOM intake).
- Provide cybersecurity guidance and education to OT engineering and operations teams; promote awareness of secure practices for plant operators and technical staff.
- Act as a liaison between enterprise cybersecurity and OT teams to improve collaboration and shared understanding.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Engineering, Electrical Engineering, or related field (or equivalent experience).
- Current valid driver’s license and ability to remain insurable under the vehicle liability policy.
- GICSP or GCIP (GIAC Critical Infrastructure Protection) certification, or ability to earn within 12 months of hire.
- 7–10 years of experience in cybersecurity with exposure to OT/ICS environments.
- Knowledge of industrial protocols including Modbus, DNP3, OPC, and IEC 61850.
- Experience with OT security tools such as Nozomi, Claroty, Dragos, Tenable.ot, or Splunk.
- Experience with network segmentation, firewalls, and security architecture principles.
- Practical understanding of how NERC CIP shapes OT controls and the ability to work with compliance staff on the technical aspects.
- Familiarity with threat detection, incident response, and security monitoring practices.
Preferred Education, Licenses, and Work Experience
- Experience with certificate lifecycle and machine identity management in OT environments.
- Experience with OT security platforms (Nozomi, Claroty, Dragos, Tenable.ot, Splunk).
- Familiarity with Palo Alto, Cisco, or similar network/security platforms.
- Knowledge of cloud-to-plant integrations (IIoT).
- Experience securing remote access solutions (VPN, ZTNA).
- Experience with energy or utilities, including critical infrastructure sectors.
- Preferred certifications: CISSP or CISM; GRID (GIAC Response and Industrial Defense); ISA/IEC 62443 certification (Cybersecurity Fundamentals Specialist or higher).
Technologies
- ISA/IEC 62443 (including zone-and-conduit model)
- NIST Cybersecurity Framework (CSF)
- NIST SP 800-82 (ICS Security)
- NERC CIP (CIP-002, -005, -007, -010, -011, CIP-008, CIP-013) and related CIP-002, CIP-008, CIP-013 references
- CISA OT asset inventory guidance and BES Cyber System identification (CIP-002)
- Industrial protocols: Modbus, DNP3, OPC, IEC 61850
- OT security tools: Nozomi, Claroty, Dragos, Tenable.ot, Splunk
- DERMS, IIoT
- OT platforms and assets: BESS, DCS, ICS, SCADA
Recruitment Notice
- Platte River Power Authority does not accept unsolicited resumes from headhunters, recruitment agencies, or fee-based placement services.
- No agency emails, calls, or solicitations to staff are accepted without a valid agreement.
- Any unsolicited resume submitted to staff will be considered property of Platte River Power Authority with no obligation to pay referral fees.
Location and Work Model
Fort Collins, CO (onsite)
Salary
USD 153,404 to 188,041 per yearly (hiring range). Full range: $153,404 to $222,458. Salaries are paid bi-weekly and actual salary may be determined by special skills, years of experience, education, and certifications.
Work Environment, Physical Demands, and Hazards
- Physical demands: Minimal physical effort typically found in clerical work; primarily sedentary with occasional lifting and carrying of light objects; minimal walking or standing as needed.
- Hazards: Minimal exposure to hazards typically found in a general office environment where there is rarely to no exposure to injury or accident.
- Work environment: Exposure to routine office noise and equipment.