Information Security Engineer III
EntergyAbout the role
Work Place Flexibility: Hybrid
Legal Entity: Entergy Services, LLC
*** These positions may be filled in any city within Entergy's service territory, The Woodlands Tx or New Orleans LA preferred ***
Brief Position Description
The OT Cyber Security team executes and/or oversees the activities required to secure Entergy’s critical systems and assets as well as meet or exceed Entergy’s commitment and obligation to the North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) standards. This position is expected to have operational experience in areas of information technology, operational technology, and cyber security, with experience working in electrical power, professional auditing, and risk-based compliance processes preferred. Engineers are accountable to perform daily assigned activities, escalate issues identified while performing daily activities, and identification and implementation of process improvement opportunities, while ensuring Entergy can demonstrate compliance with the NERC CIP requirements.
Key responsibilities include:
- Ensure OT cyber assets meet or exceed regulatory requirements and industry best practices
- For OT environments, responsible for ensuring security and compliance with relevant regulatory compliance requirements (e.g. North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP), etc. Including but not limited to:
- Configuration Baselines and monitoring
- Electronic Security Perimeters (ESP)
- Asset inventory and classification
- Commissioning new assets including substations, control centers, data centers
- Security monitoring, logging, and alerting
- Malware prevention and vulnerability management
- Transient cyber asset protections
- Security Patch Management
- Daily reconciliation of configuration baseline changes against change authorizations to detect unauthorized deviations.
- Level I triage of detected cybersecurity logging failures. Collaborate with asset owners/stakeholders regarding cyber assets that have failed logging.
- Maintenance of cyber asset inventory information for accuracy.
- Facilitate change management reviews, task completion, and evidence corresponding work.
- Monitor systems for non-compliance with standards and escalate to appropriate members of leadership.
- Support change management initiatives and weekly activities, including security assessments and Change Advisory Board review and approvals
- Participate in disaster recovery planning, preparation and testing.
- Support other departmental initiatives such as vulnerability assessments, penetration testing, internal assessments/tiger teams, or as stakeholders in other teams capital projects
- Be an active member in preparation for required audits
- Participate in audit interviews as directed by leadership
- Identify and Implement improvement opportunities including automation, tool configuration, and process changes.
- Support department projects, such as new hardware deployments, software upgrades, capability enhancements, etc.
- Expand services provided as directed by leadership.
- Other duties as required
Education Needed
- Degree: Bachelor’s degree preferred
- Certification/License: Cybersecurity certification preferred (e.g. CISSP, CISA, CRISC, etc.)
Experiences Needed
- Minimum Years of Experience: 5+
- 2+ years of technical experience in data collection and analysis.
- 2+ years of experience in Cyber Security; preferred domains include Baseline Configuration Monitoring, Backup & Recovery, Change Management Oversight, Reuse & Disposal, NERC CIP, NIST CSF, Security Controls planning and/or auditing, security monitoring and analysis.
- Experience with OT environments preferred.
- Communication Skills: Excellent
Base Competencies:
- Expert knowledge of PC, presentation, word processing and analytical software
- Strong data collection and analysis skills
- Strong ability to work in cross-functional teams
- Strong problem solving skills
- Experience working in an on-call team rotation preferred
- Strong organizational and time management skills
- Strong understanding of regulatory and compliance requirements; NERC CIP and/or SOX preferred
- Expert understanding of cyber security principles
- Strong skills and experience in cyber security technical competencies (e.g. security tools, processes, etc.)
- Continuous Improvement mindset. Can develop or proposes automation and/or process improvement, when directed, to improve efficiencies.
J
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s