Jobs and Careers
EN

Information Security Engineer Sr (Tripwire)

Entergy
The Woodlands, United Statesfull_timeVerifiedPosted 7 Aug 2024

About the role

Work Place Flexibility: Hybrid 

Legal Entity: Entergy Services, LLC 

*** This position will be filled in The Woodlands, TX or New Orleans, LA; however, this position may also be filled in Little Rock, AR.***

 

Brief Position Description

The OT Cyber Security team executes and/or oversees the activities required to secure Entergy’s critical systems and assets as well as meet or exceed Entergy’s commitment and obligation to the North American Electric Reliability Corporation Critical

Infrastructure Protection (NERC CIP) standards. This position’s primary responsibility will be the maintenance and operations of Entergy’s OT Tripwire platform for configuration baseline monitoring. This position is expected to have operational experience in areas of information technology, operational technology, and cyber security, with experience working in an electrical utility environment, professional auditing, and risk-based compliance processes preferred. Engineers are accountable to perform daily assigned activities, escalate issues identified while performing daily activities, and identification and implementation of process improvement opportunities, while ensuring Entergy can demonstrate compliance with the NERC CIP requirements.

 

Key responsibilities include:

  • Maintenance and operations of Entergy’s OT Tripwire and IP360 platform for configuration baseline monitoring, including but not limited to:
    • Security policy creation
    • Asset tagging and maintenance
    • Configuring scanning settings
    • Backend database maintenance
    • Agent maintenance and triage
    • Platform and agent updates
  • Ensure OT cyber assets meet or exceed regulatory requirements and industry best practices
  • For OT environments, responsible for ensuring security and compliance with relevant regulatory compliance requirements (e.g. North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP), etc. Including but not limited to:
    • Configuration Baselines and monitoring
    • Electronic Security Perimeters (ESP)
    • Asset inventory and classification
    • Commissioning new assets including substations, control centers, data centers
    • Security monitoring, logging, and alerting
    • Malware prevention and vulnerability management
    • NERC CIP Transient Cyber Asset protections
    • Security Patch Management
  • Daily reconciliation of configuration baseline changes against change authorizations to detect unauthorized deviations.
  • Level I triage of detected cybersecurity logging failures. Collaborate with asset owners/stakeholders regarding cyber assets that have failed logging.
  • Maintenance of cyber asset inventory information for accuracy.
  • Facilitate change management reviews, task completion, and evidence corresponding work.
  • Monitor systems for non-compliance with standards and escalate to appropriate members of leadership.
  • Support change management initiatives, security assessments and Change Advisory Board reviews
  • Participate in disaster recovery planning, preparation, and testing.
  • Support other departmental initiatives such as vulnerability assessments, penetration testing, internal assessments/tiger teams, or as stakeholders in other team’s capital projects
  • Be an active member in preparation for audits
  • Participate in audit interviews as directed by leadership
  • Identify and Implement improvement opportunities including automation, tool configuration, and process changes.
  • Support department projects, such as new hardware deployments, software upgrades, capability enhancements, etc.
  • Expand services provided as directed by leadership.
  • Other duties as required

 

Minimum Requirements:

Minimum Education Required:

  • Bachelor’s degree in computer science, Information Systems, MIS or a related discipline or equivalent work experience. 
  • Certification/License: Cybersecurity certification preferred (e.g. CISSP, CISA, CRISC, etc.)

Minimum Experiences Required:

  • Minimum Years of Experience: 10+
    • 8+ years of technical experience in data collection and analysis.
    • 8+ years of experience in Cyber Security; preferred domains include Configuration Monitoring, Backup & Recovery, Change Management Oversight, Asset Reuse and Disposal, NERC CIP, NIST CSF, Security Controls planning and/or auditing, security monitoring and analysis.
    • Experience with OT environments preferred.
    • Security Tool Experience:
    • Hands-on expert experience with, and

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Entergy

View company profile →