Jobs and Careers
EN

Cybersecurity Engineer I or II

Entergy
The Woodlands, United Statesfull_timeVerifiedPosted 11 Apr 2024

About the role

Posting End Date:  

Work Place Flexibility: Hybrid 

Legal Entity: Entergy Services, LLC 

***These positions may be filled in any city within Entergy's service territory, The Woodlands Tx or New Orleans LA preferred ***

 

Brief Position Description

The OT Cyber Security team executes and/or oversees the activities required to secure Entergy’s critical systems and assets as well as meet or exceed Entergy’s commitment and obligation to the North American Electric Reliability Corporation Critical

Infrastructure Protection (NERC CIP) standards. This position is expected to have operational experience in areas of

information technology, operational technology, and cyber security, with experience working in electrical power, professional auditing, and risk-based compliance processes preferred. Engineers are accountable to perform daily assigned activities, escalate issues identified while performing daily activities, and identification and implementation of process improvement opportunities, while ensuring Entergy can demonstrate compliance with the NERC CIP requirements.

 

Key responsibilities include:

  • Ensure OT cyber assets meet or exceed regulatory requirements and industry best practices
  • For OT environments, responsible for ensuring security and compliance with relevant regulatory compliance requirements (e.g. North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP), etc. Including but not limited to:
    • Configuration Baselines and monitoring
    • Electronic Security Perimeters (ESP)
    • Asset inventory and classification
    • Commissioning new assets including substations, control centers, data centers
    • Security monitoring, logging, and alerting
    • Malware prevention and vulnerability management
    • Transient cyber asset protections
    • Security Patch Management
  • Monitor systems for non-compliance with standards and escalate to appropriate members of leadership.
  • Support change management initiatives and weekly activities, including  security assessments and Change Advisory Board review and approvals
  • Participate in disaster recovery planning, preparation and testing.
  • Support other departmental initiatives such as vulnerability assessments, penetration testing, internal assessments/tiger teams, or as stakeholders in other teams capital projects
  • Be an active member in preparation for required audits
  • Participate in audit interviews as directed by leadership
  • Identify and Implement improvement opportunities including automation, tool configuration, and process changes
  • Support department projects, such as new hardware deployments, software upgrades, capability enhancements, etc.
  • Expand services provided as directed by leadership
  • Other duties as required

 

Experiences needed

  • Info Sec Engineer I: 0 to 2 years of relevant experience
  • Info Sec Engineer II: 2+ years of relevant experience

 

Education needed

  • Associates degree or equivalent work experience
  • Bachelor’s degree preferred

 

Knowledge, skills and abilities needed:

    • Basic knowledge of PC, presentation, word processing, and analytical software
    • Basic data collection and analysis skills
    • Basic ability to work in cross-functional teams
    • Basic experience in call center and/or customer service rolls
    • Simple problem solving skills
    • Experience working in an on-call team rotation preferred but not required
    • Good organizational and time management skills
    • Ability to work effectively with team members and with customers
    • Strong organizational and time management skills
    • Commitment to customer service with strong oral and written communication skills
    • Available to travel up to 25%
    • Self-motivated, with ability to manage and follow-up on multiple tasks simultaneously
    • Capable of meeting deadlines

 

Knowledge, skills and abilities desired:

    • Understanding of basic cyber security principles.
    • Understanding of NERC CIP Standards
    • Understanding of security impacts of other regulations (NRC 10 CFR 73.54, SOX, HIPAA, etc.)
    • Knowledge of security, risk, and control frameworks, standards, and best practices such as ISO 27001 and 27002, SANS-CAG, ITIL, NIST CSF, NIST 800-53, C2M2, etc.)
    • Understanding of multiple cyber security domains, such as:
      • Asset, Change, and Configuration Management
      • Threat and Vulnerability Management
      • Risk Management
      • Identity and Access Management
      • Situational Awareness
      • Incident Response and Continuity of Operations
      • Third-P

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Entergy

View company profile →