Cybersecurity Engineer Sr
EntergyAbout the role
Posting End Date:
Work Place Flexibility: Hybrid
Legal Entity: Entergy Services, LLC
***The official title for this role in our system will be 'Info Sec Engineer Sr'***
Brief Position Description
The Cybersecurity Engineer is responsible for the administration and execution of the Operational Technology Security Patch Management program. The Cybersecurity Engineer will lead internal and external resources in the timely execution of process controls designed to identify security vulnerabilities. The Cybersecurity Engineer will own the governance and management of the NERC CIP-007 R2 controls and will be responsible for internal and external communications and metrics regarding the program. Although technical aptitude is a requirement for this position, this role prioritizes the ability to organize workstreams and products, collaborate with multiple stakeholders, and drive completion of tasks over deep technical knowledge.
Key responsibilities include:
- Oversee the daily operations of the external Security Patch Management team, including:
- Security Patch Discovery and Evaluation
- Creation of mitigation plans
- Patch deployment planning
- Lead collaborative meetings with stakeholders and owners to drive timely completion of activities for compliance with the program and regulatory standards
- Maintain compliance with the NERC CIP-007 R2 controls
- Drive the accuracy of asset inventory within the OT operating environment
- Drive efficiencies and accuracy in continual security patch assessments
- Drive effective communications with external OT asset owners for security patch remediation strategies
- Leverage technology and scripted processes to reduce human interaction in managed processes
- Maintain auditable records of work performed
- Maintain procedures and work instructions for the Security Patch Management program
- Maintain and track performance metrics of external resources assigned to the program
- Work with external solution providers to correct any staffing or performance issues
- Perform required testing of the NERC CIP-007 R2 controls within the Entergy GRC platform
- Represent the Security Patch Management program to leadership and the Corrective Action Program
- Act as the NERC CIP-007 R2 subject matter expert for internal and external audit requests and SERC self-report activity
Education needed
Bachelor’s degree in Computer Science, Information Systems, MIS or a related discipline or equivalent work experience.
Experiences needed
6+ years of relevant work experience
Project/Program Management experience is a plus
Minimum knowledge, skills, and abilities required of the position
- Understanding of general Information Technology and/or Security concepts
- Understanding and experience with Security Patching, Vulnerability Risk Assessments, and Vulnerability Management concepts
- Understanding of general IT and OT architectures, systems, and intercommunications concepts
- Understanding of Configuration Change Management concepts
- Understanding of Operational Technology concepts
- Ability to interpret internal or external business issues and recommending best practices
- Proficiency with Microsoft Office and SharePoint
- Knowledge of security, risk, and control frameworks and standards such as ISO 27001 and 27002, SANS-CAG, NIST, FISMA, COBIT, COSO and ITIL is a plus
- Experience with the following tools is a plus:
- ServiceNow (Change Management, Incident Management, Vulnerability Response)
- Tripwire
- BigFix
- Splunk
- Automation Anywhere
- Ability to quickly adapt to changing events and priorities
- Ability to work independently, with guidance in only the most complex situations
- Strong social, verbal, and written communication skills, with demonstrated ability to effectively present analytical data to a variety of technical and non-technical audiences
- Comfortable working in high stress and ambiguous environments and developing solutions
- Capable of meeting deadlines
Any certificates, licenses, etc., required for the position
SANS GIAC and ISC2 certifications are a plus
#LI-JL1
#LI-HYBRID
Primary Location: Texas-The Woodlands Arkansas : Little Rock || Louisiana : New Orleans || Texas : Houston || Texas : The Woodlands
Job Function: Professional
FLSA Status: Professional
Relocation Option: No Relocation Offered
Union description/code: NON BARGAINING UNIT
Number of Openings: 1
Req ID: 114028
Travel Percentage:Up to 25%
An Equal Op
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s