Jobs and Careers
ED

IT Network Security Lead (NERC)

EDP
United Statesfull_timeVerifiedPosted 18 Dec 2024

About the role

EDP Renewables is a global leader in the renewable energy sector and currently operates in more than 25 markets. With eight offices and several sites, at EDP Renewables North America, we are experienced developers and operators of renewable energy. Our portfolio includes wind farms, solar parks, energy storage projects, and green hydrogen solutions throughout the continent. We are ranked among the top 5 in the U.S. in operational renewable energy capacity.
 

Our company is part of EDP, a global energy group present in around 30 markets with a particular emphasis on renewable energies. With more than 45 years of experience, we have been consolidating a relevant presence on the world energy scene based on the commitment to be all-green by 2030, leading the energy transition. With more than 13,000 employees around the world, we are committed to using our energy and heart to drive a better tomorrow.

 

What you will do

Role Overview:

The NA IT NERC Security Lead will work as part of the IT Team to develop, implement, and maintain the security posture of both the corporate infrastructure and technical networks including networks that must maintain compliance with NERC CIP Standards. This is a role that will require in depth knowledge centered on Anti-Virus/Anti-Malware management, firewall rule design, IPS/IDS, web-filtering, SEIM logging, and security event alerting. This role will work with other security team members to execute vulnerability assessments, DR planning, pen-testing, and other scheduled activities that support the review of policies, procedures, and practices. The Security Engineer will assist in the further enhancement and design of critical network security posture and support the development of new architecture to meet upcoming CIP standards. 

Main responsibilities:

  • Promote the reliability of EDPR Systems through rigorous compliance with applicable NERC standards monitoring and enforcement activities and functions as a team member for internal and external audit preparation 
  • Ensure relevant, valid, reliable, stacking, and sufficient evidence is available to demonstrate compliance 
  • Ensure effective regulatory compliance to the North American Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) Standards by providing hands on to support and enhance operational business unit’s risk management, Cyber, Information, Physical and Personnel Security programs 
  • Work and support the compliance and regulation team 
  • Maintain and revise security/compliance systems infrastructure including the administration and maintenance of compliance policies, programs, and procedures related to the NERC CIP Standards 
  • Coordinate and support compliance audits conducted by internal resources, consultants, or regulatory organizations 
  • Work with responsible EDPR internal NERC group to resolve compliance issues and develop improvement recommendations and mitigation plans 
  • Document and submit potential violations and ensure they are tracked for timely resolution and fully documented in auditable records 
  • Utilize EDPR compliance technology to assign, track, and monitor compliance efforts 
  • Implement and/or recommend appropriate IT initiatives to ensure effective integration of compliance programs or initiatives 
  • Configure and install various network devices and services (i.e., routers, switches, firewalls, etc.) 
  • Monitor system resource utilization, trending, and capacity planning 
  • Select and implement security tools, policies, and procedures 
  • Design and implement configurations management, reporting, and alerting functions to automate the environment 
  • Follow standard methodologies and develop new and innovative processes for delivering information security solutions 
  • Additional duties as required 

Employment type

Work site

What are we looking for

Minimum Requirements:

  • Bachelor's degree in Computer Science, Information Technology, or a related field 
  • 7+ years' experience in cybersecurity 
  • Prior NERC CIP v5/6 audit experience (preferably within the TRE audit region) 
  • Prior physical security regulatory experience 
  • Working knowledge of the FERC functional model 
  • Good Understanding of NIST-800 and ISO 27001 Security Frameworks 
  • Strong Cisco ASA, IPS, and IDS configuration and troubleshooting skillset 
  • Solid TCP/IP networking foundation including routing, sub netting, VPN, packet filtering/firewalling, VLANs, packet capture/analysis, and NAT configuration 
  • Demonstrated experience in system hardening and Active Directory security policy implementation 
  • SEIM management: logging, alerting, and report development 
  • Advanced Secu

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

EDP

View company profile →