Platte River Power Authority

Senior Cybersecurity Engineer, Operational Technology

Platte River Power Authority Fort Collins, Colorado, United States · $153K–$222K/yr

Utilities · 201-500 employees

17 h ago
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Senior Cybersecurity Engineer is responsible for designing and implementing security controls to protect Operational Technology environments, including industrial control systems and SCADA. They will also lead risk assessments, threat detection strategies, and ensure compliance with industry frameworks like NERC CIP.

What they look for

Cybersecurity Operational Technology ICS SCADA Network Segmentation Risk Management Vulnerability Management Incident Response NERC CIP ISA/IEC 62443 Threat Modeling Security Architecture Industrial Protocols Compliance Identity Management

Requirements

Candidates must have 7-10 years of experience in cybersecurity with a focus on OT/ICS environments and hold a bachelor's degree in a relevant field. Proficiency in industrial protocols, network security architecture, and regulatory compliance frameworks is essential for this role.

Full description

Recruitment notice: Platte River Power Authority does not accept unsolicited resumes from headhunters, recruitment agencies or fee-based placement services. No agency emails, calls, or solicitations to staff are accepted without a valid agreement. Any unsolicited resume submitted to staff will be considered property of Platte River Power Authority and with no obligation to pay any referral fees.

Job Summary

A member of the cybersecurity team, this person is responsible for designing, implementing, and continuously improving cybersecurity controls that protect the organization's Operational Technology (OT) environments, including industrial control systems (ICS), SCADA, distributed energy resources (DER), and supporting infrastructure. The role also supports OT security monitoring, incident response, and vulnerability management while ensuring alignment with industry frameworks and regulatory requirements. Serves as Platte River's dedicated OT cybersecurity subject matter expert, and establishes security architecture, standards, risk management practices, and monitoring strategies that align with enterprise cybersecurity objectives while supporting operational safety, reliability, and regulatory compliance.

Essential duties and responsibilities

OT Security Design & Architecture

  • Define and maintain OT cybersecurity standards, reference architectures, and secure design patterns
  • Design and recommend cybersecurity controls for ICS, SCADA, DCS, and OT network environments
  • Establish and guide implementation of network segmentation strategies between IT and OT environments using an ISA/IEC 62443 zone-and-conduit model with documented Security Level targets
  • Ensure alignment between enterprise cybersecurity architecture and OT operational requirements
  • Provide security guidance for emerging platforms such as DERMS, and IIoT
  • Provide cybersecurity design input for new and changing generation assets (BESS, solar, wind, DER), in coordination with resource planning.

OT Risk Management & Governance

  • Perform risk assessments, threat modeling, and security reviews of OT systems and architecture
  • Identify and communicate OT cybersecurity risks to technical and business stakeholders
  • Define security baselines and minimum control requirements for OT environments
  • Support development and continuous improvement of OT cybersecurity policies, standards, and procedures
  • Ensure all security recommendations account for safety, reliability, and operational constraints

Threat Detection & Incident Response

  • Partner with OT teams to monitor OT environments using specialized detection tools; coordinate with the OT MSSP and enterprise IT security for monitoring coverage and escalation rather than a one-person 24/7 on-call model
  • Establish and tune OT detection use cases and baselines in partnership with the OT MSSP
  • Support investigation and response to OT-related security incidents and support OT incident reporting (CIP-008) in coordination with the CIP Compliance Analyst
  • Contribute to development and testing of OT incident response playbooks and tabletop exercises
  • Triage and act on OT threat-hunting findings and monitoring from the OT MSSP, and drive continuous monitoring improvements

Vulnerability & Patch Management

  • Identify and assess vulnerabilities in OT systems, firmware, and applications
  • Define risk-based remediation and mitigation strategies in coordination with OT stakeholders
  • Guide patching approaches that balance cybersecurity risk with operational uptime
  • Conduct risk assessments for legacy and unsupported systems and define compensating controls

Asset Visibility & Identity Management

  • Develop and maintain visibility into OT assets, communications, and data flows
  • Establish a roadmap for machine identity, certificate lifecycle, and trust relationships in OT environments
  • Guide implementation of secure authentication mechanisms for users, devices, and remote access
  • Build and maintain OT asset inventory and visibility, aligned to current CISA OT asset inventory guidance and supporting BES Cyber System identification (CIP-002)

Network Security & Monitoring

  • Define OT network security requirements, including segmentation, zoning, and access controls
  • Review and validate firewall rulesets and architecture for alignment with enterprise standards
  • Analyze OT network traffic patterns and support anomaly detection efforts
  • Partner with network and OT teams to strengthen monitoring coverage and visibility
  • Select, deploy, and tune OT-aware monitoring tools (e.g., passive network monitoring, internal network security monitoring)

Compliance & Governance

  • Ensure alignment with applicable frameworks and standards, including:
  • NIST Cybersecurity Framework (CSF)
  • NIST SP 800-82 (ICS Security)
  • NERC CIP requirements (notably CIP-002, -005, -007, -010, and -011 as design constraints)
  • ISA/IEC 62443 (zones and conduits, Security Level targets)
  • Support internal and external audits, assessments, and evidence collection
  • Translate regulatory requirements into practical, risk-based security controls
  • Maintain documentation related to OT cybersecurity controls, risks, and exceptions

Vendor & Technology Integration

  • Evaluate OT security technologies and recommend solutions that support operations and align with enterprise strategy.
  • Provide cybersecurity guidance during deployment of OT systems and integrations
  • Define and govern secure remote access requirements for vendors and third parties
  • Assess vendor risk associated with OT systems, software, and managed services, contributing OT-side technical input to vendor security review and the CIP-013 supply-chain process (vendor security questionnaires, PSIRT/E-ISAC advisory monitoring, SBOM intake)

Training & Awareness

  • Provide cybersecurity guidance and education to OT engineering and operations teams
  • Promote awareness of secure practices for plant operators and technical staff
  • Act as a liaison between enterprise cybersecurity and OT teams to improve collaboration and shared understanding

Knowledge, skills, and abilities

  • Advanced 7-10 years of knowledge of Operational Technology (OT) environments, including ICS, SCADA, DCS, industrial networks, and related cybersecurity risks.
  • Ability to design and implement secure OT architectures, including network segmentation, access controls, and secure remote access solutions.
  • Knowledge of applicable OT cybersecurity frameworks, standards, and regulations, including NIST CSF, NIST SP 800-82, ISA/IEC 62443, and NERC CIP requirements.
  • Skill in conducting risk assessments, threat modeling, vulnerability management, and developing risk-based remediation strategies.
  • Ability to support OT threat detection, incident response, and security monitoring while balancing operational reliability and safety requirements.
  • Skill in evaluating and integrating OT security technologies, vendors, and third-party solutions to strengthen cybersecurity posture.
  • Ability to communicate cybersecurity risks and recommendations effectively and build collaborative relationships across cybersecurity, engineering, operations, and compliance teams. Advanced knowledge of Operational Technology (OT) environments, including ICS, SCADA, DCS, industrial networks, and related cybersecurity risks.
  • Ability to design and implement secure OT architectures, including network segmentation, access controls, and secure remote access solutions.
  • Knowledge of applicable OT cybersecurity frameworks, standards, and regulations, including NIST CSF, NIST SP 800-82, ISA/IEC 62443, and NERC CIP requirements.
  • Skill in conducting risk assessments, threat modeling, vulnerability management, and developing risk-based remediation and mitigation strategies.
  • Ability to support OT threat detection, incident response, and security monitoring while balancing operational reliability, safety, and business needs.
  • Skill in assessing vendor and third-party cybersecurity risks, establishing secure technology integration requirements, and supporting supply chain security management.
  • Ability to communicate cybersecurity risks and recommendations effectively and build collaborative relationships across cybersecurity, engineering, operations, compliance, vendors, and business stakeholders.

Qualifications

Required education and licenses

  • Bachelor’s degree in Cybersecurity, Computer Engineering, Electrical Engineering, or related field (or equivalent experience)
  • Current valid driver’s license and ability to remain insurable under the vehicle liability policy
  • GICSP or GCIP (GIAC Critical Infrastructure Protection) certification or ability to earn within 12 months of hire

Required work experience

  • 7–10 years of experience in cybersecurity, with exposure to OT/ICS environments
  • Knowledge of industrial protocols (Modbus, DNP3, OPC, IEC 61850, etc.)
  • Experience with OT security tools (e.g., Nozomi, Claroty, Dragos, Tenable.ot, Splunk)
  • Experience with network segmentation, firewalls, and security architecture principles
  • Practical understanding of how NERC CIP shapes OT controls, and the ability to work with compliance staff on the technical aspects
  • Familiarity with threat detection, incident response, and security monitoring practices

Preferred education, licenses and work experience

  • Experience with certificate lifecycle and machine identity management in OT environments
  • Experience with OT security platforms (e.g., Nozomi, Claroty, Dragos, Tenable.ot, Splunk)
  • Familiarity with Palo Alto, Cisco, or similar network/security platforms
  • Knowledge of cloud-to-plant integrations (IIoT)
  • Experience securing remote access solutions (VPN, ZTNA)
  • Experience with energy or utilities
  • Background in energy, utilities, or critical infrastructure sectors
  • Preferred Certifications
  • CISSP or CISM
  • GRID (GIAC Response and Industrial Defense)
  • ISA/IEC 62443 certification (Cybersecurity Fundamentals Specialist or higher)

Physical demands

Minimal physical effort typically found in clerical work. Primarily sedentary, may occasionally lift and carry light objects. Minimal walking or standing as needed.

Hazards

Minimal exposure to hazards are typically found in general office environment where there is rarely to no exposure to injury or accident.

Work environment

Exposure to routine office noise and equipment

Pay

Salaries are paid bi-weekly and are annualized below for reference. Factors that may be used to determine actual salary include special skills, years of experience, education, and certifications.

Full range: $153,404 to $222,458

Hiring range: $153,404 to $188,041

Similar roles