RWE

Security Architecture Engineer II

RWE Chicago, Illinois, United States · $105K–$141K/yr

Utilities · 10,001+ employees

Yesterday
Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Security Architecture Engineer II will design and manage the security architecture for industrial control systems across a large fleet of renewable energy sites. This role involves defining security standards, performing risk assessments, and acting as the technical authority for OT security toolchains.

What they look for

Security architecture OT security ICS/SCADA Vulnerability management Threat detection Risk assessment Network engineering Incident response NERC CIP ISA/IEC 62443 CIS Benchmarks SIEM Endpoint protection Technical documentation Cross-functional leadership

Requirements

Candidates must have a bachelor's degree in a relevant field and at least 5 years of experience in cybersecurity or network engineering, with 3 years specifically in OT/ICS environments. Strong communication skills and the ability to work independently in a complex industrial setting are required.

Benefits

Medical Dental Vision Life Insurance Short-term disability Long-term disability 401(k) match Flexible spending accounts Employee assistance program Education assistance Parental leave Paid time off Holidays

Full description

RWE Americas, LLC To start as soon as possible, full time, permanent

Functional area: IT / Digital Remuneration: Exempt

Join RWE Americas' OT Security team and take architectural ownership of the security controls protecting our grid-scale generation fleet. As the Security Architecture Engineer II, you will design and build the defenses standing between live industrial control systems and the threats targeting them, across 160+ wind, solar, and battery storage sites plus natural gas-powered generation in 27 states.

The Security Architecture Engineer II's core focus will be maturing a defensible, standards-based OT security architecture and the platform stack that enforces it. Acting as the technical design authority for operational technology, you will set the reference architectures and secure baselines that every new project is built to, and own the OT security toolchain end to end.

Role Responsibilities:

  • Security Architecture & Platform Ownership:
  • Own the architecture and operation of the OT security toolset — asset visibility and access control, monitoring and SIEM, vulnerability management, endpoint protection, and ICS-aware detection. Define how each platform is laid out and behaves across the fleet, including sensor placement, data flows, policy and enforcement structures, and integration into enterprise security systems, then configure, tune, and lifecycle-manage the platforms and set a repeatable deployment standard for new and acquired sites
  • Standards, Baselines & Documentation:
  • Maintain OT security standards, secure configuration baselines, and hardening requirements aligned to ISA/IEC 62443 and CIS Benchmarks, along with version-controlled reference architectures, connectivity maps, and network diagrams reflecting current and planned state
  • Threat Detection & Monitoring:
  • Onboard OT logs and telemetry into enterprise monitoring platforms with reliable normalization and event forwarding, build and tune OT-specific detection content, and partner with the SOC on use cases, alert routing, and escalation paths
  • Risk Assessment & Vulnerability Management:
  • Perform in-depth OT risk assessments using MITRE ATT&CK for ICS to map attack paths and control gaps, operate a risk-based vulnerability remediation cadence with plant teams, and validate fixes in staging environments ahead of production rollout
  • Incident Resolution:
  • Act as technical escalation point for OT security incidents, leading investigation, threat hunting, and root-cause analysis, and shaping containment plans that respect operational safety and availability constraints
  • Access & Third-Party Assurance:
  • Define least-privilege roles, privileged account controls, access reviews, and MFA where feasible; design secure remote access for internal engineers and vendors; and review OEM- and vendor-supplied designs and third-party connectivity into OT environments, recommending mitigations for identified gaps
  • Security Requirements in Projects & Procurement:
  • Embed OT security requirements into new-build and repowering projects, acquisitions, and OEM and EPC contracts, and review proposed designs and connectivity before commitments are made
  • Cross-Functional Partnership:
  • Serve as the OT security point of contact for OT, plant operations, asset management, project engineering, and the SOC — sequencing security work around maintenance windows and outages, and translating risk into terms each audience can act on
  • Team Enablement & Knowledge Transfer:
  • Produce the runbooks and technical guidance the team runs on, provide informal mentorship to junior analysts and engineers, and deliver hands-on training so site and operations personnel can support OT security controls locally
  • Compliance & Audit Support:
  • Support audit and compliance activity across NERC CIP (as applicable to in-scope assets), TSA security directives, NIST SP 800-82, and ISA/IEC 62443, providing evidence and remediation input as required

Job Requirements and Experience:

  • Bachelor's degree in Engineering, Computer Science, Cybersecurity, IT, or related fields — or equivalent proven track record of security engineering excellence in complex industrial environments
  • Minimum of 5 years in cybersecurity, network engineering, or control systems engineering, including at least 3 years focused on OT/ICS/SCADA environments, working independently within defined processes and providing informal technical guidance to junior team members
  • Strong interpersonal skills, with ability to manage customer relationships
  • Demonstrated desire to learn about the Company and the renewables space
  • Excellent proficiency with Microsoft Office (Excel, Word, PowerPoint, Outlook) and Teams
  • Strong leadership and communication, and ability to meet deadlines
  • Strong organization skills and ability to coordinate multiple tasks and deliverables
  • Ability to multi-task, while working independently and as part of a team
  • Motivated self-starter, goal-oriented, and strong problem-solving abilities
  • Proven ability to empathize, build relationships, and effectively communicate with people from a diverse set of backgrounds
  • Responds well to direction, is easy to challenge and develop, and is coachable
  • Is detail-oriented, has strong business acumen, and a sound understanding of business concepts
  • This position is an office-based role with some travel and visits to other RWEA offices and field locations
  • Must be able to sit, walk, or stand for long durations of time

Applicants must be legally authorized to work in the United States. RWE Americas is unable to sponsor or take over sponsorship of employment visas at this time.

Pay range: The annual base salary range for this position in Illinois or New York is $105,000- $141,000. The listed salary range represents our good faith estimate for this position and represents the range for new hire salaries across all U.S locations. Please note that the salary information is a general guideline only. RWE considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s education & work experience, training & certifications, and key skills as well as market and business considerations at the time of the offer.

Benefits offered: Medical, Dental, Vision, Life Insurance, Short-Term Disability, Long-Term Disability, 401(k) match, Flexible Spending Accounts, EAP, Education Assistance, Parental Leave, Paid time off, and Holidays. Eligible employees also participate in short-term incentives, in addition to salary.

Apply with just a few clicks: ad code 93444. Any questions? Contact HR: rwe_americas_recruiting@rwe.com

We look forward to meeting you. Of course, you can find us on LinkedIn, Instagram, Facebook, YouTube and Xing, too.

All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status.

RWE Americas, a subsidiary of RWE, is a US-based energy company that is helping to meet the growing demand for energy across the United States. Backed by RWE’s 125-year global legacy of managing diverse power assets, RWE Americas operates approximately 13 GW of power projects across 27 states. With a talented workforce of 2,000 employees, RWE Americas develops, constructs and operates wind, solar and battery storage projects that safely deliver affordable, reliable electricity to our customers. Committed to responsible development, RWE Americas invests in local and rural communities, creating jobs and partnering with stakeholders to support and strengthen the places where we live and work. Learn more about how RWE Americas is generating impact at americas.rwe.com.

At RWE Americas, we foster a culture defined by our Essential Behaviors – Have Courage, Create Impact and Actively Collaborate. We encourage bold thinking and continuous learning, and we value ownership, resilience and inclusion in everything we do. When you join us, you become part of a team that supports your development, respects your contributions and celebrates shared success. This is a place where you can grow your career and make a meaningful difference.