Capital Power Operations (USA) - Phoenix, AZ

posted about 2 months ago

Full-time - Senior
Remote - Phoenix, AZ
Utilities

About the position

Capital Power Corporation is seeking a Senior Industrial Network Engineer with a strong track record in designing, deploying, and monitoring industrial network communication systems and cyber security programs for our diverse fleet of Thermal and Renewable power generation facilities. This position is a permanent full-time role based in Phoenix, where you will contribute to our commitment to providing reliable and sustainable energy solutions in the power generation industry. As a Senior Industrial Network Engineer, you will be responsible for designing, supporting, monitoring, and maintaining industrial networks and security appliances across the fleet. This includes the integration of greenfield developments, brownfield acquisitions, and existing system modifications, utilizing industry best practices. You will also be involved in network drawing development and authentication as required per change management standards. In this role, you will develop and maintain industrial network security standards, procedures, and guidelines to align with industry best practices and applicable regulations. You will examine and offer insights on industrial network, SCADA, and control system designs to enhance availability and reduce the risk of cyber threats. Additionally, you will be responsible for firewall rule specifications and reviews, developing Cyber Risk Mitigation Plans for Industrial Control Systems, Operational Technology, and associated networks for Critical Infrastructure. You will participate in scope and contract negotiations to mitigate risk, manage OT patch management, and conduct vulnerability assessments, monitoring, and remediation based on risk. You will contribute to the development and ongoing maintenance of the compliance program for NERC Critical Infrastructure Protection (CIP) standards, managing, reviewing, and optimizing existing tools, alerts, and processes within the OT environment. This includes asset management software, SIEM & Logging, network monitoring, and vulnerability scanning tools & alerts, endpoint protection, and privileged access management. You will also contribute to the cybersecurity roadmap and long-term planning to meet and maintain our maturity goals, offering technical direction to contract and maintenance staff to facilitate the completion of ICS-related tasks. Building relationships with external vendors and industry partners will be essential to stay informed about emerging threats and new technologies, as well as contributing to organizational change initiatives through front-end input and post-implementation support.

Responsibilities

  • Design, support, monitor and maintain industrial networks and security appliances across the fleet.
  • Integrate greenfield developments, brownfield acquisitions, and existing system modifications utilizing industry best practices.
  • Develop and maintain industrial network security standards, procedures, and guidelines to align with industry best practices and applicable regulations.
  • Examine and offer insights on industrial network, SCADA, and control system designs to enhance availability and reduce the risk of cyber threats.
  • Specify and review firewall rules.
  • Develop Cyber Risk Mitigation Plans for Industrial Control Systems, Operational Technology and associated networks for Critical Infrastructure.
  • Participate in scope and contract negotiations to mitigate risk.
  • Manage OT patch management and conduct vulnerability assessments, monitoring and remediation based on risk.
  • Contribute to the development and ongoing maintenance of the compliance program for NERC Critical Infrastructure Protection (CIP) standards.
  • Manage, review, and optimize existing tools, alerts, and processes within the OT environment.
  • Contribute to the cybersecurity roadmap and long-term planning to meet and maintain maturity goals.
  • Offer technical direction to contract and maintenance staff to facilitate the completion of ICS-related tasks.
  • Ensure Management of Change (MOC) compliance and review for ICS-related work across the fleet.
  • Build relationships with external vendors and industry partners to stay informed about emerging threats and new technologies.
  • Contribute to organizational change initiatives through front-end input and post-implementation support.

Requirements

  • Completed post-secondary degree in Computer or Electrical Engineering; other educational backgrounds will be considered depending on experience.
  • Eligible for Professional Engineering status in the region of office location.
  • 7+ years of experience with design, support, and maintenance of industrial control or computer systems, including HMIs, servers, and communication networks.
  • 3+ years of ICS network focused experience.
  • Extensive knowledge of network administration, configuration, and troubleshooting.
  • Working knowledge of key network infrastructure components, including network firewalls, switches, routers, and their impact on operating facilities.
  • Advanced knowledge of Operational Technology, SCADA, and ICS Cyber Security best practices.
  • Solid understanding of codes and standards related to controls and industrial networks design.
  • Understanding of industrial communication protocols such as MODBUS, ICCP, DNP3, OPC.
  • Understanding of control systems (PLC, DCS, SCADA, RTU).
  • Familiarity with NIST, NERC CIP and other standards related to cyber security and ICS design.
  • Experience with Windows administration, domain administration and virtualization.
  • Familiarity with CMMS such as Maximo.

Nice-to-haves

  • Additional network and security-related training or cyber certifications would be considered an asset.

Benefits

  • Health care benefits
  • Retirement benefits
  • Paid time off
  • Annual bonus
  • Flexible and affordable employee benefits
  • Comprehensive onboarding and training programs
  • Programs supporting career development
  • Relocation assistance may be available depending on posting requirements
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service