SonicJobs Logo
Left arrow iconBack to search

Senior Cybersecurity Engineer, Operational Technology

Platte River Power Authority
Posted a day ago, valid for 19 days
Location

Fort Collins, CO, US

Salary

$153,404 - $222,458 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • Platte River Power Authority is seeking a cybersecurity professional with 7-10 years of experience in Operational Technology (OT) environments.
  • The role involves designing and implementing cybersecurity controls for various OT systems, ensuring compliance with industry frameworks and regulatory requirements.
  • Key responsibilities include risk management, incident response, and the development of security architecture and standards.
  • The position offers a salary range of $153,404 to $222,458, with a hiring range of $153,404 to $188,041.
  • Candidates must possess a Bachelor’s degree in a related field and may need to obtain specific cybersecurity certifications within 12 months of hire.

Recruitment notice: Platte River Power Authority does not accept unsolicited resumes from headhunters, recruitment agencies or fee-based placement services. No agency emails, calls, or solicitations to staff are accepted without a valid agreement. Any unsolicited resume submitted to staff will be considered property of Platte River Power Authority and with no obligation to pay any referral fees.

 

Job Summary

 

A member of the cybersecurity team, this person is responsible for designing, implementing, and continuously improving cybersecurity controls that protect the organization's Operational Technology (OT) environments, including industrial control systems (ICS), SCADA, distributed energy resources (DER), and supporting infrastructure. The role also supports OT security monitoring, incident response, and vulnerability management while ensuring alignment with industry frameworks and regulatory requirements. Serves as Platte River's dedicated OT cybersecurity subject matter expert, and establishes security architecture, standards, risk management practices, and monitoring strategies that align with enterprise cybersecurity objectives while supporting operational safety, reliability, and regulatory compliance.

 

Essential duties and responsibilities

 

OT Security Design & Architecture

  • Define and maintain OT cybersecurity standards, reference architectures, and secure design patterns
  • Design and recommend cybersecurity controls for ICS, SCADA, DCS, and OT network environments
  • Establish and guide implementation of network segmentation strategies between IT and OT environments using an ISA/IEC 62443 zone-and-conduit model with documented Security Level targets
  • Ensure alignment between enterprise cybersecurity architecture and OT operational requirements
  • Provide security guidance for emerging platforms such as DERMS, and IIoT
  • Provide cybersecurity design input for new and changing generation assets (BESS, solar, wind, DER), in coordination with resource planning.

OT Risk Management & Governance

  • Perform risk assessments, threat modeling, and security reviews of OT systems and architecture
  • Identify and communicate OT cybersecurity risks to technical and business stakeholders
  • Define security baselines and minimum control requirements for OT environments
  • Support development and continuous improvement of OT cybersecurity policies, standards, and procedures
  • Ensure all security recommendations account for safety, reliability, and operational constraints

Threat Detection & Incident Response

  • Partner with OT teams to monitor OT environments using specialized detection tools; coordinate with the OT MSSP and enterprise IT security for monitoring coverage and escalation rather than a one-person 24/7 on-call model
  • Establish and tune OT detection use cases and baselines in partnership with the OT MSSP
  • Support investigation and response to OT-related security incidents and support OT incident reporting (CIP-008) in coordination with the CIP Compliance Analyst
  • Contribute to development and testing of OT incident response playbooks and tabletop exercises
  • Triage and act on OT threat-hunting findings and monitoring from the OT MSSP, and drive continuous monitoring improvements

Vulnerability & Patch Management

  • Identify and assess vulnerabilities in OT systems, firmware, and applications
  • Define risk-based remediation and mitigation strategies in coordination with OT stakeholders
  • Guide patching approaches that balance cybersecurity risk with operational uptime
  • Conduct risk assessments for legacy and unsupported systems and define compensating controls

Asset Visibility & Identity Management

  • Develop and maintain visibility into OT assets, communications, and data flows
  • Establish a roadmap for machine identity, certificate lifecycle, and trust relationships in OT environments
  • Guide implementation of secure authentication mechanisms for users, devices, and remote access
  • Build and maintain OT asset inventory and visibility, aligned to current CISA OT asset inventory guidance and supporting BES Cyber System identification (CIP-002)

Network Security & Monitoring

  • Define OT network security requirements, including segmentation, zoning, and access controls
  • Review and validate firewall rulesets and architecture for alignment with enterprise standards
  • Analyze OT network traffic patterns and support anomaly detection efforts
  • Partner with network and OT teams to strengthen monitoring coverage and visibility
  • Select, deploy, and tune OT-aware monitoring tools (e.g., passive network monitoring, internal network security monitoring)

Compliance & Governance

  • Ensure alignment with applicable frameworks and standards, including:
  • NIST Cybersecurity Framework (CSF)
  • NIST SP 800-82 (ICS Security)
  • NERC CIP requirements (notably CIP-002, -005, -007, -010, and -011 as design constraints)
  • ISA/IEC 62443 (zones and conduits, Security Level targets)
  • Support internal and external audits, assessments, and evidence collection
  • Translate regulatory requirements into practical, risk-based security controls
  • Maintain documentation related to OT cybersecurity controls, risks, and exceptions

Vendor & Technology Integration

  • Evaluate OT security technologies and recommend solutions that support operations and align with enterprise strategy.
  • Provide cybersecurity guidance during deployment of OT systems and integrations
  • Define and govern secure remote access requirements for vendors and third parties
  • Assess vendor risk associated with OT systems, software, and managed services, contributing OT-side technical input to vendor security review and the CIP-013 supply-chain process (vendor security questionnaires, PSIRT/E-ISAC advisory monitoring, SBOM intake)

Training & Awareness

  • Provide cybersecurity guidance and education to OT engineering and operations teams
  • Promote awareness of secure practices for plant operators and technical staff
  • Act as a liaison between enterprise cybersecurity and OT teams to improve collaboration and shared understanding

 

Knowledge, skills, and abilities

 

  • Advanced 7-10 years of knowledge of Operational Technology (OT) environments, including ICS, SCADA, DCS, industrial networks, and related cybersecurity risks.
  • Ability to design and implement secure OT architectures, including network segmentation, access controls, and secure remote access solutions.
  • Knowledge of applicable OT cybersecurity frameworks, standards, and regulations, including NIST CSF, NIST SP 800-82, ISA/IEC 62443, and NERC CIP requirements.
  • Skill in conducting risk assessments, threat modeling, vulnerability management, and developing risk-based remediation strategies.
  • Ability to support OT threat detection, incident response, and security monitoring while balancing operational reliability and safety requirements.
  • Skill in evaluating and integrating OT security technologies, vendors, and third-party solutions to strengthen cybersecurity posture.
  • Ability to communicate cybersecurity risks and recommendations effectively and build collaborative relationships across cybersecurity, engineering, operations, and compliance teams. Advanced knowledge of Operational Technology (OT) environments, including ICS, SCADA, DCS, industrial networks, and related cybersecurity risks.
  • Ability to design and implement secure OT architectures, including network segmentation, access controls, and secure remote access solutions.
  • Knowledge of applicable OT cybersecurity frameworks, standards, and regulations, including NIST CSF, NIST SP 800-82, ISA/IEC 62443, and NERC CIP requirements.
  • Skill in conducting risk assessments, threat modeling, vulnerability management, and developing risk-based remediation and mitigation strategies.
  • Ability to support OT threat detection, incident response, and security monitoring while balancing operational reliability, safety, and business needs.
  • Skill in assessing vendor and third-party cybersecurity risks, establishing secure technology integration requirements, and supporting supply chain security management.
  • Ability to communicate cybersecurity risks and recommendations effectively and build collaborative relationships across cybersecurity, engineering, operations, compliance, vendors, and business stakeholders.

 

Qualifications

 

Required education and licenses

  • Bachelor’s degree in Cybersecurity, Computer Engineering, Electrical Engineering, or related field (or equivalent experience)
  • Current valid driver’s license and ability to remain insurable under the vehicle liability policy
  • GICSP or GCIP (GIAC Critical Infrastructure Protection) certification or ability to earn within 12 months of hire

 

Required work experience

  • 7–10 years of experience in cybersecurity, with exposure to OT/ICS environments
  • Knowledge of industrial protocols (Modbus, DNP3, OPC, IEC 61850, etc.)
  • Experience with OT security tools (e.g., Nozomi, Claroty, Dragos, Tenable.ot, Splunk)
  • Experience with network segmentation, firewalls, and security architecture principles
  • Practical understanding of how NERC CIP shapes OT controls, and the ability to work with compliance staff on the technical aspects
  • Familiarity with threat detection, incident response, and security monitoring practices

 

Preferred education, licenses and work experience

  • Experience with certificate lifecycle and machine identity management in OT environments
  • Experience with OT security platforms (e.g., Nozomi, Claroty, Dragos, Tenable.ot, Splunk)
  • Familiarity with Palo Alto, Cisco, or similar network/security platforms
  • Knowledge of cloud-to-plant integrations (IIoT)
  • Experience securing remote access solutions (VPN, ZTNA)
  • Experience with energy or utilities
  • Background in energy, utilities, or critical infrastructure sectors
  • Preferred Certifications
    • CISSP or CISM
    • GRID (GIAC Response and Industrial Defense)
    • ISA/IEC 62443 certification (Cybersecurity Fundamentals Specialist or higher)

 

Physical demands

 

Minimal physical effort typically found in clerical work. Primarily sedentary, may occasionally lift and carry light objects. Minimal walking or standing as needed.

 

Hazards

 

Minimal exposure to hazards are typically found in general office environment where there is rarely to no exposure to injury or accident.

 

Work environment

 

Exposure to routine office noise and equipment

 

Pay

 

Salaries are paid bi-weekly and are annualized below for reference. Factors that may be used to determine actual salary include special skills, years of experience, education, and certifications.

 

Full range: $153,404 to $222,458

Hiring range: $153,404 to $188,041




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.