Job DescriptionThe Senior Cyber Security Engineer is a technical authority responsible for setting technical directions for the delivery of enterprise security solutions. This role defines security standards and architecture, serves as a key resource during major security incidents, mentors engineers across the team, and drives continuous improvement of Tri-State's cybersecurity posture. The position operates with a high degree of autonomy and represents the Cyber Security function to leadership and enterprise stakeholders.
Note: There is one position available, and this position will be filled at one of four job grade levels: Cyber Security Engineer I, job grade 6; Cyber Security Engineer II, job grade 7; Cyber Security Engineer III, job grade 9 or Senior Cyber Security Engineer, job grade 10. This decision will be based on the qualifications and experience of the selected candidate and Tri-State business needs at the time of hire.
Tri-State recognizes the value of a highly engaged and committed workforce and provides an excellent benefits program that includes : Medical Insurance, Dental Insurance, Vision Insurance, Flexible Work Schedules including compressed work week and telecommuting opportunities to work remotely up to 40%, Health Savings Account (HSA), Flexible Spending Accounts (FSA), Tuition Reimbursement, Life Insurance, Retirement Option, Long Term Disability (LTD), Short Term Disability (STD), Employee Assistant Program (EAP) and Paid Leave Benefits.
Senior Cyber Security EngineerHiring Salary Range: $109,000-$139,000
Cyber Security Engineer IIIHiring Salary Range: $98,000-$124,000
Cyber Security Engineer IIHiring Salary Range: $80,000-$99,000
Cyber Security Engineer IHiring Salary Range: $72,000-$88,000
Actual compensation offer to candidate may vary outside of the posted hiring salary range based upon work experience, education and/or skill level.
Responsibilities- Set technical direction and define standards for the architecture, configuration, and lifecycle of enterprise security platforms, including firewalls, SIEM, intrusion detection/prevention systems, CND tools, network access control, and other security platforms.
- Evaluate, recommend, and lead the adoption of new security technologies, tools, and capabilities to advance Tri-State's security posture.
- Own the enterprise risk management approach; oversee the risk register, and present risk assessments, mitigation plans, and recommendations to senior and executive management.
- Serve as backup incident lead / commander during major or high-severity security incidents; direct containment, coordinate response across teams, and work directly with data asset owners and business response plan owners.
- Lead post-incident reviews and drive resulting program-wide improvements to detection, response, and prevention.
- Define and lead the threat hunting, detection engineering, and adversary tracking strategy.
- Establish security processes, control frameworks, standards, and documentation, and drive continuous improvement across the enterprise.
- Provide strategic direction for the vulnerability management program and for third-party/vendor risk assessment.
- Serve as the senior escalation point for complex engineering and investigation challenges across all security domains and technology stacks.
- Advise on compliance strategy, including NERC CIP and SOX, and represent the Cyber Security function in audits and with regulators as needed.
- Mentor, coach, and develop Cyber Security Engineers at all levels; lead knowledge sharing and establish engineering best practices.
- Partner with leaders across the enterprise to build support and partnership for cyber asset data collection and management across all technologies.
- Lead cross-functional and enterprise-wide security initiatives from concept through delivery.
- Research emerging threats and vulnerabilities and translate them into actionable defensive strategy.
- Maintain compliance with all company policies and procedures and serve as a subject-matter expert on the regulations, laws, standards, and best practices applicable to the functional area.
- Because Tri-State has an obligation to provide continuous, reliable electric service to its customers, the ability to work overtime at any time of the day or week is considered an essential function of the job.
OTHER DUTIES / RESPONSIBILITIES- Perform other related duties as assigned.
QualificationsEducation and TrainingBachelor's degree in cybersecurity, computer science, information technology, information security, information assurance, or a related field, or equivalent work experience.
Experience Eight (8) or more years of experience in cybersecurity engineering or a related field.
- Expert-level experience with security architecture, engineering, and operational support.
- Deep expertise across security technologies (firewall, antivirus, intrusion detection/prevention, SIEM, vulnerability scanning, data loss prevention, encryption, PKI, Identity and Access Management, Rights Management Services, etc.).
- Recognized expertise leading incident/forensic response planning and execution, including as a backup incident lead for major events.
- Extensive experience designing security processes, control frameworks, and standards.
- Experience leading auditor coordination and control compliance at an enterprise level.
- Advanced proficiency with one or more scripting languages (e.g., Python, JavaScript, Scapy).
- Demonstrated ability to set technical direction, lead enterprise initiatives, and mentor and develop engineers.
- Strong executive communication skills, including presenting to senior leadership.
- Ability to work in a fast-paced environment and manage workload during periods of stress or escalated activity.
Note: The above requirements describe the experience and education qualifications for the Senior Cyber Security Engineer. Those with less experience will be hired at the I, II or III job grade level.
Knowledge, Skills, and Abilities- Expert understanding of Internet Protocol (IP), Transmission Control Protocol (TCP)/IP, and other network administration protocols.
- Deep technical knowledge of Microsoft server infrastructure and networking, Linux/Unix variant operating systems.
- Deep familiarity with governance and controls frameworks, such as Center for Internet Security (CIS) security controls, North American Electric Reliability Corporation (NERC) CIP compliance requirements, and National Institute of Standards and Technology (NIST) standards, with the ability to interpret and guide the organization on their application.
- Expert knowledge of security architectures and devices.
- Ability to define and lead threat intelligence consumption and management.
- Expert knowledge of the root causes of malware infections and proactive mitigation.
- Expert knowledge of lateral movement, footholds, and data exfiltration techniques.
- Track record of creative problem solving, and the desire to create and build new processes and standards.
- Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate option.
- Excellent oral and written communication skills, including presenting to senior leadership.
- Ability to build and maintain effective working relationships across the enterprise and with external stakeholders.
Other- Willingness to travel up to 10% for investigations, meetings and training as needed. (Must possess a valid driver's license.)
- Willingness to work on-call duty as assigned.
DESIRED JOB QUALIFICATIONSOne or more of the following security industry certifications and knowledge regarding security frameworks and regulations required, or the ability to obtain within an agreed timeframe:
- Certified Information Systems Security Professional (CISSP)
- Global Information Assurance Certification (GIAC)
- Certified Information Systems Auditor (CISA)
- An MS, MBA, or related advanced degree desired.
- Experience in Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS).
- Experience in Sarbanes-Oxley (SOX) and North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) compliance.
- Experience in designing and delivering security awareness training.