CybersecurityJobs.io
← Back to all jobs

Job Description

Platte River Power Authority is seeking a Senior Cybersecurity Engineer focused on Operational Technology (OT) security to help design, implement, and continuously improve cybersecurity controls across its OT environments. This role operates as Platte River’s dedicated OT cybersecurity subject matter expert, shaping OT security architecture, standards, and risk management practices while aligning monitoring and incident response support with enterprise objectives and applicable regulations. The position is based in Fort Collins, CO and works onsite.

What you’ll do

  • Define and maintain OT cybersecurity standards, including reference architectures and secure design patterns.
  • Design and recommend cybersecurity controls for ICS, SCADA, DCS, and broader OT network environments.
  • Establish and guide implementation of network segmentation between IT and OT using the ISA/IEC 62443 zone-and-conduit model, including documented Security Level targets.
  • Ensure alignment between the enterprise cybersecurity architecture and OT operational requirements.
  • Provide security guidance for emerging platforms such as DERMS and IIoT.
  • Deliver cybersecurity design input for new and changing generation assets (including BESS, solar, wind, DER) in coordination with resource planning.
  • Perform risk assessments, threat modeling, and security reviews of OT systems and architecture.
  • Identify, assess, and communicate OT cybersecurity risks to both technical and business stakeholders.
  • Define security baselines and minimum control requirements for OT environments, and support ongoing improvement of OT cybersecurity policies, standards, and procedures.
  • Ensure recommendations account for safety, reliability, and operational constraints.
  • Partner with OT teams and the OT MSSP for monitoring, escalation, and coverage (without relying on a one-person 24/7 on-call model).
  • Establish and tune OT detection use cases and baselines with the OT MSSP, and triage threat-hunting findings to drive continuous monitoring improvements.
  • Support investigation and response to OT-related security incidents, including OT incident reporting aligned to CIP-008 in coordination with the CIP Compliance Analyst.
  • Contribute to the development and testing of OT incident response playbooks and tabletop exercises.
  • Identify and assess vulnerabilities in OT systems, firmware, and applications; guide risk-based remediation and mitigation strategies with OT stakeholders.
  • Support patching approaches that balance cybersecurity risk with operational uptime, and assess legacy or unsupported systems to define compensating controls.
  • Maintain visibility into OT assets, communications, and data flows.
  • Develop and govern the OT roadmap for machine identity, certificate lifecycle, and trust relationships.
  • Guide implementation of secure authentication mechanisms for users, devices, and remote access.
  • Build and maintain OT asset inventory and visibility aligned to CISA OT asset inventory guidance and supporting BES Cyber System identification (CIP-002).
  • Define OT network security requirements, including zoning, segmentation, and access controls, and validate firewall rulesets for alignment with enterprise standards.
  • Analyze OT network traffic patterns, support anomaly detection, and strengthen monitoring coverage with network and OT teams.
  • Select, deploy, and tune OT-aware monitoring tools (including passive network monitoring and internal network security monitoring).
  • Align OT cybersecurity controls with applicable frameworks and standards, and support internal and external audits, assessments, and evidence collection.
  • Translate regulatory requirements into practical, risk-based security controls, and maintain documentation related to OT cybersecurity controls, risks, and exceptions.
  • Evaluate OT security technologies and recommend solutions that support operations and align with enterprise strategy.
  • Provide cybersecurity guidance during OT deployments and integrations, including secure remote access requirements for vendors and third parties.
  • Assess vendor risk for OT systems, software, and managed services by contributing OT-side technical input to the CIP-013 supply-chain process (including vendor security questionnaires, PSIRT/E-ISAC advisory monitoring, and SBOM intake).
  • Provide cybersecurity guidance and education to OT engineering and operations teams, and act as a liaison between enterprise cybersecurity and OT teams to improve collaboration.

Required qualifications

  • Bachelor’s degree in Cybersecurity, Computer Engineering, Electrical Engineering, or a related field (or equivalent experience).
  • Current valid driver’s license and ability to remain insurable under the vehicle liability policy.
  • GICSP or GCIP (GIAC Critical Infrastructure Protection) certification, or ability to earn within 12 months of hire.
  • 7 to 10 years of cybersecurity experience with exposure to OT/ICS environments.
  • Knowledge of industrial protocols such as Modbus, DNP3, OPC, and IEC 61850 (and similar).
  • Experience with OT security tools such as Nozomi, Claroty, Dragos, Tenable.ot, and Splunk.
  • Experience with network segmentation, firewalls, and security architecture principles.
  • Practical understanding of how NERC CIP shapes OT controls, and ability to work with compliance staff on technical aspects.
  • Familiarity with threat detection, incident response, and security monitoring practices.

Preferred qualifications

  • Experience with certificate lifecycle and machine identity management in OT environments.
  • Familiarity with OT security platforms such as Nozomi, Claroty, Dragos, Tenable.ot, and Splunk.
  • Familiarity with Palo Alto, Cisco, or similar network/security platforms.
  • Knowledge of cloud-to-plant integrations (IIoT) and securing remote access solutions (VPN, ZTNA).
  • Experience in energy, utilities, or critical infrastructure sectors.
  • Preferred certifications: CISSP or CISM, GRID (GIAC Response and Industrial Defense), and ISA/IEC 62443 certification (Cybersecurity Fundamentals Specialist or higher).

Technologies and frameworks

  • ISA/IEC 62443 and zone-and-conduit model
  • NIST Cybersecurity Framework (CSF)
  • NIST SP 800-82 (ICS Security)
  • NERC CIP (including CIP-002, -005, -007, -010, -011, CIP-008, CIP-013)
  • CISA OT asset inventory guidance
  • Industrial protocols: Modbus, DNP3, OPC, IEC 61850
  • OT/security platforms: Nozomi, Claroty, Dragos, Tenable.ot, Splunk
  • OT/energy platforms: DERMS, IIoT, BESS, DCS, ICS, SCADA

Pay and salary range

  • USD 153,404 - 188,041 per year (hiring range)
  • Full range referenced: $153,404 to $222,458
  • Salaries are paid bi-weekly and are annualized for reference; actual salary may depend on skills, years of experience, education, and certifications.

Recruitment notice

  • Platte River Power Authority does not accept unsolicited resumes from headhunters, recruitment agencies, or fee-based placement services.
  • No agency emails, calls, or solicitations to staff are accepted without a valid agreement.
  • Any unsolicited resume submitted to staff will be considered property of Platte River Power Authority with no obligation to pay referral fees.

Work environment and demands: The role involves routine office noise and equipment, primarily sedentary work with minimal physical effort, and occasional lifting and carrying of light objects as needed. Hazards are minimal and similar to a general office environment with rarely to no exposure to injury or accident.

Similar Jobs