VancouverWARecruiter Since 2001
the smart solution for Vancouver jobs

Information System Security Engineer

Company: Motus Recruiting and Staffing
Location: Vancouver
Posted on: June 12, 2021

Job Description:

Information System Security Engineer 3Our client, a leading Pacific Northwest utility provider committed to public service and environmental preservation, is looking for an Information System Security Engineer for their Vancouver, Washington location. This position will assist management in implementing, managing, operating, and maintaining mission critical systems that support the reliable and secure operations of grid operations as well as critical business applications. This position serves as a programmatic expert for the recommendation, development and implementation of operational cyber security and compliance strategies, standards, processes, guidelines, and projects to safeguard critical cyber assets that are necessary for reliable and secure operation of the assets used in the operation and control of the Bulk Electric System (BES). This position is a one-year contract with the opportunity to renew on an annual basis. It also includes employee benefits! If you think you would be a good fit, we want to hear from you! Responsibilities of Information System Security Engineer: Provide technical expertise on control center infrastructure security architecture and management for control center infrastructure systems and related matters. Applies a broad knowledge of power system operations and associated control center systems including knowledge of security and regulatory (i.e., FISMA and NERC CIP) as it pertains to compliance computer networks, user interfaces, system software, data acquisition, telecommunications, substation field equipment, and related computer hardware areas. Provide Information System Security Officer support and technical expert for the control center General Support Systems and programs by providing expert technical advice, guidance, and recommendations to management and other technical and security specialists on critical operational issues relating to control center control infrastructure and data systems including the upgrade and enhancement of all systems in the two critical control centers. Recommend security strategies in the development of system, software and hardware architectures, technical plans and specifications, system designs, software designs, integration plans, test plans, and project plans. Advises other IT experts and security practitioners throughout the control centers on a variety of situations and issues that involve applying or adapting new security technology theories, concepts, applications, standards, and/or practices. As the control center infrastructure security architect and expert, serve as the project security/compliance lead, on assigned projects, for an interdisciplinary project team of electrical engineering and information technology staff assigned to execute on the most complex control center system projects. Architect and design high availability infrastructures and applications to support current and future grid operations. Verifies that the project plans conform to applicable organizational, agency and external security and compliance standards, policies, and guidelines. Provide technical expertise and assistance with the recommendation, development and implementation of management-approved operational cyber security and compliance strategies, processes, guidelines, and projects to safeguard critical cyber assets. Provide technical input, recommendations, and assistance with the implementation of both higher and granular-level cyber security approaches, methods and solutions that incorporate and maintain compliance to requirements resulting from laws, regulations, or Presidential directives. Develop / draft, recommend and execute management-approved testing plans; report results and recommendations. Provide security engineering expertise and recommendations. In collaboration with the manager and per established procedures, develop a cyber-security architecture for the control centers to include accurate, comprehensive applicable documentation. Perform detailed and comprehensive security event analysis. Provide guidance and input into technical reviews of proposed projects, and system security authorization processes. Provide technical input and support to the Continuous Assessment and Monitoring Program. Draft and recommend detailed project plans, timelines, milestones and objectives for upgrades, patches, and other changes and/or for monitoring security measures for the protection of networks and information. Perform risk assessments and execute tests of data processing system to validate functioning of data processing activities and security measures. Validate appropriate security controls are in place that will safeguard digital files and vital electronic infrastructure. Coordinate, facilitate and assist with general support systems and major applications security and compliance projects and program changes and initiatives that:o Are designed to anticipate, assess, and minimize system vulnerabilities and weaknesses. o Integrate across disciplines, platforms, and internal organizations; (people, processes, systems).o Under the direction and leadership of Management Recommend the scope and level of detail for system security plans and collaborate and assist with draft policies, processes and procedures that are applicable to and promote Transmission Systems Operations security program. Develop / draft long-range plans and strategies for IT security systems that anticipate, identify, evaluate, mitigate, and minimize risks associated with IT systems vulnerabilities. Keep abreast of current and new security technologies and threats. Identify the need or potential opportunity for changes based on new security technologies and threats, present recommendations, and supportive data for consideration. Research and review proposed new systems, networks, and software designs for potential security risks and impacts; recommend mitigation, countermeasures, or other options. Identify integration issues related to the implementation of new systems within the existing infrastructure; recommend mitigation and/or resolution options. Provide subject matter expertise, technical guidance and assistance to other Security Control Assessors, Cyber Security personnel and Transmission Technology Operations (TTO) co-workers on a variety of ad hoc and standing projects requiring data / system process analysis. Provide technical expertise, guidance, and assistance to organizational co-workers with less experience, including cross-training as requested. Requirements of Information System Security Engineer: A Bachelor s degree in Computer Science, Information Technology is highly preferred.o With an applicable bachelor s degree, 15 years of experience is required.o Without an applicable degree, 20 years of experience is required. Experience must include:o Hands on technical implementation of networks and systems.o Experience evaluating various technical, operational and management solutions to security problems, using written language and various media to present alternatives and recommendations.o Proven ability to develop documentation sufficient to arrive at logical and comprehensive conclusions and recommendations. The documentation must be of a sufficient professional level to stand as an artifact for reuse as part of the security architecture.o Experience evaluating the adequacy and existence of IT security controls as is conforms to security architectures.o Experience having properly documented evidence of security architecting, design, and cyber-security activities sufficient for a third-party reviewer to arrive at the conclusion the Security control Assessor has reached in the work.o 3+ years previous experience effectively performing security control implementation on networks, servers, and systems and/or vulnerability assessments. One or more of the following networking or security certifications:o Certified Information Systems Security Professional (CISSP)o Certified Information Systems Auditor (CISA)o Certified Information Security Manager (CISM) 5+ years of experience performing security control evaluation and testing. 8+ years of experience with North American Electric Reliability Corporation, Critical Infrastructure Protection (NERC CIP) regulatory standards and requirements. 10+ years of experience with the Risk Management Framework and the 800 series of National Institute of Standards & Technology (NIST) Special Publications (in particular 800-37, 800-39, 800-53, 800-53A, and 800-115); Expert knowledge on FISMA controls Expert knowledge on NERC-CIP standards Understanding and experience in Federal electrical utility operations and how it interplays with FISMA/NERC-CIP standards and compliance. **We are unable to accommodate corp. to corp. candidates** About Motus Recruiting and Staffing, Inc:Founded in 2006, Motus is an award-winning recruiting and staffing firm in the Pacific Northwest, specializing in professional services and technology solutions. We are a group of people who not only recognize the importance of representation, but actively fight for diversity, equity, and inclusion in the recruitment process. Our goal is to educate organizations on the importance of DEI when hiring, promoting, and supporting diverse employees. We are calling organizations to demonstrate their commitment to DEI by being intentional about who they hire. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, citizenship, disability or protected veteran status. AP / 9114 ($70-$80)

Keywords: Motus Recruiting and Staffing, Vancouver , Information System Security Engineer, Other , Vancouver, Washington

Click here to apply!

Didn't find what you're looking for? Search again!

I'm looking for
in category
within


Log In or Create An Account

Get the latest Washington jobs by following @recnetWA on Twitter!

Vancouver RSS job feeds