Cyber Security SME -- Nuclear
8470 River Road SE Southport, NC 28461 US
Job Description
Cyber Security Subject Matter Experts (SMEs). This an engineering position inside the Instrumentation and controls (I&C) design group. This position is a dual role to provide Design and Cyber Security Program compliance support for projects managed in the I&C design department.
This position’s primary role is to provide I&C Design project support. Evaluating technical designs to ensure compliance with Duke Energy’s Cyber Security Program. This requires staying tuned into changing cyder processes and interfacing with site and fleet cyber organizations to ensure project designs stay compliant in a changing environment.
SMEs provide support to Instrumentation and Control Engineering as required and Cyber Security Program support to include Document Preparation, Reviews and hands-on related equipment support as required.
SMEs should have the background and skills necessary to provide implementation support for highly complex digital design activities. Ensuring proper installation, configuration, testing, and cyber compliance.
SMEs should have the background and skills necessary to obtain Duke Energy qualifications as required to allow support of certain network systems, components, and activities. These qualifications will need to be obtained at the discretion of the site/fleet Duke Energy Leadership.
Cyber Security Specialists SMEs require specific expertise in developing and reviewing Cyber Security Plan required documents and support digital projects including:
- Perform Cyber Security Direct and Indirect Assessments for Critical Digital Assets (CDA)
- Develop Access Control Forms
- CDA Walkdown plans and walkdown support
- Duke Energy procedure AD-EG-ALL-1931 Digital Asset (DA)/Critical Digital Asset (CDA) list documentation support
- Equipment Database (EDB) updates for hardware and software tags as required
- CDA capability determination as required
- Project Coordination
- Creating baseline documentation for all CDAs
- Completion of Configuration Control Summary (CCS) sheets which may require executing a Script to capture baseline data, such as running the EZ-Auditor or similar data collection tools.
- Extracting information from baselines, images, Security Information & Event Management (SIEM) or Intrusion Detection System (IDS) reports and plant drawings
- Running a vulnerability scanner against CDAs.
- Taking pictures, documenting physical connections and other CDA physical data.
- Interface with other DPS SMEs will be required.
- Performing Back-ups of CDAs and documenting storage location.
- Documenting security controls mitigated by the implementation of Monitoring Systems and the issuance of Cyber Procedures.
- Assist in scanning/managing Portable Media and Mobile Devices.
- Perform Wireless scans/walkdowns or equivalent process.
- Perform Maintenance, troubleshooting, and patching of systems within the span of control of the Digital Process systems group, including defensive architecture equipment as defined by Duke Energy.
- Performance of Operating Experience (OE) actions to support evaluation and implementation resulting from cyber security inspections and audits.
- Performance of hardening of Windows and Linux workstations and servers.
- Review of industry guidance for cyber security and application of principles to critical systems and critical digital assets.
- Review of cyber security policies, standards, and procedures in support of programmatic requirements to meet the Cyber Security Plan.
- Provide design inputs and SME reviews to Design Engineering for digital cyber attributes of an activity.
- Perform hands-on keyboard activities on site digital equipment in accordance with (IAW) approved site procedures.
- Perform work management administrative activities.
- Perform testing activities on digital equipment IAW approved processes.
In addition to preparing and reviewing the documents, SMEs will obtain Cyber Security Assessment Team (CSAT) approval, provide input to Engineering leadership team to identify and evaluate other tasks where appropriate.
Basic Qualifications:
- • Bachelor’s degree in Electrical Engineering, Computer Engineering, Computer Science, or Information Technology or equivalent work experience
- • 10+ years industry experience
- • Ability to obtain and maintain unescorted access to a nuclear facility (General Employee Training, Radiation Worker Training, Security Clearance checks and subject to the site’s Fitness for Duty Program)
- • Strong oral / written communication skills within a professional environment
- • Skilled in the practices of researching engineering and design issues, evaluating alternatives, making sound recommendations and preparing and presenting recommendations.
- • Must be able to work in a team environment
Share This Job:
Related Jobs:
Login to save this search and get notified of similar positions.About Southport, NC
Although this hasn't been an issue at The Planet Group, the staffing industry has seen an increase in people falsely representing themselves as recruiters to gather personal information from job seekers. For your safety, do not provide sensitive data to anyone you have not spoken with thoroughly and never provide banking information during the application process. Candidate safety is a top priority at The Planet Group.