Westinghouse Electric Company-posted 9 months ago
Full-time • Manager
Warrendale, PA
Computer and Electronic Product Manufacturing

This Supervisor Engineer will be responsible to leadership and collaborate with the customer and Westinghouse stakeholders to define and convey the engineering process requirements for implementing upgrade projects. In addition, the Lead Engineer will participate in process development, change management, and management of a small team (3-5 people) to ensure that customer requirements are defined and satisfied.

  • Enforce company policies and practices to ensure that all products and systems are compliant with cybersecurity standards.
  • Collaborate with the Information Technology department to manage and enhance the secure development functions.
  • Provide input for security risk assessments and compliance audits, identifying potential information and network security vulnerabilities.
  • Manage the detection, response, mitigation, and reporting of incidents within the environment.
  • Participate in the IT vulnerability management program by classifying vulnerabilities, providing remediation guidance, and working with the team to prioritize and address vulnerabilities.
  • Ensure compliance with relevant cybersecurity compliance regulations.
  • Document standard operating procedures and guidelines.
  • Investigate and recommend security technologies and solutions to support secure development functions.
  • Provide technical guidance and consultation related to information security issues.
  • Actively participate in security processes and procedures, ensuring their effectiveness and efficiency.
  • Be an active member of secure development meetings, providing updates, insights, and participating in the decision-making process.
  • Interface with system end users and customers as required to support meeting project technical objectives.
  • Provide cost and schedule estimates as required.
  • Travel up to 50%, typically when deploying systems to the field for installation and commissioning.
  • Bachelor's degree in a relevant field or equivalent experience, coupled with high proficiency operating in Enterprise OT Security.
  • Proven experience in cybersecurity operations, risk assessment, and incident management, along with demonstrated supervisory experience.
  • Strong knowledge of cybersecurity best practices, compliance regulations, and industry standards.
  • Hands-on experience with security tools and technologies.
  • Excellent communication and teamwork skills.
  • Minimum 5+ Years of managerial experience in Operational Technology / Information Technology with 5+ Years experience leading a large-scale cyber security program.
  • Ability to be granted 10 CFR 73.56 Trustworthy and Reliability Clearance for US Nuclear Plant Entry.
  • Experience with interpreting Security Control & Program Frameworks such as NIST 800-53, NIST 800-82r2, 20 Critical controls, ISO 27001 & 27002, NEI-08-09, NEI 13-10 into Cybersecurity Program, Policy & Procedures.
  • Strong risk analysis, risk management and proven experience in reducing risk to the organization.
  • At least 10 years of commercial nuclear industry experience is preferred or industry experience in a highly regulated industry with increasing levels of responsibility.
  • Experience leading and directing medium to high complexity projects to successful completion.
  • Advanced people skills such as effective verbal and written communications, ability to lead and direct complex team structures.
  • Familiar with the AP1000 project, processes, and procedures.
  • Network Device Configuration Knowledge / Experience.
  • Experience with virtualization technologies (VMware).
  • Knowledge and experience in I&C systems, specifically in system administration, cyber security, and process control systems.
  • Experience with developing engineering deliverables.
  • Demonstrated ability to solve complex problems.
  • Relevant certifications (e.g., CISSP, CISM, CompTIA Security+) are a plus.
  • Knowledge and experience in Ovation (Emerson) Platform are preferred but not required.
  • At least one of the following certifications is preferred but not required: GIAC Security Essentials Certification (GSEC) or equivalent, Security+ Certification, Network+ Certification.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service