Staff Network Engineer

Stem IncBroomfield, CO
$111,680 - $167,520Hybrid

About The Position

The Staff Network Engineer is the senior technical authority for the network and OT cybersecurity architecture underlying STEM's PowerTrack platform for grid-connected battery energy storage and solar sites. This role owns the design, evolution, and field implementation of STEM's five-tier Layered Cybersecurity Architecture international standard requirements. The Staff Network Engineer leads high-visibility initiatives, including cybersecurity development efforts, sets technical direction for the broader development, design, and project engineering teams, and represents STEM in customer, vendor, and audit-facing conversations on network security architecture.

Requirements

  • 8+ years of network engineering experience, including experience architecting and securing OT/ICS or industrial control system networks.
  • Deep working knowledge of NERC CIP standards (CIP-002, CIP-004, CIP-005, CIP-007, CIP-009, CIP-010, CIP-015), with hands-on experience supporting compliance audits for Medium and/or High Impact BES Cyber Systems.
  • Expert-level knowledge of IEC 62443 zone/conduit architecture and Security Level target definitions.
  • Working knowledge of ISO/IEC 27001 Annex A controls, particularly those governing monitoring, backup, network segregation, and access/identity management.
  • Hands-on experience configuring and hardening enterprise/industrial firewalls (Palo Alto preferred) and managed switch infrastructure (Moxa or equivalent) for zone segmentation.
  • Experience designing or deploying SIEM platforms (log collection, correlation, alerting, retention) and IDS/INSM solutions in OT/ICS environments, including protocol-aware detection.
  • Experience with jump-server/bastion-mediated remote access architectures, Domain Controller/identity management, patch management (e.g., WSUS), and malware protection at scale.
  • Experience with DMZ architecture design, including single and redundant (dual-DMZ) topologies.
  • Familiarity with Industrial SCADA/EMS platforms; Inductive Automation’s Ignition platform and cloud-based site monitoring platforms are a plus.
  • Experience with SQL databases and time-series/log data stores (e.g., Synology, InfluxDB, or equivalent).
  • Competency in scripting or programming for network automation and tooling (Python, PowerShell, or similar).
  • Experience integrating industrial networking hardware, serial communications, and virtualization technologies.
  • Demonstrated experience leading vendor RFP processes, technical evaluations, and cross-functional stakeholder alignment.
  • Bachelor’s degree in engineering, computer science, network engineering, or a related field, and a minimum of 8 years of relevant experience, or an equivalent combination of education and experience.
  • Demonstrated ability to operate as a senior technical authority with minimal supervision, setting technical direction for a team or program area.
  • Strong written and verbal communication skills; able to translate complex network security and compliance concepts for technical and non-technical audiences, including executives, customers, and auditors.
  • Proven mentorship and technical leadership experience.
  • Ability to manage multiple concurrent, high-visibility initiatives and drive them to completion with minimal oversight.

Nice To Haves

  • Relevant certifications a plus (e.g., CISSP, GICSP, CCNP, PCNSE).

Responsibilities

  • Owns and evolves STEM's Layered Cybersecurity Architecture across the product lines, ensuring segmentation, zone/conduit design, and architecture remain current against ISO/IEC 27001, IEC 62443, and NERC CIP.
  • Leads design, configuration, and troubleshooting of network infrastructure including dual Palo Alto firewall deployments, Moxa managed switch segmentation, and DMZ Server/Jump Host configurations.
  • Directs the technical design and field rollout of the Operational Technology (OT) Server (SIEM and backup-server functions) and Intrusion Detection System (IDS) capabilities in STEM’s architecture, including log correlation/alerting pipelines, Syslog and time-series archiving (Synology NAS), and protocol-aware passive network monitoring across DNP3, Modbus, IEC 61850, IEC 60870, and OPC UA.
  • Serves as senior technical lead on vendor RFPs and evaluations for OT/IT network security capabilities (SIEM, IDS, firewall, DMZ infrastructure), authoring technical scope and requirements, scoring proposals against compliance and architecture criteria, and leading vendor selection and onboarding.
  • Designs and maintains Interactive Remote Access, jump-server-mediated access models, Domain Controller/identity management, patch management (WSUS), and malware protection to satisfy CIP-005 R2 and CIP-007 R2/R3/R5.
  • Leads security event monitoring, Internal Network Security Monitoring (INSM), and backup/recovery architecture to meet CIP-007 R4, CIP-009, and CIP-015 obligations for Medium and High Impact Bulk Electric System (BES) Cyber Systems.
  • Partners with Product, Compliance, and customer-facing teams to translate NERC CIP, IEC 62443, and ISO/IEC 27001 requirements into deployable network architecture, and advises customers and account teams on the appropriate tier for a given site.
  • Provides technical leadership, design review, and mentorship for various team members, including architecture review and onboarding support.
  • Leads root-cause analysis and remediation for complex network security incidents, escalations, and audit findings across the customer fleet, coordinating with Engineering, Field Service, Support, and Security teams.
  • Drives standardization of network architecture patterns, zone/conduit mapping, and compliance cross-reference documentation for reuse across customer engagements, RFPs, and future architecture tiers.
  • Represents STEM’s network security architecture in customer, vendor, and auditor-facing conversations, including NERC CIP audit support as needed.
  • Supports critical-site commissioning and escalations, with occasional travel up to 20% of the time.
  • Other duties as assigned.

Benefits

  • A competitive compensation package, including eligibility for a bonus or commission based on the role.
  • Full health benefits on the first day of employment (several medical plan options-HDHP and PPO, dental plans, FSA/HSA-with employer contribution, employer paid vision/LTD/STD/Life, variety of voluntary coverage)
  • 401k (pre- or post-tax) on first day of employment
  • 12 paid calendar holidays per year
  • Flexible time-off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service