- Company Name
- The Nuclear Company
- Job Title
- Red Team Cybersecurity Engineer
- Job Description
-
**Job title:** Red Team Cybersecurity Engineer
**Role Summary:**
Lead the design, implementation, and continuous improvement of cybersecurity defenses for enterprise IT and operational technology (OT) environments in a regulated nuclear energy context. Serve as a technical authority on risk assessment, incident response, regulatory compliance, and secure architecture for critical infrastructure.
**Expectations:**
- Demonstrate 7+ years of progressive cybersecurity experience, with 3+ years in nuclear or other highly regulated critical infrastructure sectors.
- Apply deep knowledge of NIST CSF, ISO 27001, IEC 62443, NRC, NERC CIP, and related standards to translate regulations into technical controls.
- Own end‑to‑end security lifecycle activities (architecture, risk, vulnerability, incident response, threat intelligence, audit readiness) and mentor junior staff.
**Key Responsibilities:**
- Architect secure network segmentation, access controls, IDS/IPS, SIEM, EDR, and data protection for IT and OT systems (SCADA, DCS, PLCs).
- Conduct comprehensive risk assessments, penetration tests, and vulnerability management for critical assets.
- Develop and maintain incident response plans, threat intelligence frameworks, and proactive defense strategies.
- Lead regulatory audit preparation, documentation, and compliance validation for NRC, NERC CIP, 10 CFR Part 73, NIST CSF, and ISO 27001.
- Evaluate, select, and manage security vendors; ensure solutions meet performance and compliance requirements.
- Mentor and guide cross‑functional teams, promoting best practices and continuous improvement.
**Required Skills:**
- Advanced expertise in secure architecture design, network segmentation, and access control.
- Proficiency with SIEM, EDR, IDS/IPS, firewalls, vulnerability scanners, and penetration testing tools.
- Strong understanding of industrial control system (ICS) security (SCADA, DCS, PLCs) and secure remote access solutions.
- Experience with regulatory frameworks: NIST CSF, ISO 27001, IEC 62443, NRC, NERC CIP, 10 CFR Part 73.
- Ability to translate complex regulatory requirements into actionable technical controls.
- Leadership, communication, and mentorship skills for technical and non‑technical stakeholders.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Cybersecurity, Electrical Engineering, or related field (Master’s preferred).
- Relevant certifications such as CISSP, CISM, CISA, CEH, or equivalent.
- Industry‑specific security certifications (e.g., NIST 800‑53, IEC 62443, or nuclear energy regulatory credentials) are highly desirable.