Nextracker Logo

Nextracker

Engineer III, OT/ICS Cybersecurity & Controls

Posted 6 Days Ago
Remote
Hiring Remotely in US
Senior level
Remote
Hiring Remotely in US
Senior level
Designs and secures OT/ICS networks supporting utility-scale battery energy storage systems. Responsibilities include network segmentation, firewall configuration, Ignition SCADA administration, SIEM deployment, Azure security, identity management, vulnerability assessments, compliance with NERC CIP and IEC 62443, incident response, commissioning support, and technical mentorship. The role advises leadership on OT cybersecurity architecture and supports field operations with up to 20% travel.
The summary above was generated by AI

Job Description:

Engineer III, OT/ICS Cybersecurity & Controls

 

Location: Heathrow, FL / Hybrid / Remote


About Nextpower


The world's demand for electricity is growing faster than ever. Meeting that demand requires infrastructure that's smarter, more reliable, and built to last. The future of energy is not about one advanced technology – it’s about bringing the right solutions together in a unified platform that can deliver reliable power at scale. As a trusted, bankable partner, Nextpower provides integrated technology solutions for utility-scale solar, energy storage, and critical power infrastructure, helping customers design, build, and operate projects with greater speed, reliability, and long-term value. Building on more than a decade of innovation and execution, we're helping power the electrified world. Together, we're powering what's next.


Our Values


Innovation

·         We challenge limits to power what’s next.


Integrity

·         We do the right thing with honesty and respect.


Accountability

·         We own it, we deliver, we rise together.


Collaborative

·         We listen, include, and win as a team.


Customer Focus

·         We earn trust by partnering to solve what matters most.

 

Job Summary


The OT/ICS Cybersecurity & Controls Engineer III reports to the Director, EMS Engineering and Delivery and is responsible for securing, hardening, and maintaining the industrial network and control system environments that support Prevalon Energy's insightOS™ Container Management System (CMS) and utility-scale Battery Energy Storage System (BESS) deployments. As a senior individual contributor, this engineer owns the cybersecurity posture of OT networks in the field and in the cloud - designing and maintaining segmented network architectures, configuring and troubleshooting managed switches and firewalls, deploying and tuning SIEM tooling, and administering the Ignition SCADA/HMI platform - while advising on architecture, risk, and strategy across the fleet. The role partners closely with Controls, Software, and IT leadership to ensure BESS sites meet applicable cybersecurity compliance requirements (e.g., NERC CIP, IEC 62443, NIST 800-82) while supporting commissioning, incident response, and ongoing operations across the fleet.


Essential Duties & Responsibilities


Essential duties and responsibilities include, but are not limited to the following:


  • Design, configure, and maintain OT network architecture for BESS sites, including managed Layer 2/3 switches, VLAN segmentation, subnetting, and routing between control, SCADA, and enterprise zones.
  • undefined
  • Configure, harden, and troubleshoot firewalls (policies, ACLs, NAT, and site-to-site/remote access VPNs) to enforce network segmentation and zero-trust principles across industrial control networks.

  • Administer the Ignition SCADA/HMI platform, including Gateway configuration, tag structures, alarming, security zones/roles, and scripting (Python/Jython) to support monitoring and supervisory control of BESS assets.

  • Deploy, tune, and monitor SIEM platforms (e.g., Splunk, Microsoft Sentinel) to aggregate logs, build detections/dashboards, and identify anomalous activity across OT and IT-adjacent systems.
  • undefined
  • Design and maintain Azure cloud network and security architecture supporting cloud-connected CMS/SCADA applications, including virtual networks, network security groups, Azure Firewall, and Microsoft Defender for Cloud.

  • Administer identity and access management (Azure Entra ID) for OT/ICS system access, including role-based access control, conditional access, and privileged access reviews.
  • Conduct cybersecurity risk assessments, vulnerability scanning, and gap analyses for ICS/OT assets, and drive remediation in accordance with IEC 62443, NERC CIP, and NIST 800-82/800-53 frameworks.
  • undefined
  • Support cybersecurity compliance audits by maintaining system inventories, network diagrams, security control documentation, and evidence of compliance.

  • Develop, maintain, and exercise OT incident response and disaster recovery playbooks/procedures in coordination with IT Security and Operations.

  • Partner with Controls Engineering on secure integration of PLCNext controllers, Modbus TCP/RTU, and OPC-UA communications into the CMS network architecture.

  • Provide onsite and remote support for network and cybersecurity-related troubleshooting during commissioning, ensuring switches, firewalls, and SCADA/Ignition systems are properly configured prior to energization.

  • Maintain awareness of emerging OT/ICS threats, vulnerabilities, and industry best practices, and recommend improvements to the security posture of the fleet.

  • Assist the Operations team in resolving network- and cybersecurity-related issues that arise post-commissioning.

  • Serve as the technical authority on OT/ICS cybersecurity architecture, advising Engineering and Delivery leadership on risk, tradeoffs, and long-term security strategy for the CMS/BESS platform.

  • Establish and evolve team standards, reference architectures, and best practices for network segmentation, firewall policy, SIEM use, and Ignition/SCADA security across the fleet.

  • Mentor junior engineers on OT network and cybersecurity fundamentals and review their designs and configurations for adherence to security and compliance standards.

  • Perform other duties as assigned.

Knowledge, Skills, & Abilities


To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.


Knowledge

  • Working knowledge of industrial network architecture and hands-on configuration/troubleshooting of managed switches, routers, and firewalls (e.g., Cisco, Fortinet, Palo Alto).
  • undefined
  • Mastery of network fundamentals: VLANs, subnetting, routing, NAT, ACLs, and secure remote access (VPN).
  • undefined
  • Required working knowledge of NERC CIP compliance requirements as they apply to BES Cyber Systems, including asset categorization, electronic/physical security perimeters, and access management.
  • undefined
  • Required familiarity with the IEC 62443 series of industrial automation and control systems (IACS) cybersecurity standards, including zone/conduit segmentation, security levels, and lifecycle security requirements.
  • undefined
  • Familiarity with additional ICS/OT cybersecurity frameworks and standards, including NIST 800-82/800-53.
  • undefined
  • Working knowledge of SIEM platforms, log aggregation, and security event correlation/alerting for threat detection.

  • Understanding of SCADA/HMI system architecture, particularly the Ignition platform (Gateway, Designer, tag/alarm structures).

  • Protocol working knowledge in Modbus TCP/RTU, OPC-UA, MQTT-SpB, and/or IEC 61850 is a plus.
  • Working knowledge of Microsoft Azure cloud networking and security services (VNets, NSGs, Azure Firewall, Entra ID, Defender for Cloud).
  • undefined
  • Experience with BESS, Container Management Systems, or other industrial control system environments including their communication network architecture and cybersecurity requirements is a plus.

Skills

  • Hands-on proficiency configuring, troubleshooting, and hardening Layer 2/3 managed network switches and firewalls (policies, routing, VLAN tagging, fiber network technology).
  • undefined
  • Proficient administering the Ignition SCADA/HMI platform, including scripting and security configuration.
  • undefined
  • Proficient with SIEM tooling (e.g., Splunk, Microsoft Sentinel, or similar) for building detections, dashboards, and alerting.
  • undefined
  • Proficient with Microsoft Azure networking and security services; working knowledge of Azure AD/Entra ID administration.
  • undefined
  • Proficient supporting cybersecurity compliance activities, including documentation, evidence gathering, and audit support for frameworks such as IEC 62443 and NERC CIP.

  • Proficient with Modbus and/or OPC-UA industrial protocols.
  • undefined
  • Basic / Foundational experience with Python or PowerShell scripting for automation and log analysis.
  • undefined
  • Basic / Foundational experience with vulnerability scanning and assessment tooling.
  • undefined
  • Proficient in MS Office, Windows RDP, and remote administration tools.
  • undefined
  • Working knowledge of Linux OS, including command-line administration, service/log management, and basic hardening practices is a plus.

Abilities

  • Able to define problems, collect data, establish facts, and draw valid conclusions. Able to interpret an extensive variety of technical instructions and read/understand network, control, and electrical drawings.
  • undefined
  • Communicate effectively with staff and management at all levels, including translating technical cybersecurity risk into business terms.
  • undefined
  • Always maintain the highest degree of honesty and integrity.
  • undefined
  • Lead proactive efforts to achieve departmental and company cybersecurity and compliance goals.
  • undefined
  • Ability to work under pressure and adapt to changing requirements with a positive attitude.
  • undefined
  • Protect confidential information by not communicating, disclosing to, or using it for the benefit of 3rd parties. Protection of the CMS/SCADA platform and its cybersecurity posture is of utmost importance.
  • undefined
  • Comply with all EHS policies, practices, and procedures, reporting all unsafe activities to Management and/or Human Resources.
  • undefined
  • Work in a global environment to maintain standards and latest cybersecurity practices.
  • undefined
  • Ability to work closely with and influence cross-functional teams (Controls, Software, IT, and Operations).
  • undefined
  • Self-directed project management skills to lead security initiatives to completion.

  • Highly competitive, self-starter that can work both individually and in a group setting.
  • undefined
  • Ability to work flexible hours and be independent in the field during commissioning support.

Education & Experience


  • Bachelor's degree in cybersecurity, computer engineering, electrical engineering, computer science, or a related field, with a minimum of five (5) years of related experience in OT/ICS or IT network security.
  • undefined
  • Demonstrated familiarity with and hands-on experience supporting NERC CIP compliance requirements (e.g., asset identification/categorization, electronic and physical security perimeters, access control, and audit evidence/documentation) is required.
  • undefined
  • Hands-on experience configuring and troubleshooting managed network switches and firewalls in a production or industrial environment is required.
  • undefined
  • Experience administering or supporting a SCADA/HMI platform (Ignition preferred) is required.
  • undefined
  • Experience with SIEM deployment, tuning, or monitoring is required.
  • undefined
  • Experience with Microsoft Azure networking, security, and identity services is preferred.
  • undefined
  • Familiarity with IEC 62443 industrial cybersecurity standards is required.
  • undefined
  • Experience supporting cybersecurity compliance programs more broadly (NIST 800-82) is preferred.

  • Relevant certifications a plus: CISSP, GICSP, CCNA/CCNP Security, CompTIA Security+, Microsoft Certified: Azure Security Engineer Associate, or Certified SCADA Security Architect.
  • undefined
  • Experience with inverter-based technology projects, especially involving Battery Energy Storage Systems or PV, is considered an asset.

  • Experience reading and understanding project drawings, network diagrams, and technical documentation.
  • s (e.g., SAP, Oracle) and E Procurement tools (e.g., Coupa, Ariba).

Physical Requirements & Work Environment


The physical demands and work environment characteristics described herein are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.


  • Ability to travel up to 20% of the time, including occasional international travel, to support commissioning and network/cybersecurity configuration of BESS sites.
  • undefined
  • Regularly required to sit and use a computer for extended periods; occasionally required to stand, walk, and move equipment in switchgear/network rooms.
  • undefined
  • Occasionally lift and/or move up to 25 pounds (networking hardware, laptops, test equipment).
  • undefined
  • The noise level in the work environment is usually low to moderate in office settings, and moderate to loud during site visits.
  • undefined
  • Our Lake Mary, FL office is conveniently located near Orlando International Airport (MCO), with a modern floor plan including a Diagnostics Operations Center (DOC) and SCADA provisioning room embedded in the design. This role would be either Remote or Hybrid (2-3 days a week) in the office, depending on the situation.
  • undefined
  • Work Environment Conditions
    • Work is performed in a climate-controlled office environment with standard lighting and noise levels. During occasional site visits, the employee may be exposed to outdoor weather conditions, industrial noise levels requiring hearing protection, and energized electrical equipment requiring appropriate PPE. Site visits may require hands-on network/cybersecurity configuration, installation, or troubleshooting work.
    • undefined
    • PPE Requirements (if applicable)
      • Standard office attire applies for daily work. When visiting operational sites, the employee must wear employer-provided PPE including: hard hat, safety glasses, steel-toed footwear, high-visibility vest, and hearing protection as posted. Arc flash rated PPE is not required as this position does not perform energized electrical work.
      • undefined
      • Travel Requirements (if applicable)
        • Travel up to 20% of the time, including occasional international travel, to support network and cybersecurity configuration during BESS commissioning.
    •   

At Nextpower, we are driving the global energy transition with an integrated clean energy technology platform that combines intelligent structural, electrical, and digital solutions for utility-scale power plants. Our comprehensive portfolio enables faster project delivery, higher performance, and greater reliability, helping our customers capture the full value of solar power. Our talented worldwide teams are redefining how solar power plants are designed, built, and operated every day with smart technology, data-driven insights, and advanced automation. Together, we’re building the foundation for the world’s next generation of clean energy infrastructure.

Nextpower is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

We are Nextpower

Similar Jobs

11 Minutes Ago
Remote or Hybrid
45K-85K Annually
Junior
45K-85K Annually
Junior
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Handles inbound calls and warm leads, consults customers on insurance needs, recommends appropriate property and casualty coverage, and converts prospects into policyholders. The role includes paid licensing and sales training, customer communication, persuasion, lead conversion, and adherence to remote-work and scheduling requirements.
Top Skills: Cable/Fiber/Dsl InternetPcWired High-Speed Internet
An Hour Ago
Remote or Hybrid
88K-118K Annually
Senior level
88K-118K Annually
Senior level
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
The Senior Consultant develops and implements business process and technology solutions for clients, provides training, and manages project risks and deliverables while mentoring junior consultants.
Top Skills: Active DirectoryAzure
An Hour Ago
Remote or Hybrid
United States
88K-132K Annually
Senior level
88K-132K Annually
Senior level
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Leads business and technical requirements analysis, business case development, process improvement, solution design, testing, implementation, and post-deployment optimization for Workday ERP systems. Partners with business leaders, architects, QA, IT, vendors, and project teams to deliver scalable solutions. Facilitates large-group meetings, mentors analysts, assesses system changes, and recommends continuous improvements across Workday modules.
Top Skills: Enterprise Resource Planning (Erp)System Lifecycle ManagementWorkday Adaptive PlanningWorkday ErpWorkday FinancialsWorkday PsaWorkday Time And Expense

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account