
Senior Control System Cybersecurity Engineer
- Huntsville, AL
- Permanent
- Full-time
- Providing network and system specification documentation deliverables to address cybersecurity vulnerabilities and the security controls necessary to mitigate the vulnerabilities to an acceptable level of risk through application of risk management framework concepts
- Participate in and lead project meetings and provide specification deliverables in coordination with other Dewberry team designers, implementers, architects, and engineers
- Serve as a cross-sector OT cybersecurity resource for Dewberry engineering project teams servicing critical infrastructure; this capability requires expertise in OT design, development, and deployment.
- Comprehensive knowledge of secure control systems design standards to include NIST 800-53, NIST 800-82, ISA-62443, UFC-4-010-06, and others as required by the client
- Lead, with direct contribution to, the creation of winning proposals
- Identify and consult with others on solutions to unusual, difficult, or complex tasks
- Leverage existing customer relationships inside the company to generate warm leads
- Prepare responses to RFIs and RFPs
- Reduce complex aspects of cybersecurity engineering to terms understandable to others
- Prepare fee estimates for cybersecurity design services for internal and external clients
- Lead communications with Government stakeholders and provide advisory support.
- Manage task deliverables, quality, and budgets for multiple ongoing projects
- Prioritize and balance competing project demands and conflicting project requirements
- Mentor junior Cybersecurity Design Engineers in the planning and execution of project tasks and conduct quality management reviews of cybersecurity designs
- Ability to work in teams and establish and maintain cross-functional and working relationships
- Ability to control behavior under situations involving pressure, conflict and uncertainty
- Travel, as needed and approved, to provide technical and analytical support in a designated region or specific installation.
- Bachelor's degree in a technical field related to the following: Computer Engineering, Electrical Engineering, Mechanical Engineering, Cybersecurity, or Information Security System Engineering
- Minimum of ten (10) years of directly related experience in OT cybersecurity solutions design, development, deployment, and commissioning.
- Certification(s): One of the following: Certified Information Systems Security Professional (CISSP), Global Industrial Cyber Security Professional (GICSP), Certified Information Security Manager (CISM)
- Excellent communication skills, both written and verbal to clearly articulate ideas for senior leadership as well as technical staff consumption.
- Extensive experience in reviewing comprehensive facility design plans and specifications related to low voltage facility related control systems, power distribution systems, industrial controls, and network architecture
- Highly motivated self-starter with the ability to work with minimum supervision on medium to large control system centric projects
- Understanding of projects at the conceptual level and development of the corresponding control system cybersecurity engineering scope of work, budget, and schedule
- Proficient with Microsoft Office Suite of tools, including Word, Excel, and PowerPoint.
- Experience working within DoD, U.S. Army Corps of Engineers, Naval Facilities Engineering Systems Command, Air Force Civil Engineer Center, Military Health System, and or Veterans Affairs Healthcare programs a significant plus
- Experience in supporting Military Construction (MILCON) and Facilities Sustainment, Restoration and Modernization (SRM) projects
- Direct hands on experience in the design of control systems and development of project level design specifications using DoD Standards & Criteria specifically, UFC 4-010-06 “Cybersecurity of Facility Related Control Systems” and UFGS 25 05 11 “Cybersecurity for Facility Related Control Systems”
- Comprehensive knowledge of DoD Cybersecurity Assessment & Authorization policies, practices, and toolsets.
- HVAC Control Systems experience to include experience with BACnet and LonWorks protocols
- Multiple control system types (PLC based, DCS, BMS, and SIS)