> Markdown version of [/jobs/ext/2120105-info-security-engineer-i](https://www.wearedevelopers.com/jobs/ext/2120105-info-security-engineer-i). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Info Security Engineer I - **Company:** Duquesne Light Company - **Location:** Sumter, SC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Monitoring of Systems, Network Security, Network Administration, Security Information and Event Management, Tripwire, Software Vulnerability Management, Computer Networking Systems, Cyber Threat Analysis, Information Technology, Process Control Systems, Operational Systems, CIS Benchmarks, Splunk - **Published:** August 19, 2026 - **Apply:** https://www.juju.com/job/00000000gnu3iv ## About the Role + Bachelor's degree in Information Security, Computer Science, Engineering or a related field, or equivalent professional experience, required. + Seven (7) or more years of experience in cybersecurity engineering, security operations or compliance-focused security roles, required. + Hands-on experience with SIEM technologies, such as Splunk, required. + Experience with configuration monitoring and file integrity monitoring tools, including Tripwire Enterprise or equivalent solutions, required. Preferred Qualifications: + Experience in electric utility, energy, industrial control system or operational technology environments preferred. + Experience supporting or implementing NERC CIP compliance programs preferred. + Experience supporting regulatory audits and compliance evidence management preferred. + Experience managing or supporting infrastructure or network systems, such as server or network administration, preferred. + Industry certification such as CISSP, GCIH, GCIA, Security+, CEH or a Splunk certification preferred. Skills/Abilities: + Knowledge of cybersecurity incident response processes and methodologies. + Understanding of network security, system hardening, vulnerability management and access control principles. + Familiarity with cybersecurity frameworks such as the NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls or IEC 62443. + Experience with endpoint detection and response, vulnerability management and threat intelligence platforms preferred. + Strong analytical, troubleshooting and problem-solving skills. + Ability to interpret technical and regulatory requirements and translate them into practical cybersecurity controls and documentation. + Ability to communicate clearly and effectively, verbally and in writing, with technical and nontechnical stakeholders. + Ability to collaborate across cybersecurity, infrastructure, network, application, operations and compliance teams. + Ability to mentor and support junior cybersecurity personnel through technical guidance and knowledge sharing. ## Description The **Information Security Engineer I** supports and enhances the Company's cybersecurity program, with a strong emphasis on North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) compliance, security information and event management (SIEM), configuration monitoring and incident response. The position safeguards critical infrastructure systems, supports regulatory compliance activities, monitors enterprise and operational technology security controls, and provides technical guidance and knowledge sharing to junior cybersecurity personnel. The role applies hands-on cybersecurity engineering experience across industrial control system (ICS), operational technology (OT) and enterprise environments and works collaboratively with business and technical stakeholders to strengthen cyber resilience., + Conduct risk assessments and gap analyses related to NERC CIP requirements and cybersecurity leading practices. + Administer, monitor and optimize SIEM platforms to support threat detection, alerting, log correlation and incident investigation. + Develop and tune SIEM use cases, correlation rules, dashboards and reporting capabilities. + Provide technical guidance, knowledge sharing and operational support to junior security analysts and engineers. + Collaborate with infrastructure, network, application and operations teams to improve system hardening and secure configuration practices. + Support and maintain compliance with applicable NERC CIP standards across enterprise and operational technology environments. + Participate in NERC CIP audits, assessments, evidence collection, remediation tracking and compliance reporting activities. + Collaborate with internal stakeholders to implement and maintain cybersecurity controls aligned with regulatory and organizational requirements. + Assist in the development, review and maintenance of cybersecurity policies, standards, procedures and technical documentation. + Analyze security events and alerts to identify indicators of compromise, suspicious activity or policy violations. + Integrate log sources from enterprise and OT systems into centralized monitoring platforms. + Manage and support configuration monitoring and file integrity monitoring solutions. + Develop and maintain baselines for critical cyber assets and monitor for unauthorized changes. + Investigate configuration drift, integrity violations and security exceptions. . + Participate in cybersecurity incident response activities, including detection, triage, containment, eradication, recovery and post-incident analysis. + Support incident investigations involving enterprise and OT/ICS environments. + Maintain incident response documentation, playbooks and lessons-learned reports. + Assist in coordinating tabletop exercises and cybersecurity readiness activities. + Participate in cross-functional cybersecurity projects and strategic initiatives. + Participate in an on-call rotation for cybersecurity incidents and operational support. Additional Responsibilities: + Perform other job-related duties as assigned + Storm team duties as assigned ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering)