Location: Hybrid (2-3 days onsite) – Allentown, PA, with travel to generation sites and control rooms as required (up to 20%)
About the Role
We are seeking an experienced IT Systems & Compliance Analyst to support the secure, compliant, and reliable operation of IT and OT systems within critical energy and industrial infrastructure. This role bridges IT and OT domains, providing cybersecurity, network, and compliance expertise across operational technology environments. You will help deploy security tools, improve network segmentation, enhance threat detection, and ensure adherence to NERC CIP and industry cybersecurity standards such as NIST SP 800-82 and IEC 62443.
Key Responsibilities
Participate in a 24/7 on-call rotation, supporting operational control and visibility of the Bulk Electric System.
Ensure NERC CIP compliance and contribute to security and operational objectives.
Configure, update, and maintain network devices including switches, firewalls, IDS, and associated systems.
Support IT/OT development projects, integrating security into infrastructure and processes.
Troubleshoot and resolve network security issues efficiently.
Analyze network logs and events to detect and respond to security incidents proactively and reactively.
Coordinate with cross-functional teams to support the Bulk Electric System and related operations.
Communicate complex technical concepts to technical and non-technical stakeholders.
Architecture, Assessment & Continuous Improvement
Design and validate cybersecurity architectures spanning IT and OT environments.
Plan, coordinate, and execute OT cybersecurity assessments in collaboration with internal teams, third parties, and site engineers.
Conduct tabletop exercises, incident simulations, and post-event reviews to validate operational readiness.
Support incident response efforts including root cause analysis, containment, and corrective actions.
Qualifications & Experience
Bachelor’s degree in IT, Computer Science, Cybersecurity, Industrial Automation, or related field; or equivalent experience.
7+ years of combined IT/OT experience, including 2+ years in industrial cybersecurity or compliance-driven environments (e.g., SCADA, PLCs, DCS, plant operations).
Strong understanding of NERC CIP compliance and industrial cybersecurity frameworks (NIST SP 800-82, IEC 62443).
Hands-on experience with OT infrastructure and cybersecurity controls, including:
Servers (Windows/Linux), virtualization (VMware/Proxmox), backup (Commvault/Veeam)
Network segmentation, firewalls (Fortinet, Palo Alto), industrial DMZ design
Endpoint protection/EDR platforms (CrowdStrike, Microsoft Defender)
Asset inventory and monitoring tools (Industrial Defender, Nozomi, Claroty, Dragos)
Identity and access management (Active Directory, Okta, Azure AD), vulnerability scanning, and service management (ServiceNow)
Physical security systems (CCURE, camera systems, sensors) and compliance documentation
Preferred Qualifications
Professional certifications such as CISSP, CISM, GCIP, GICSP, or equivalent.
Experience supporting or leading NERC CIP audits or evidence collection processes.
Hands-on experience with firewall rule analysis, network hosting, and OT risk assessment.
Background in utilities, energy, or manufacturing industries.
Skills & Attributes
Strong ownership and accountability – drives initiatives from concept to completion.
Collaborative communicator who aligns IT, OT, and business functions.
Applies common sense and sound judgment in complex or ambiguous situations.
Comfortable working with legacy systems and constrained resources.
Balances security imperatives with operational continuity.
Why Join Us?
Contribute to critical infrastructure operations and help protect vital energy systems.
Work in a collaborative, inclusive, and innovative environment with opportunities for professional growth.
Competitive benefits package including health, dental, vision, life and disability insurance, 401(k) plan, and generous vacation/sick leave.
Working Conditions
Hybrid work arrangement (2-3 days onsite).
Travel to generation sites and control rooms as required (up to 20%).
Participation in on-call rotations or incident response activities.
