Job Closed
This listing is no longer active.
TerraForm Power (“TERP”), a platform company of Brookfield Renewable, attracts high-performing individuals who are driven to make an impact in a fast-paced and collaborative environment. We offer unparalleled opportunity to lead and manage one of the largest renewable energy businesses with decades of history, while contributing to the global need for sustainable energy. We offer tremendous growth opportunity for individuals with an entrepreneurial mindset. The company is committed to employee development, encouraging curiosity, ownership, and continuous learning. You’ll be empowered to take initiative, contribute ideas, and grow your career within a supportive and ambitious organization.
Engineer/Senior Engineer, Firewall
Location
United States
Posted
157 days ago
Salary
$120K - $140K / year
Seniority
Senior
Job Description
Engineer/Senior Engineer, Firewall
Brookfield Renewable U.S.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description This is an Operational Technology (OT) role embedded in the TerraForm Power Remote Operations Centre, responsible for designing, implementing, and maintaining secure network perimeters for wind, solar, and battery storage operations with a focus on NERC CIP compliant architecture. The Firewall Engineer will work in close partnership with the TERP Cybersecurity Manager, Compliance and Operations Centre staff to ensure robust, compliant, and resilient OT network security across all sites and control centers. Responsibilities - Architecture, Design & Implementation - Design and implement OT network security controls, such as perimeter firewalls, internal segmentation, site‑to‑site and remote‑access VPNs, and WAFs. - Build secure network solutions that align with system architecture for wind, solar, and BESS facilities, EMS/SCADA, and the system control centers. - Define network security zones and conduits for OT, corporate IT, and cloud environments; enforce least privilege and micro‑segmentation. - Engineer solutions using Cisco (ASA/Firepower/FTD) and Check Point (CCSA/CCSE) platforms; integrate with management consoles and policy orchestration tools. - Implement secure remote access for operators, vendors, and field technicians using MFA, bastion/Jump hosts, and role‑based access. - Operations, Monitoring & Incident Response - Administer firewall policies, objects, NAT, routing (OSPF/BGP), and HA/cluster configurations; manage rule lifecycle and clean‑up. - Maintain WAF protections (e.g., F5, Fortinet, Check Point, or cloud WAF) including rule tuning, bot mitigation, and API security. - Operate and improve monitoring and control tools (SIEM/SOAR, NetFlow, packet capture, IDS/IPS); build dashboards and alerts for NERC systems. - Conduct log analysis, threat hunting, and participate in incident triage and response; provide on‑call support for critical events. - Perform regular firewall health checks, performance tuning, firmware/OS upgrades, and vulnerability remediation. - Support occasional after‑hours maintenance windows on an as needed basis. - Compliance & Change Management (NERC Focus) - Implement and maintain controls aligned to NERC CIP standards applicable to Low Impact sites and Medium Impact control centers (e.g., CIP‑003, CIP‑005, CIP‑007, CIP‑008, CIP‑009, CIP‑010, CIP‑011, CIP‑013). - Serve as the technical owner for firewall‑related CIP controls (for example CIP‑005, CIP‑007, CIP‑010), including configuration baselines, access controls, logging, and evidence collection. - Establish and enforce configuration baselines, access controls, evidence collection, and audit‑ready documentation. - Run structured change management programs for firewall and WAF policies, including risk assessment, testing, approvals, and post‑implementation review. - Support audits, self‑assessments, and impact ratings; assist with personnel risk assessment and vendor risk management where applicable. - Collaborate with OT, IT, Compliance, Engineering, and Plant Operations to ensure controls meet operational needs without compromising reliability. - Collaborative Responsibilities - Work in close partnership with the TERP Cybersecurity Manager to align firewall, VPN, and WAF controls with OT/IT cybersecurity strategy, incident response protocols, and compliance requirements. - Participate in joint incident response, risk assessments, and continuous improvement initiatives with the Cybersecurity Manager and Operations Centre leadership. - Coordinate with Operations Centre, plant operators, and engineering teams to ensure security controls support operational reliability and compliance. - Technology Evaluation & Continuous Improvement - Evaluate new firewall, WAF, VPN, and OT security technologies; lead POCs and make data‑driven recommendations. - Identify opportunities to enhance resilience (segmentation, Zero Trust, SD‑WAN security, secure cloud connectivity), and automate repeatable tasks (e.g., policy linting, backup/restore, compliance evidence collection). - OT-Specific Duties - Manage vendor and contractor access for maintenance and commissioning, ensuring robust controls for temporary access and logging. - Design solutions that address site-specific challenges, including limited bandwidth, remote access constraints, and environmental factors. - Support operational resilience by coordinating change windows with grid operations and implementing failsafe configurations to avoid plant outages. Qualifications - Engineer - 5+ years of hands‑on experience administering enterprise firewalls and VPNs (Cisco ASA/Firepower/FTD; Check Point). - Working knowledge of WAF technologies and web security (OWASP Top 10, TLS, mTLS, API security). - Strong command of TCP/IP, routing (OSPF/BGP), NAT, ACLs, IPS/IDS, and packet analysis. - Experience with SIEM/log management (e.g., Splunk, QRadar, LogRhythm), network monitoring (e.g., SolarWinds), and configuration management. - Familiarity with NERC CIP concepts and control implementations for Low and/or Medium Impact environments, or equivalent experience in other regulated OT/ICS environments (for example IEC 62443). - Solid documentation skills and experience operating within formal change management processes. - Clear communicator able to translate complex security topics for plant operations, engineering, compliance, and leadership. - Strong prioritization and execution in high‑availability environments; calm under pressure during incidents. - Collaborative and customer‑focused; builds trusted relationships with site personnel and external partners. - Senior Engineer - All above, plus; - 10+ years in network security with deep expertise in Cisco and Check Point ecosystems, including clustering/HA, threat defense, and advanced policy design. - Proven leadership of firewall/WAF architecture in OT/ICS or critical infrastructure (utilities, energy, industrial). - Demonstrated experience interpreting and implementing NERC CIP requirements in Medium Impact control centers, including evidence management and audit support. - Proficiency guiding incident response and problem management for high-availability environments; ability to mentor engineers and lead complex changes. - Track record of evaluating, selecting, and integrating new technologies; experience with automation (e.g., Ansible, Python) and policy compliance tooling. Education & Certifications - Bachelor’s degree in Computer Science, Electrical/Computer Engineering, Information Security, or related field; or equivalent experience. - Relevant certifications preferred: - Cisco: CCNP Security, CCIE (Security) (plus) - Check Point: CCSA/CCSE - Others, a plus Industry‑Specific (Renewable Energy & OT/ICS) Requirements - Experience with the secure transport of SCADA/EMS, plant DCS/RTUs/PLCs, and OT protocols (OPC, DNP3, Modbus). - Understanding of interconnections between substations, collector systems, BESS EMS, and corporate networks; secure data flows to forecasting, trading, and asset performance platforms. - Knowledge of telecom links common in renewables (leased lines, microwave, LTE/private cellular) and secure backhaul to control centers. - Awareness of site conditions (limited bandwidth, remote access constraints, environmental factors) and designing resilient, maintainable solutions. - Vendor and contractor access management for maintenance, OEM support, and commissioning activities, with strong control over temporary access and logging. - Safety and reliability mindset: change windows coordinated with grid operations, rollback plans, and fail‑safe configurations to avoid plant outages. Compensation $120,000-$140,000 USD, bonus eligible
Job Requirements
- Engineer 5+ years of hands‑on experience administering enterprise firewalls and VPNs (Cisco ASA/Firepower/FTD; Check Point). Working knowledge of WAF technologies and web security (OWASP Top 10, TLS, mTLS, API security). Strong command of TCP/IP, routing (OSPF/BGP), NAT, ACLs, IPS/IDS, and packet analysis. Experience with SIEM/log management (e.g., Splunk, QRadar, LogRhythm), network monitoring (e.g., SolarWinds), and configuration management. Familiarity with NERC CIP concepts and control implementations for Low and/or Medium Impact environments, or equivalent experience in other regulated OT/ICS environments (for example IEC 62443). Solid documentation skills and experience operating within formal change management processes. Clear communicator able to translate complex security topics for plant operations, engineering, compliance, and leadership. Strong prioritization and execution in high‑availability environments; calm under pressure during incidents. Collaborative and customer‑focused; builds trusted relationships with site personnel and external partners.
- 5+ years of hands‑on experience administering enterprise firewalls and VPNs (Cisco ASA/Firepower/FTD; Check Point).
- Working knowledge of WAF technologies and web security (OWASP Top 10, TLS, mTLS, API security).
- Strong command of TCP/IP, routing (OSPF/BGP), NAT, ACLs, IPS/IDS, and packet analysis.
- Experience with SIEM/log management (e.g., Splunk, QRadar, LogRhythm), network monitoring (e.g., SolarWinds), and configuration management.
- Familiarity with NERC CIP concepts and control implementations for Low and/or Medium Impact environments, or equivalent experience in other regulated OT/ICS environments (for example IEC 62443).
- Solid documentation skills and experience operating within formal change management processes.
- Clear communicator able to translate complex security topics for plant operations, engineering, compliance, and leadership.
- Strong prioritization and execution in high‑availability environments; calm under pressure during incidents.
- Collaborative and customer‑focused; builds trusted relationships with site personnel and external partners.
- Senior Engineer All above, plus; 10+ years in network security with deep expertise in Cisco and Check Point ecosystems, including clustering/HA, threat defense, and advanced policy design. Proven leadership of firewall/WAF architecture in OT/ICS or critical infrastructure (utilities, energy, industrial). Demonstrated experience interpreting and implementing NERC CIP requirements in Medium Impact control centers, including evidence management and audit support. Proficiency guiding incident response and problem management for high-availability environments; ability to mentor engineers and lead complex changes. Track record of evaluating, selecting, and integrating new technologies; experience with automation (e.g., Ansible, Python) and policy compliance tooling.
- All above, plus;
- 10+ years in network security with deep expertise in Cisco and Check Point ecosystems, including clustering/HA, threat defense, and advanced policy design.
- Proven leadership of firewall/WAF architecture in OT/ICS or critical infrastructure (utilities, energy, industrial).
- Demonstrated experience interpreting and implementing NERC CIP requirements in Medium Impact control centers, including evidence management and audit support.
- Proficiency guiding incident response and problem management for high-availability environments; ability to mentor engineers and lead complex changes.
- Track record of evaluating, selecting, and integrating new technologies; experience with automation (e.g., Ansible, Python) and policy compliance tooling.
- Education & Certifications
- Bachelor’s degree in Computer Science, Electrical/Computer Engineering, Information Security, or related field; or equivalent experience.
- Relevant certifications preferred: Cisco: CCNP Security, CCIE (Security) (plus) Check Point: CCSA/CCSE Others, a plus
- Cisco: CCNP Security, CCIE (Security) (plus)
- Check Point: CCSA/CCSE
- Others, a plus
- Industry‑Specific (Renewable Energy & OT/ICS) Requirements
- Experience with the secure transport of SCADA/EMS, plant DCS/RTUs/PLCs, and OT protocols (OPC, DNP3, Modbus).
- Understanding of interconnections between substations, collector systems, BESS EMS, and corporate networks; secure data flows to forecasting, trading, and asset performance platforms.
- Knowledge of telecom links common in renewables (leased lines, microwave, LTE/private cellular) and secure backhaul to control centers.
- Awareness of site conditions (limited bandwidth, remote access constraints, environmental factors) and designing resilient, maintainable solutions.
- Vendor and contractor access management for maintenance, OEM support, and commissioning activities, with strong control over temporary access and logging.
- Safety and reliability mindset: change windows coordinated with grid operations, rollback plans, and fail‑safe configurations to avoid plant outages.
- Compensation
- $120,000-$140,000 USD, bonus eligible
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Engineer – Europe
TempoWith over 30,000 customers, including a third of Fortune 500 companies, Tempo is trusted by organizations across the globe to make their workflows work better. We create a suite of integrated solutions for time management, resource planning, budget management, roadmapping, program management, reporting and more. Since our beginning in 2007 as a project to make a time-tracking tool to help a client – Tempo has expanded to become the #1 time management add-on for Jira, and we have developed and acquired a multitude of tools to become one of the most trusted names in the Atlassian ecosystem. We want everyone to work better - but we also want to be a tech company with a heart. Join us as we continuously innovate our award-winning products, create new solutions, and help the world work smarter, not harder.
• Proactively hunt for vulnerabilities in the Tempo protocol, consensus engine, and bridge architecture, treating our mainnet like a continuous CTF challenge. • Design and implement security tooling and automation in liaison with the Foundry team to catch logic errors and edge cases. • Partner with engineering teams to review critical architecture across our codebase. • Analyze incentives and game-theoretic risks within the protocol, such as MEV and staking dynamics, to prevent economic exploits.
Security Engineer
TempoWith over 30,000 customers, including a third of Fortune 500 companies, Tempo is trusted by organizations across the globe to make their workflows work better. We create a suite of integrated solutions for time management, resource planning, budget management, roadmapping, program management, reporting and more. Since our beginning in 2007 as a project to make a time-tracking tool to help a client – Tempo has expanded to become the #1 time management add-on for Jira, and we have developed and acquired a multitude of tools to become one of the most trusted names in the Atlassian ecosystem. We want everyone to work better - but we also want to be a tech company with a heart. Join us as we continuously innovate our award-winning products, create new solutions, and help the world work smarter, not harder.
• Proactively hunt for vulnerabilities in the Tempo protocol, consensus engine, and bridge architecture, treating our mainnet like a continuous CTF challenge. • Design and implement security tooling and automation in liaison with the Foundry team to catch logic errors and edge cases. • Partner with engineering teams to review critical architecture across our codebase. • Analyze incentives and game-theoretic risks within the protocol, such as MEV and staking dynamics, to prevent economic exploits.
Head of Product – Cybersecurity SaaS, GovCon, Compliance
UrrlyEmpowering People and Property Management companies with future proof staffing solutions.
• Own product vision, roadmap, and delivery for a high-growth SaaS platform • Translate complex compliance requirements into intuitive customer workflows • Prioritize ruthlessly; say no to protect speed and quality • Partner with the CTO on scope, sequencing, and trade-offs • Improve UX, onboarding, and core workflows to reduce friction • Engage directly with customers to validate problems and solutions • Identify automation and AI opportunities that create real leverage
Product Manager, Cyber Security Engineering
Live Nation EntertainmentA Fortune 500 company lauded for innovative business practices by Fast Company magazine, Live Nation Entertainment is a global leader in live entertainment and
• Working with internal business experts, internal / external consultants, and owners of products throughout the Live Nation ecosystem to define and prioritize implementation of a world class information security product portfolio. • Day-to-day management of the product portfolio and triage of any issues or concerns of the system that are impacted by the implementation. • Become a point person within Live Nation for tooling implementation-related questions, specifically around how systems work and future enhancements. • Working with engineering, software, business leads and QA organizations in the development and deployment of compliant products and features. • Identifying interdependencies between core systems and other products to ensure regulatory compliance. • Documenting use cases, updating epics and user stories, prioritizing and maintaining product backlogs, and guiding development through the dev cycle for feature stories


