Job Details
Qualifications
- Bachelor's degree
- CCNP
- CCSP
- Distributed control systems
- ISO 27001
- Network protocols
Job Description
Position Purpose
**Candidates that do not meet all years of required experience are encouraged to apply, including experience directly related to OT Cyber Security.
The City of Arvada promotes Equal Pay for Equal Work. Starting salary will be determined by the applicant's education, experience, knowledge, skills and abilities, as well as internal equity. The range listed reflects the entire range and typical placement is entry to mid range ($93,547-$110,033).
Evaluates and secures operational technology system assets by identifying and solving potential and actual security issues. Administers and maintains existing security technology and coordinates these efforts with other departments within the City and outside agencies. Analyzes new security technologies and the potential for utilization by the city. Documents and supports the development of security policies as they relate to OT/ICS. Implements proper security to meet regulatory security requirements.
Job Functions / Scope of Authority
ESSENTIAL JOB FUNCTIONS
Develop cybersecurity technology implementation strategies for OT environments with clear understanding of the differences between IT and OT.
Develop OT cybersecurity reference architectures, standards, and guidelines for ICS systems and networks.
Understanding of ICS design considerations with emphasis on human safety and the availability/security of the operating environment.
Responsible for developing and implementing security strategies and processes for OT environments.
Will create and support the management, deployment, and upkeep of security controls for ICS systems.
Utilize knowledge of ICS technologies to install, monitor, and maintain security controls and firewalls.
Align OT standards, frameworks, and security with overall business and technology strategy.
Develop security operations procedures and protocols that will provide appropriate situational awareness and clear remedial action plans.
Apply knowledge of industrial control systems and cybersecurity to help develop secure network architecture designs, identify exploitable vulnerabilities that could impact operations, evaluate and maintain systems for cyber risks and remediation activities, and design and implement OT cybersecurity monitoring solutions.
Conduct activities, including implementing cybersecurity solutions or performing security assessment activities, such as physical security walk-downs, observations, technical configuration reviews, and conducting personnel interviews.
Conducts network monitoring and intrusion detection analysis using various computer network defense tools, such as intrusion detection/prevention systems, firewalls and host-based security systems
Conducts log-based and endpoint-based threat detection to detect and protect against threats coming from multiple sources
Supports the creation of business continuity/disaster recovery plans, including conducting disaster recovery tests, publishing test results and making changes necessary to address deficiencies
Researches emerging threats and vulnerabilities to aid in the identification of incidents
Communicates information security risks and issues to managers and others.
Performs basic risk assessments for OT/ICS systems. Assist in complying with EPA’s AWIA (American Water Infrastructure Act) requirements.
Contributes to vulnerability assessments. Assist in complying with EPA’s AWIA (American Water Infrastructure Act) requirements.
Applies and maintains specific security controls as required by organizational policy, local risk assessments and Industry/AWWA standards.
Investigates suspected attacks.
Responds to security breaches in line with security policy and records the incidents and action is taken.
Works closely with Water Treatment Manager, Plant Supervisor-SCADA, IT CISO and security staff to develop seamless security solutions.
Investigates and analyzes software/firmware updates and patches for impacts on OT/ICS system and performs updates when vetted out. Maintain active equipment/hardware inventory.
Correlates network and endpoint activity across environments to identify attacks and unauthorized use
Assists in determining proper access rights and privileges to OT systems
Provides users with incident response support, including mitigating actions to contain activity and facilitating forensics analysis when necessary
Proactively ensures security is appropriately addressed
Contributes to the security culture of the organization
ESSENTIAL KNOWLEDGE, SKILLS, AND ABILITIES
Strong written and communication skills with the ability to effectively communicate and interact with all levels of personnel within the City and outside agencies and partners in a positive, cooperative and effective manner.
Strong knowledge of firewall configurations.
Strong Knowledge of intrusion prevention/detection systems.
Strong understanding of cybersecurity frameworks for ICS/OT environments (ISA-99/IEC 62443, NIST SP 800-82, CIS, etc.)
Strong understanding of OT network communication protocols (e.g., Ethernet/IP, CIP, Modbus, OPC, Profibus,etc.) and industrial networking topologies (e.g., ring, star, etc.)
Advanced knowledge of network protocols, routers, switches, wireless Access Points
Demonstrated technical skills to analyze, design, and deploy complex Ethernet/IP architectures and communication technologies, including fiber optic, copper, Cellular, Microwave/Radio communications systems
Certified SCADA Security Architect (CSSA)
GIAC certifications (e.g., GICSP, GRID, Critical Infrastructure Protection)
ISA/IEC 62443 Cybersecurity Certificates
Networking certifications (e.g., CCNA, CCNP, JNCIP-ENT, etc.)
Cybersecurity certification (e.g., CEH, CISA, CISM, CCSP, etc.)
Understanding of MITRE ATT&CKS for ICS or NERC CIP frameworks
Understanding of general cybersecurity frameworks (ISO IEC 27001/27002, ISO 15408, NIST Cybersecurity Framework (CSF), NIST SP800-53)
A strong working knowledge of industrial control systems (e.g., DCS, PLCs, SCADA, etc.)
Ability to perform vulnerability / penetration testing in ICS/OT environment, and/or threat hunting
Advanced knowledge of PII security requirements
Ability to prioritize daily work tasks.
Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one
An ability to effectively influence others to modify their opinions, plans or behaviors
An understanding of organizational mission, values, goals and consistent application of this knowledge
Strong problem-solving and troubleshooting skills
Maintains technical knowledge by attending educational workshops; reviewing publications.
OTHER FUNCTIONS:
Assists with and is required to be available for after hours support.
Other duties as required.
—Employees are held accountable for all duties of this job—
SCOPE OF AUTHORITY:
Receives minimal supervision under the direction of the Water Treatment Manager. Plans daily work activities
and prioritize tasks. Expected to handle different and specialized situations in the department or functional area.
Financial Accountability:
Makes recommendations to supervisor for budget allocations pertaining to the department. Recommends purchase of equipment, software and consulting services.
Working Environment / Qualifications
WORKING ENVIRONMENT/PHYSICAL ACTIVITIES:
The work environment/physical activities described here are representative of those an employee encounters while performing the essential functions of the job.
Work is primarily performed in an office and field environment with low to moderate noise levels . Physical effort and activities include: Moderate physical activity required by handling objects up to 50 pounds occasionally and/or up to 20 pounds frequently.
MINIMUM REQUIRED QUALIFICATIONS (EDUCATION, LICENSE, TRAINING AND EXPERIENCE):
Requires Bachelor’s Degree in Computer Science or related studies and four (4) years’ experience in OT cybersecurity, OT operating environments, or a related field. A minimum of three (3) years “hands on” experience assessing, designing, and implementing ICS/OT network architectures
Preferred Qualifications:
CISSP, CISA, SANS GIAC certifications.
Vision Mission Values
The City is an Equal Employment Opportunity
The City’s Core values are in every employee’s individual Performance Plan which helps us to reinforce our expectations for living and working by our Core Values.
Every City employee is expected to perform his/her job to the highest professional standards. This includes upholding the City’s values with integrity and accountability, acting in a manner that is respectful and inclusive towards others, and adhering to the City’s policy on employee conduct as detailed in the personnel rules sec. 70-143.
Vision: We Dream Big and Deliver
Mission: We are dedicated to delivering superior services to enhance the lives of everyone in our community.
Values:
Innovation: We excel in creativity, flexibility and the use of best practices while valuing diverse backgrounds, ideas and perspectives.
Passion: We are a high performing, inclusive team inspiring each other to pursue excellence.
Opportunity: We value our diversity, embrace possibilities, face challenges, persevere and take action to deliver quality results.
Full Time Employee BenefitsAll new employees hired after January 1, 2023 will receive a bank of 40 hours of New Hire Leave that can be used at any time. Part time benefited hires will receive a prorated amount based on the number of hours worked. The City of Arvada offers employees an excellent benefit packageThe City of Arvada values the contributions each employee makes every day toward the success of the organization and community. The importance of being able to provide our employees and their families with quality benefits as part of their overall compensation package is a high priority. As a result, the City has developed a comprehensive benefits package that delivers quality and value while satisfying the diverse needs of our workforce. EligibilityTo be eligible, full-time and part-time employees who work a minimum of 30 hours per week are eligible for benefits for themselves, their spouse, their same-sex partner, and their dependent children. New hires are eligible for insurance the first day of the month following one full calendar month of employment following their hire date. The City of Arvada offers employees a competitive pay planThe City of Arvada Pay Plan reflects the City's Total Compensation Philosophy. This philosophy includes being an employer of choice in the Denver/Boulder region by attracting and retaining highly talented and engaged employees. Developed in partnership with the members of City Council, this philosophy serves to guide staff in the management of the City's compensation practices. It ensures that the pay plan is updated with competitive market-based salaries, and managed in a manner that is fiscally responsible and within the City's ability to fund. The Pay Plan can be found here. (Download PDF reader)Benefits SummaryThe City of Arvada Pay Plan is specifically designed to help you further understand the highlights of the benefit options offered. That information can be found here (Download PDF reader). Additionally, the City offers a bank of 40 hours of New Hire Leave for full time employees hired after January 1, 2023. For more information about employee benefits, please visit http://arvada.org/about/jobs/city-benefits.