- Salary
- $91k – $109k
- Location
- Vermont - Hybrid A, United States of America
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Education
- Associate
- Visa
- Not sponsored
- Source
- Workday
Description
As the nation’s first statewide, “transmission only” company, VELCO manages the safe, reliable, cost-effective transmission of electric power throughout Vermont and as a part of the integrated New England regional network.
Why you should join our team
At VELCO, cybersecurity is essential to maintaining a reliable and resilient electric grid. As a Cybersecurity Operations Engineer, you will play a critical role in protecting VELCO’s corporate technology environment from evolving cyber threats while supporting the secure delivery of the technology and services our organization depends on.
If you enjoy solving complex problems, investigating suspicious activity, improving security capabilities, and working with a team committed to protecting critical infrastructure, this is an opportunity to make a meaningful impact.
How you will make an impact
This role combines hands-on security operations, incident response, threat analysis, vulnerability management, security engineering, and regulatory compliance. You will work across endpoints, identities, networks, servers, cloud services, applications, and third-party connections while partnering with Information Security, IT Infrastructure, business teams, Compliance, Legal, Human Resources, and other stakeholders.
You will also contribute to VELCO’s NERC CIP cybersecurity program, including cybersecurity incident response activities under CIP-008, internal network security monitoring under CIP-015, and risk assessment support under CIP-013.
The Cybersecurity Operations Engineer is expected to independently complete assigned operational and compliance-support activities, apply sound judgment during security events, and escalate material risks promptly. The role performs complex security analysis, develops repeatable operational procedures, maintains defensible records, and contributes to continuous improvement of VELCO’s corporate cybersecurity program. The position typically requires progressively responsible experience sufficient to operate with limited oversight while collaborating effectively across technical and business functions.
Responsibilities
- Monitor and triage security alerts from corporate endpoints, identity platforms, networks, servers, cloud services, email, applications, and other enterprise security technologies.
- Investigate suspicious activity, validate the scope and severity of events, document findings, coordinate containment and remediation, and escalate incidents in accordance with VELCO procedures.
- Participate in VELCO’s cybersecurity incident response program and NERC CIP-008 activities, including preparation, testing, event classification support, evidence preservation, response coordination, recovery, lessons learned, and maintenance of incident records.
- Participate in NERC CIP-015 internal network security monitoring activities, including support for monitoring strategy, sensor and data-source coverage, alert review, analysis, escalation, evidence retention, testing, and documented process improvement.
- Administer and improve corporate security operations tools such as security information and event management, endpoint detection and response, email security, vulnerability management, identity protection, network monitoring, and security orchestration technologies.
- Develop and tune detections, dashboards, correlation rules, use cases, playbooks, and response procedures to improve visibility and reduce response time while managing false positives.
- Conduct vulnerability assessment and remediation coordination for corporate systems; validate risk, establish priorities with system owners, track corrective actions, and report unresolved exposure.
- Support identity and access security through review of privileged activity, authentication anomalies, account misuse, access-control exceptions, and other indicators of compromise.
- Analyze threat intelligence and emerging attack techniques for relevance to VELCO, recommend practical defensive actions, and incorporate useful indicators and behaviors into monitoring processes.
- Perform proactive threat hunting and security analysis using available telemetry, baselines, and contextual information to identify malicious or abnormal activity.
- Maintain accurate case notes, operational metrics, evidence, procedures, diagrams, inventories, and other records needed for management reporting, audits, investigations, and regulatory compliance.
- Partner with IT Infrastructure and application owners to securely implement changes, validate logging and monitoring requirements, and resolve security issues affecting corporate services.
- Support security assessments, control testing, audit requests, regulatory reviews, tabletop exercises, and corrective action plans in coordination with VELCO’s Compliance and business teams.
- Provide security guidance and awareness to employees and technical teams, translating technical findings into clear business risk, recommended actions, and status updates.
- Participate in project planning, technology evaluations, vendor security reviews, and implementation activities to ensure security requirements are addressed throughout the solution lifecycle.
- Participate in an on-call rotation and support coordinated response during significant cybersecurity events or operational emergencies.
- Represent VELCO in appropriate industry, regional, and regulatory forums; maintain current knowledge through training, exercises, workshops, and professional development.
- Perform other duties as assigned.
Who you are
Education & Training
Bachelor’s degree in cybersecurity, information technology, computer science, information systems, or a related technical discipline is preferred. An associate degree, recognized technical or military training, or an equivalent combination of relevant education and progressively responsible experience may be considered. At least one current industry-recognized cybersecurity certification aligned with security operations—such as CompTIA Security+, CompTIA CySA+, GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), or an equivalent credential—is preferred; candidates without a certification may be expected to obtain an approved credential within 12 months of hire. The position requires ongoing role-based training in incident response, security monitoring and detection, threat analysis, vulnerability management, cloud and identity security, and applicable VELCO procedures and NERC CIP requirements, including CIP-008 and CIP-015.
Experience
3–7 years of progressively responsible experience in cybersecurity operations, security engineering, incident response, infrastructure security, or a related field. Experience in a regulated environment, electric utility, or critical infrastructure organization is preferred. Practical experience investigating alerts, administering security tools, coordinating remediation, and producing clear operational or compliance evidence is expected.
Knowledge/Skills
- Working knowledge of security operations center practices, incident handling, threat analysis, alert triage, case management, and escalation.
- Experience with SIEM, endpoint detection and response, vulnerability management, email security, identity protection, network security monitoring, and related enterprise security platforms.
- Knowledge of Windows and Linux systems, Microsoft Active Directory and Entra ID, Microsoft 365, virtualization, networking, DNS, DHCP, VPN technologies, cloud services, and common enterprise applications.
- Ability to analyze logs and telemetry from endpoints, identity systems, firewalls, network devices, servers, cloud platforms, and applications to identify suspicious behavior and determine impact.
- Understanding of cybersecurity incident response lifecycles, evidence handling, root-cause analysis, recovery, lessons learned, and the preparation of clear incident documentation.
- Familiarity with internal network security monitoring concepts, detection engineering, traffic and flow analysis, sensor coverage, logging architecture, and escalation procedures.
- Working knowledge of NERC CIP concepts and the ability to support documented controls, evidence, testing, and audit activities, particularly for CIP-008 and CIP-015.
- Familiarity with recognized cybersecurity practices and frameworks such as NIST guidance, CIS Controls, MITRE ATT&CK, vendor security guidance, and risk-based vulnerability management.
- Ability to develop and maintain scripts, queries, automation, playbooks, test plans, and technical procedures that improve security operations while following change-control requirements.
- Strong analytical, troubleshooting, organizational, and project coordination skills, with careful attention to detail and the ability to manage competing priorities.
- Excellent written and verbal communication skills, including the ability to explain technical findings, operational impact, compliance considerations, and recommended actions to technical teams, management, auditors, and business stakeholders.
- Ability to maintain confidentiality, exercise sound judgment, work effectively during high-pressure events, and collaborate professionally across a diverse organization.
Work Environment
- Open office setting and dog friendly
- Opportunity to work closely with engineering, IT, and operations
- Mission-driven organization supporting critical energy infrastructure
- Collaborative, cross-functional team environment
Physical/Mental Demands
Prolonged periods of sitting at a desk and working on a computer are required. The position must be able to perform detailed analytical work, manage multiple priorities, communicate clearly during time-sensitive events, and maintain accuracy in potentially stressful situations with frequent interruptions. Participation in rotating on-call coverage and work outside normal business hours may be required for significant security events, maintenance, exercises, or regulatory activities. Periodic travel and overnight stays may be required for training, workshops, meetings, or industry events.
Compensation Range:
$90,916.80 - $109,100.16 - $127,283.52/salaryThis compensation range represents the minimum, midpoint and maximum pay for this position. Individual offers will be based on various factors including, but not limited to, qualifications, education, skills, competencies, and experience. Please note that most offers for new employees fall under the midpoint of the range, allowing room for continued salary growth. Base pay is just one component of our total compensation package, which may also include comprehensive benefits, generous paid time off and incentive compensation (bonus) potential.
Important Considerations
Visit Velco.com for additional information on VELCO culture, benefits, and the recruiting process.
We are an equal opportunity employer, and ALL qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Eligible applicants must be authorized to work in the United States.
VELCO is handling all aspects of talent acquisition internally and will not engage the services of third-party staffing agencies, recruiters, or headhunters. We kindly request that these entities refrain from contacting us.
Any offer of employment will be contingent upon successful reference check, background check (including social media check), physical examination, drug screening.
If you need an accommodation as part of the application or interview process, please send a request to [email protected]