
Principal Cybersecurity Engineer (m/w/d)
Plus Power
公司概况
Plus Power
美国加利福尼亚州旧金山
2018年
商业模式
可再生能源
Plus Power专注于开发和运营大型电池储能系统,以支持可再生能源的整合和电网的稳定性。他们的项目旨在提高电力系统的灵活性和可靠性。
Plus Power的收入主要来自于电池储能项目的开发和运营,以及与电力公司和政府机构的合作。
地点与地理
Plus Power在美国多个州开展业务,主要集中在加利福尼亚州、德克萨斯州、纽约州和佛罗里达州。他们的总部位于旧金山,致力于推动可再生能源的应用。
公司文化
Plus Power的使命是通过创新的电池储能解决方案,推动可再生能源的普及和使用。他们重视可持续发展和环境保护,致力于为未来创造一个更清洁的能源系统。
Plus Power提供一个开放和协作的工作环境,鼓励员工分享创意和创新思维。他们重视团队合作,致力于创造一个包容和多样化的工作氛围。
Plus Power为员工提供多种职业发展机会,包括培训和继续教育项目,以帮助员工提升技能和职业发展。他们鼓励员工参与行业会议和研讨会,以保持对最新技术和趋势的了解。
活动与项目
Plus Power目前正在多个电池储能项目上进行开发,其中包括在加利福尼亚州和德克萨斯州的多个大型储能设施。这些项目旨在支持当地电网的稳定性和可再生能源的整合。
Plus Power致力于开发先进的电池技术,以提高储能系统的效率和经济性。他们与多家技术公司合作,推动电池技术的创新和应用。
Plus Power在其运营中实施可持续实践,致力于减少碳足迹和环境影响。他们的项目设计考虑了环境保护和资源的可持续利用。
职业机会
Plus Power通常招聘电气工程师、项目经理和市场开发专员等职位。他们寻找具有创新思维和团队合作精神的人才,以支持公司的发展。
Plus Power为员工提供竞争力的薪酬和福利,包括健康保险、退休计划和灵活的工作时间。他们还提供职业发展支持和培训机会,以帮助员工实现职业目标。
联系信息
最后更新于 2025-03-27 | 报告问题
Plus Power is an energy storage market leader, with a market-leading 10+ GW portfolio across more than 25 US states and Canadian provinces that will transform North American electric grids into cleaner and more versatile critical infrastructure.
Standalone energy storage is rapidly transforming the North American energy markets, because it is cheaper than new natural gas plants, faster to build than fossil peakers or transmission, and able to perform diverse energy services. Plus Power partners with electricity system operators, utilities, and investors to originate, develop, finance, own and operate standalone energy storage projects that provide critical services to the wholesale electric market. Plus Power’s team applies an intentional mindset to energy storage development by using a data-driven approach to development and operations.
At Plus Power, we are focused on solving hard climate problems, profitably. We are growing fast, and value candidates who, like us, share a focus on setting high expectations, owning and learning from mistakes in the spirit of radical transparency, and are committed to internal partnering as a key element of our ideas meritocracy. Our team praises Plus Power’s culture and excels through our game-changing mission and supportive ecosystem.
About the Role
Plus Power recruits outstanding energy industry professionals who are driven to develop, build and operate assets safely and reliably to decarbonize the power markets while growing their careers. Our team looks for data-driven and fact-based mindsets, engaging and collaborative behaviors, and personal growth-focused professionals.
In order for the global energy system to make the transition from a carbon-based grid, to a renewable energy grid, large scale energy storage must be introduced into the electricity system to balance intra-hour supply and demand. Energy storage is the enabler of high penetration variable renewable generation like solar and wind.
We are currently seeking a Principal Cybersecurity Engineer who will lead and execute on key cybersecurity activities and protections at the company. The ideal candidate has deep expertise and understanding of cybersecurity principles and frameworks, and has built or managed InfoSec, AppSec, SecOps, identity and access management, and data privacy programs. Reporting to the Manager of Information Technology, you will work cross functionally with our IT, Data Engineering, Data Science, Operational Technology, Asset Management, Engineering Procurement and Construction, Legal, External Relations, and HR teams to create strategies, policies, and manage cybersecurity controls and testing associated with our project needs and corporate needs.
Responsibilities
- Work day-to-day with a broad set of stakeholders and contributors to drive Plus Power’s cybersecurity program and activities aligning with the company’s compliance and security postures
- Promote secure by design and secure by default strategies
- Baseline, monitor, identify, and assess security vulnerabilities and risks in applications and infrastructure across operational technology (OT), information technology (IT), data science, and data engineering environments
- Own and drive the resolution of different security events, control gaps, policy questions, and technical security risks
- Contribute to building repeatable/reusable/systematic security processes and frameworks to identify potential security events, quantifying and documenting their feasibility, and enumerating the potential blast radius for the organization
- Manage the company’s Compliance & Security Posture Management (CSPM) Platforms, and advance the enterprise's efforts to obtain cybersecurity framework certifications that align with compliance posture along with attestations to reassure internal stakeholders and external customers of our cybersecurity posture, including:
- Provide project management for the implementation of security controls while operating cross-functionally
- Conduct automated evidence collection operations to guarantee the longevity and uniformity of our controls
- Assist with identification and mitigation of cybersecurity risks including compliance concerns (SOX, ISO, NERC-CIP, NIST CSF 2.0)
- Develop, communicate, and assess the compliance stance of the framework in relation to internal and external policies
- Build out and run a Third-Party Cyber Risk Management (TPRM) Program and mitigate systemic risk from security posture vendors and end-to-end software supply chain
- Communicate and maintain cybersecurity and risk metrics for senior executives and leaders of various business units
- Work with External Relations team on proposed cybersecurity legislation and regulations
- Work with Legal and Compliance team to establish cybersecurity controls to facilitate compliance with applicable laws and regulations
Qualifications
- 8+ years of experience in identifying security issues and developing mitigation plans
- Bachelor's or Master's degree in Information Systems, Computer Science, Software Engineering, or a closely related field
- Deep hands-on technical expertise in at least two of the following areas: network security, embedded/hardware security, cryptography, web and network protocols, secure bill of materials, threat modeling, pen tests, or vulnerability assessments
- Demonstrated use of scripting/software development skills (e.g., Python, Rust) to automate processes
- Certifications in Security: CISSP, CISM, CRISC, CISA, GIAC, and EC-Council desired
- Knowledge of fundamental security Email Security, DLP, CSPM, ZTNA, EDR/XDR, and additional security technologies preferred
- Experience in successfully implementing KPIs and metrics for security and risk management
- Proficient in overseeing the execution of audits, certification programs, and control assessments, encompassing responsibilities such as scope planning, delineating control procedures in accordance with established policies, standards, and requirements, conducting control testing, associating issues with risks, and disseminating findings
- Experience with SOC2 ISO27001, and/or NIST security frameworks, controls, tests, and auditing and associated requirements, in addition to familiarity with SOX-regulated environments
- Excellent written and verbal communication skills to communicate effectively at all levels
- Ability to work in a fast-paced environment while managing multiple priorities
- Ability to operate as a team and/or independently while demonstrating flexibility to changing requirements
- Demonstrated ability to work well in a cross-functional environment with both technical and non-technical team members
- Ability to effectively use Microsoft Office products – Word, Excel, Power Point, Outlook
- Knowledge of operational technologies preferred
Compensation, Location, and Benefits
Highly competitive total compensation from one of North America’s leading energy storage developers, owners and operators. Flexible, work from home or hybrid work from Plus Power’s offices in San Francisco, Houston, Chicago, Seattle, and Palm Beach.
The expected salary range* for this position begins at $150,000. We may ultimately pay more or less than the posted range based on several factors including, but not limited to relevant experience, skills, qualifications, geographic labor market, and other factors consistent with applicable law. This position is also eligible to participate in our annual bonus program.
Plus Power offers a comprehensive benefits program, unlimited vacation, flexible remote work, educational assistance, parental leave, and a highly engaging company culture with opportunities for in-person connection and learning and growth.
Plus Power is committed to a diverse and inclusive workplace where people of all backgrounds can thrive. Plus Power is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.
关于这个角色
- 休斯顿,德克萨斯州,美国
- 西雅图,华盛顿,美国
- 旧金山,加利福尼亚州,美国
- 芝加哥,美国
- 棕榈滩,美国
8+ years
UTC-08:00 — UTC-05:00
靠近 休斯顿,德克萨斯州,美国 的类似工作
与朋友分享
形势严峻,谈话的时机已过。现在是采取行动的时候。 帮助朋友加快向可持续未来的转变。
分享这份工作 - Principal Cybersecurity Engineer (m/w/d) - 给你的朋友们,帮助他们找到一份值得自豪的职业。