Senior IT Process Engineer

Requisition ID # 119203

Job Category : Engineering / Science

Job Level : Individual Contributor

Business Unit: Information Technology

Department Overview

The Cybersecurity team enables PG&E to achieve its mission by providing governance, oversight, and support of operational resiliency and asset safeguards in a relevant, timely and data-driven manner. The Cybersecurity team consists of security professionals in their chosen disciplines, including:

  • Cybersecurity Services
  • Risk & Strategy
  • Security Intelligence & Operations
  • Compliance

Working together, we review the current cyber threat landscape and lend our expertise to help the company understand its security posture and act on the highest priority risks.

The Cybersecurity team takes a proactive approach to security by focusing on the cyber risks PG&E faces. Our methodology and framework synthesizes current legal, regulatory, and operating mandates with PG&E’s business goals and operations. By taking this information and focusing on the cyber risks unique to individual Lines of Business (LOB), Cybersecurity helps PG&E’s LOBs make informed decisions about where to invest their resources.

Position Summary

The Senior IT Process Engineer will conduct, monitor and improve identity and access management (IAM) processes and controls to facilitate regulatory compliance working closely with managers, team leaders, specialists, security teams, compliance teams and subject matter experts. This position will provide support to deliver regular IAM compliance health status and metrics, and internal and external auditor interactions as necessary.

The role will work from your home office through April 2022. Once a date for returning to the office is identified the work location can be flexible in Rocklin, Sacramento, San Ramon, or Oakland. 

Job Responsibilities

  • Reviews and stays current on North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) regulations as they apply to the Identity and Access (IAM) Management domain
  • Establishes and executes IAM domain procedures and processes in support of NERC CIP compliance
  • Works with lines of business to execute IAM procedures in a timely manner to maintain NERC CIP compliance
  • Performs ongoing monitoring to ensure IAM processes and technology solutions continue supporting NERC CIP compliance
  • Works with compliance teams to establish, test, and maintain CIP related IAM controls
  • Identifies potential compliance gaps and as required follows compliance reporting processes, performs extent of condition reviews, and establishes mitigation plans
  • Investigates and addresses CIP related IAM corrective action program (CAP) issues
  • Works within IAM Operations and with other cross functional operations and compliance teams to ensure processes and technical solutions align to meet NERC CIP requirements, and provide requirements to update processes and technical solutions as needed
  • Supports the development and presentation of regular status reports and metrics providing visibility to NERC CIP compliance status in the IAM domain
  • Supports regular reviews and updates to CIP004 standards and reliability standard audit worksheets (RSAW)
  • Supports interactions with external regulatory enforcement organizations during audits or other required meetings, and internal audit teams

Qualifications

Minimum:

  • Bachelors Degree in Computer Science or job-related discipline or equivalent experience
  • Experience in enterprise architecture environments, job-related
  • 5 years experience in IT-Information Technology engineering design

Desired:

  • 2 years of IT/Cybersecurity experience
  • Solid understanding of general computing controls (GCCs)
  • Experience with NERC CIP regulations preferably in the IAM domain
  • Utility industry experience
  • Certified Information Systems Security Professional (CISSP)
  • Experience with documenting processes and procedures
  • Strong oral and written communication skills
  • Strong analytical skills
  • Ability to work with minimal supervision in a fast-paced environment
  • Detail oriented

More Information

Apply for this job

Leave your thoughts

Share this job

PG&E

(0)