Sr. Level ICS Cyber Security Consultant (Houston)
Houston, TX (Locals only)
Long Term Contract
Job Description
The Senior Analyst, Technology Security (ICS) reports to the Manager, Technology Security and is a technical expert for plant control systems networks and computing assets, ICS cybersecurity best practices and ICS cybersecurity compliance programs. The position is responsible for hands-on troubleshooting, administrating, supporting, maintaining and improving control system networks, computers, applications, and cybersecurity initiatives including documentation. The Senior Analyst with direction from the Manager, Technology Security and input from the Control Systems Engineer will provide support for development and execution of ongoing infrastructure and cybersecurity projects.
RESPONSIBILITIES AND ESSENTIAL DUTIES
Support execution and development of infrastructure/cybersecurity projects and major capital projects.
Build and administer the Maritime Transportation Security Act (MTSA) Cybersecurity compliance program. This includes but is not limited to developing/maintaining a Cybersecurity Plan, auditing and updating the Plan; ensuring the Cyber Incident Response Plan is executed and exercised, ensuring adequate training of personnel, and compliance with the Plan.
Serve as the cybersecurity advisor to the Controls Systems experts. Monitor with the use of cybersecurity program tools, the health of control system software, hardware, and networks, troubleshoots hardware, software and network issues, performs hardware replacements, performs software corrections, and schedules upgrades as needed. Provide Controls Systems support to Maintenance and Operations groups to keep systems operational.
Maintain, troubleshoot and improve existing cybersecurity management systems including endpoint security, patch management, logging, asset monitoring, access control, IDS, Active Directory Group Policies and administration, firewall rules, and network configuration management.
Support development of cybersecurity framework including creation/revision of policies, guidelines, standards and procedures. Support development of practical ICS Asset Management KPIs and associated reporting.
Participate in ICS Security Incident Response.
Use sound engineering practices, plant standards, and specifications to ensure that documentation for the Controls Systems are maintained properly. Maintains the controls systems asset inventory and system architecture documentation. Evaluate database/automated solutions to keep these up to date.
Thoroughly understand the technical Management of Change (MOC) process and utilize it in support of capital projects and routine facility changes. Support development of risk assessment and cybersecurity Management of Change process.
Develop design basis, preliminary estimates, and schedules for project design scopes.
Work with multidisciplinary Technical Services team to define problems, establish work scopes, prepare task budgets and schedules, plan work, provide technical direction, and report the work status to management.
Reinforce safety and environmental awareness through frequent job observations and by interfacing with plant personnel.
Interact with and support IT, Technology Security, Site Operations, Regulatory Affairs, and other departments as required.
The duties and responsibilities described above are not a comprehensive list, and additional tasks may be assigned to the employee from time to time, or the scope of the job may change as necessitated by business demands.
KNOWLEDGE AND SKILLS
Knowledge: Strong understanding of ICS cybersecurity standards/best practices and systems administration in an operating facility.