Programmer Analyst / System Engineer at Confidential company
About the Job
Position: Sr. Programmer Analyst / System Engineer
Location: Lexington, KY
Duration: Full Time / Direct Hire
POSITION SUMMARY
This is a well-rounded computer professional position utilizing skills in the areas of system and network administration, database management, and programming to manage commercial and in-house developed applications used to ensure compliance with NERC standards and assist in maintaining the security of Client’s critical infrastructure networks and connected systems.
DUTIES AND RESPONSIBILITIES
- Responsible for the implementation and maintenance of SigmaFlow and/or other software solutions to automate workflows and manage documentation necessary to demonstrate compliance with NERC Critical Infrastructure Protection (CIP) Standards.
- Designs, codes, tests, debugs, and documents customizations to the software.
- Jointly responsible, along with the Cyber Security Analyst, for maintenance, patching, malware signature updates, and upgrades of critical infrastructure network equipment, computers, and transient laptops. Creates change control tickets, performs security tests on the changes prior to implementation, and generates related evidence.
- Provides system administration for Client physical access control system used to protect critical infrastructure, and manages the associated in-house developed system used for visitor management.
- Assists to maintain SCADA/EMS and other critical infrastructure firewalls.
- Assists to establish and implement security configuration procedures and standards and ensures their conformance with Critical Infrastructure Protection policies.
- Monitors and maintains server backup system and responds to problems; assists in recovery of critical systems by performing restoration from backup and other tasks as assigned.
- Creates network user accounts and performs security changes in compliance with Critical Infrastructure Protection policies and controls.
- Assists in the implementation and maintenance of software solutions to automate and manage security of the SCADA/EMS, including integrity management, intrusion detection, log collection, and analysis.
- Research new products and technologies.
- Assists to develop and maintain accurate software and hardware inventories and baselines of approved security configurations.
- Assists to train and advise users on security practices and CIP compliance.
- Actively participates in NERC CIP compliance audits, including interviews and collecting responses to data requests.
- Maintains awareness of current and planned NERC CIP and related standards and their impact to client.
Skills and Abilities:
- Knowledge of PC/LAN/WAN communication hardware/software including Dell Sonicwall firewalls.
- Knowledge of Windows Active Directory, Windows Server, Linux.
- Experience in installation, configuration, and management of operating systems Windows Server, Windows 10, and Linux.
- Knowledge of MS SQL Server administration.
- Competent to develop queries and programming using MS SQL and Access.
- Competent to develop scripts and programs using VBScript, VBA, PowerShell and regular expressions.
- Knowledge of client’s physical access management system and door panels.
- Knowledge of Tripwire Enterprise and Log Center software products.
- Knowledge of SigmaFlow compliance management system.
- Basic knowledge of the SCADA/EMS architecture.