Cybersecurity Operations Engineer

Posted 4 Days Ago
Be an Early Applicant
Rutland, VT, USA
In-Office
91K-127K Annually
Mid level
Energy
The Role
Performs cybersecurity operations across alert monitoring, incident response, threat hunting, vulnerability management, detection engineering, identity security, and regulatory compliance. The role administers security tools, investigates suspicious activity, coordinates containment and remediation, supports NERC CIP-008 and CIP-015 activities, maintains audit evidence, and partners with technical and business stakeholders. Participation in on-call coverage, security assessments, projects, vendor reviews, and periodic industry travel is required.
Summary Generated by Built In

As the nation’s first statewide, “transmission only” company, VELCO manages the safe, reliable, cost-effective transmission of electric power throughout Vermont and as a part of the integrated New England regional network.

 Why you should join our team

At VELCO, cybersecurity is essential to maintaining a reliable and resilient electric grid. As a Cybersecurity Operations Engineer, you will play a critical role in protecting VELCO’s corporate technology environment from evolving cyber threats while supporting the secure delivery of the technology and services our organization depends on.


If you enjoy solving complex problems, investigating suspicious activity, improving security capabilities, and working with a team committed to protecting critical infrastructure, this is an opportunity to make a meaningful impact.

 How you will make an impact

This role combines hands-on security operations, incident response, threat analysis, vulnerability management, security engineering, and regulatory compliance. You will work across endpoints, identities, networks, servers, cloud services, applications, and third-party connections while partnering with Information Security, IT Infrastructure, business teams, Compliance, Legal, Human Resources, and other stakeholders.

You will also contribute to VELCO’s NERC CIP cybersecurity program, including cybersecurity incident response activities under CIP-008, internal network security monitoring under CIP-015, and risk assessment support under CIP-013.


The Cybersecurity Operations Engineer is expected to independently complete assigned operational and compliance-support activities, apply sound judgment during security events, and escalate material risks promptly. The role performs complex security analysis, develops repeatable operational procedures, maintains defensible records, and contributes to continuous improvement of VELCO’s corporate cybersecurity program. The position typically requires progressively responsible experience sufficient to operate with limited oversight while collaborating effectively across technical and business functions.

 

Responsibilities

  • Monitor and triage security alerts from corporate endpoints, identity platforms, networks, servers, cloud services, email, applications, and other enterprise security technologies.
  • Investigate suspicious activity, validate the scope and severity of events, document findings, coordinate containment and remediation, and escalate incidents in accordance with VELCO procedures.
  • Participate in VELCO’s cybersecurity incident response program and NERC CIP-008 activities, including preparation, testing, event classification support, evidence preservation, response coordination, recovery, lessons learned, and maintenance of incident records.
  • Participate in NERC CIP-015 internal network security monitoring activities, including support for monitoring strategy, sensor and data-source coverage, alert review, analysis, escalation, evidence retention, testing, and documented process improvement.
  • Administer and improve corporate security operations tools such as security information and event management, endpoint detection and response, email security, vulnerability management, identity protection, network monitoring, and security orchestration technologies.
  • Develop and tune detections, dashboards, correlation rules, use cases, playbooks, and response procedures to improve visibility and reduce response time while managing false positives.
  • Conduct vulnerability assessment and remediation coordination for corporate systems; validate risk, establish priorities with system owners, track corrective actions, and report unresolved exposure.
  • Support identity and access security through review of privileged activity, authentication anomalies, account misuse, access-control exceptions, and other indicators of compromise.
  • Analyze threat intelligence and emerging attack techniques for relevance to VELCO, recommend practical defensive actions, and incorporate useful indicators and behaviors into monitoring processes.
  • Perform proactive threat hunting and security analysis using available telemetry, baselines, and contextual information to identify malicious or abnormal activity.
  • Maintain accurate case notes, operational metrics, evidence, procedures, diagrams, inventories, and other records needed for management reporting, audits, investigations, and regulatory compliance.
  • Partner with IT Infrastructure and application owners to securely implement changes, validate logging and monitoring requirements, and resolve security issues affecting corporate services.
  • Support security assessments, control testing, audit requests, regulatory reviews, tabletop exercises, and corrective action plans in coordination with VELCO’s Compliance and business teams.
  • Provide security guidance and awareness to employees and technical teams, translating technical findings into clear business risk, recommended actions, and status updates.
  • Participate in project planning, technology evaluations, vendor security reviews, and implementation activities to ensure security requirements are addressed throughout the solution lifecycle.
  • Participate in an on-call rotation and support coordinated response during significant cybersecurity events or operational emergencies.
  • Represent VELCO in appropriate industry, regional, and regulatory forums; maintain current knowledge through training, exercises, workshops, and professional development.
  • Perform other duties as assigned.

 

Who you are

Education & Training

Bachelor’s degree in cybersecurity, information technology, computer science, information systems, or a related technical discipline is preferred. An associate degree, recognized technical or military training, or an equivalent combination of relevant education and progressively responsible experience may be considered. At least one current industry-recognized cybersecurity certification aligned with security operations—such as CompTIA Security+, CompTIA CySA+, GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), or an equivalent credential—is preferred; candidates without a certification may be expected to obtain an approved credential within 12 months of hire. The position requires ongoing role-based training in incident response, security monitoring and detection, threat analysis, vulnerability management, cloud and identity security, and applicable VELCO procedures and NERC CIP requirements, including CIP-008 and CIP-015.


Experience

3–7 years of progressively responsible experience in cybersecurity operations, security engineering, incident response, infrastructure security, or a related field. Experience in a regulated environment, electric utility, or critical infrastructure organization is preferred. Practical experience investigating alerts, administering security tools, coordinating remediation, and producing clear operational or compliance evidence is expected.


Knowledge/Skills

  • Working knowledge of security operations center practices, incident handling, threat analysis, alert triage, case management, and escalation.
  • Experience with SIEM, endpoint detection and response, vulnerability management, email security, identity protection, network security monitoring, and related enterprise security platforms.
  • Knowledge of Windows and Linux systems, Microsoft Active Directory and Entra ID, Microsoft 365, virtualization, networking, DNS, DHCP, VPN technologies, cloud services, and common enterprise applications.
  • Ability to analyze logs and telemetry from endpoints, identity systems, firewalls, network devices, servers, cloud platforms, and applications to identify suspicious behavior and determine impact.
  • Understanding of cybersecurity incident response lifecycles, evidence handling, root-cause analysis, recovery, lessons learned, and the preparation of clear incident documentation.
  • Familiarity with internal network security monitoring concepts, detection engineering, traffic and flow analysis, sensor coverage, logging architecture, and escalation procedures.
  • Working knowledge of NERC CIP concepts and the ability to support documented controls, evidence, testing, and audit activities, particularly for CIP-008 and CIP-015.
  • Familiarity with recognized cybersecurity practices and frameworks such as NIST guidance, CIS Controls, MITRE ATT&CK, vendor security guidance, and risk-based vulnerability management.
  • Ability to develop and maintain scripts, queries, automation, playbooks, test plans, and technical procedures that improve security operations while following change-control requirements.
  • Strong analytical, troubleshooting, organizational, and project coordination skills, with careful attention to detail and the ability to manage competing priorities.
  • Excellent written and verbal communication skills, including the ability to explain technical findings, operational impact, compliance considerations, and recommended actions to technical teams, management, auditors, and business stakeholders.
  • Ability to maintain confidentiality, exercise sound judgment, work effectively during high-pressure events, and collaborate professionally across a diverse organization.

Work Environment
  • Open office setting and dog friendly
  • Opportunity to work closely with engineering, IT, and operations
  • Mission-driven organization supporting critical energy infrastructure
  • Collaborative, cross-functional team environment

Physical/Mental Demands

Prolonged periods of sitting at a desk and working on a computer are required. The position must be able to perform detailed analytical work, manage multiple priorities, communicate clearly during time-sensitive events, and maintain accuracy in potentially stressful situations with frequent interruptions. Participation in rotating on-call coverage and work outside normal business hours may be required for significant security events, maintenance, exercises, or regulatory activities. Periodic travel and overnight stays may be required for training, workshops, meetings, or industry events.

 

Compensation Range: 

$90,916.80 - $109,100.16 - $127,283.52/salary 

This compensation range represents the minimum, midpoint and maximum pay for this position. Individual offers will be based on various factors including, but not limited to, qualifications, education, skills, competencies, and experience. Please note that most offers for new employees fall under the midpoint of the range, allowing room for continued salary growth.  Base pay is just one component of our total compensation package, which may also include comprehensive benefits, generous paid time off and incentive compensation (bonus) potential.

Important Considerations

  • Visit Velco.com for additional information on VELCO culture, benefits, and the recruiting process.

  • We are an equal opportunity employer, and ALL qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Eligible applicants must be authorized to work in the United States.

  • VELCO is handling all aspects of talent acquisition internally and will not engage the services of third-party staffing agencies, recruiters, or headhunters. We kindly request that these entities refrain from contacting us.

  • Any offer of employment will be contingent upon successful reference check, background check (including social media check), physical examination, drug screening.


If you need an accommodation as part of the application or interview process, please send a request to [email protected]

    Skills Required

    • 3-7 years of progressively responsible experience in cybersecurity operations, security engineering, incident response, infrastructure security, or a related field
    • Practical experience investigating alerts, administering security tools, coordinating remediation, and producing operational or compliance evidence
    • Working knowledge of security operations center practices, incident handling, threat analysis, alert triage, case management, and escalation
    • Experience with SIEM, endpoint detection and response, vulnerability management, email security, identity protection, network security monitoring, and enterprise security platforms
    • Knowledge of Windows, Linux, Active Directory, Entra ID, Microsoft 365, networking, DNS, DHCP, VPN technologies, cloud services, and enterprise applications
    • Bachelor's degree in cybersecurity, information technology, computer science, information systems, or a related technical discipline
    • Associate degree, recognized technical or military training, or equivalent education and progressively responsible experience may be considered
    • Current industry-recognized cybersecurity certification such as Security+, CySA+, GCIH, GCIA, or equivalent
    • Ability to support NERC CIP controls, evidence, testing, and audit activities, particularly CIP-008 and CIP-015
    • Ability to develop and maintain scripts, queries, automation, playbooks, test plans, and technical procedures
    • Strong analytical, troubleshooting, organizational, communication, and project coordination skills
    • Ability to participate in rotating on-call coverage and work outside normal business hours during significant events
    Am I A Good Fit?
    beta
    Get Personalized Job Insights.
    Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

    The Company
    HQ: Mendon, VT
    174 Employees
    Year Founded: 1956

    What We Do

    VELCO is Vermont’s statewide electric transmission provider whose sights are set on creating a sustainable Vermont through our people, assets, relationships and operating model. Formed in 1956 when local Vermont utilities established the nation’s first “transmission only” company to access clean hydro power from New York, VELCO remains unique in two important ways: 1. Our ownership comprises the state’s 17 distribution utilities and a public benefits corporation; and, 2. our for-profit status is structured to return cooperative-like value to our owners, their customers, and every Vermonter. VELCO’s system now includes: 740 miles of transmission lines; 55 substations, switching stations and terminal facilities; 13,000 acres of rights-of-way; a statewide emergency service radio system; and, a 1,600-mile fiber optic network that monitors and controls the electric system and helps to deliver broadband services to Vermonters. Headquartered in Rutland, Vermont, VELCO employees strive to give Vermont’s utilities and their customers a reliable high-voltage grid, a strong unified voice on regional energy issues, and continued access to safe, reliable, cost-effective electricity.

    Similar Jobs

    Wipfli Logo Wipfli

    Analyst III, Workday ERP

    Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
    Remote or Hybrid
    United States
    2900 Employees
    88K-132K Annually

    Shield AI Logo Shield AI

    Senior Lead, Enterprise Strategy and Operations (R5624)

    Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software • Defense Technology
    In-Office or Remote
    4 Locations
    160K-240K Annually
    Remote or Hybrid
    US
    15100 Employees
    91K-128K Annually

    Shield AI Logo Shield AI

    Director, Enterprise Strategy and Operations (R5626)

    Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software • Defense Technology
    In-Office or Remote
    4 Locations
    190K-290K Annually

    Similar Companies Hiring

    Energy CX Thumbnail
    Greentech • Professional Services • Business Intelligence • Consulting • Energy • Financial Services • Utilities
    Chicago, IL
    150 Employees
    Rangeview Thumbnail
    Aerospace • Robotics • Energy • Defense • Manufacturing • Weapons Systems
    El Segundo, California
    38 Employees
    Ford Energy Thumbnail
    Automotive • Software • Energy • Utilities • Manufacturing • Renewable Energy
    US
    55 Employees

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account