Job Description:
Engineer III, OT/ICS Cybersecurity & Controls
Location: Heathrow, FL / Hybrid / Remote
About Nextpower
The world's demand for electricity is growing faster than ever. Meeting that demand requires infrastructure that's smarter, more reliable, and built to last. The future of energy is not about one advanced technology – it’s about bringing the right solutions together in a unified platform that can deliver reliable power at scale. As a trusted, bankable partner, Nextpower provides integrated technology solutions for utility-scale solar, energy storage, and critical power infrastructure, helping customers design, build, and operate projects with greater speed, reliability, and long-term value. Building on more than a decade of innovation and execution, we're helping power the electrified world. Together, we're powering what's next.
Our Values
Innovation
· We challenge limits to power what’s next.
Integrity
· We do the right thing with honesty and respect.
Accountability
· We own it, we deliver, we rise together.
Collaborative
· We listen, include, and win as a team.
Customer Focus
· We earn trust by partnering to solve what matters most.
Job Summary
The OT/ICS Cybersecurity & Controls Engineer III reports to the Director, EMS Engineering and Delivery and is responsible for securing, hardening, and maintaining the industrial network and control system environments that support Prevalon Energy's insightOS™ Container Management System (CMS) and utility-scale Battery Energy Storage System (BESS) deployments. As a senior individual contributor, this engineer owns the cybersecurity posture of OT networks in the field and in the cloud - designing and maintaining segmented network architectures, configuring and troubleshooting managed switches and firewalls, deploying and tuning SIEM tooling, and administering the Ignition SCADA/HMI platform - while advising on architecture, risk, and strategy across the fleet. The role partners closely with Controls, Software, and IT leadership to ensure BESS sites meet applicable cybersecurity compliance requirements (e.g., NERC CIP, IEC 62443, NIST 800-82) while supporting commissioning, incident response, and ongoing operations across the fleet.
Essential Duties & Responsibilities
Essential duties and responsibilities include, but are not limited to the following:
- Design, configure, and maintain OT network architecture for BESS sites, including managed Layer 2/3 switches, VLAN segmentation, subnetting, and routing between control, SCADA, and enterprise zones.
- undefined
- Configure, harden, and troubleshoot firewalls (policies, ACLs, NAT, and site-to-site/remote access VPNs) to enforce network segmentation and zero-trust principles across industrial control networks.
- Administer the Ignition SCADA/HMI platform, including Gateway configuration, tag structures, alarming, security zones/roles, and scripting (Python/Jython) to support monitoring and supervisory control of BESS assets.
- Deploy, tune, and monitor SIEM platforms (e.g., Splunk, Microsoft Sentinel) to aggregate logs, build detections/dashboards, and identify anomalous activity across OT and IT-adjacent systems.
- undefined
- Design and maintain Azure cloud network and security architecture supporting cloud-connected CMS/SCADA applications, including virtual networks, network security groups, Azure Firewall, and Microsoft Defender for Cloud.
- Administer identity and access management (Azure Entra ID) for OT/ICS system access, including role-based access control, conditional access, and privileged access reviews.
- Conduct cybersecurity risk assessments, vulnerability scanning, and gap analyses for ICS/OT assets, and drive remediation in accordance with IEC 62443, NERC CIP, and NIST 800-82/800-53 frameworks.
- undefined
- Support cybersecurity compliance audits by maintaining system inventories, network diagrams, security control documentation, and evidence of compliance.
- Develop, maintain, and exercise OT incident response and disaster recovery playbooks/procedures in coordination with IT Security and Operations.
- Partner with Controls Engineering on secure integration of PLCNext controllers, Modbus TCP/RTU, and OPC-UA communications into the CMS network architecture.
- Provide onsite and remote support for network and cybersecurity-related troubleshooting during commissioning, ensuring switches, firewalls, and SCADA/Ignition systems are properly configured prior to energization.
- Maintain awareness of emerging OT/ICS threats, vulnerabilities, and industry best practices, and recommend improvements to the security posture of the fleet.
- Assist the Operations team in resolving network- and cybersecurity-related issues that arise post-commissioning.
- Serve as the technical authority on OT/ICS cybersecurity architecture, advising Engineering and Delivery leadership on risk, tradeoffs, and long-term security strategy for the CMS/BESS platform.
- Establish and evolve team standards, reference architectures, and best practices for network segmentation, firewall policy, SIEM use, and Ignition/SCADA security across the fleet.
- Mentor junior engineers on OT network and cybersecurity fundamentals and review their designs and configurations for adherence to security and compliance standards.
- Perform other duties as assigned.
Knowledge, Skills, & Abilities
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Knowledge
- Working knowledge of industrial network architecture and hands-on configuration/troubleshooting of managed switches, routers, and firewalls (e.g., Cisco, Fortinet, Palo Alto).
- undefined
- Mastery of network fundamentals: VLANs, subnetting, routing, NAT, ACLs, and secure remote access (VPN).
- undefined
- Required working knowledge of NERC CIP compliance requirements as they apply to BES Cyber Systems, including asset categorization, electronic/physical security perimeters, and access management.
- undefined
- Required familiarity with the IEC 62443 series of industrial automation and control systems (IACS) cybersecurity standards, including zone/conduit segmentation, security levels, and lifecycle security requirements.
- undefined
- Familiarity with additional ICS/OT cybersecurity frameworks and standards, including NIST 800-82/800-53.
- undefined
- Working knowledge of SIEM platforms, log aggregation, and security event correlation/alerting for threat detection.
- Understanding of SCADA/HMI system architecture, particularly the Ignition platform (Gateway, Designer, tag/alarm structures).
- Protocol working knowledge in Modbus TCP/RTU, OPC-UA, MQTT-SpB, and/or IEC 61850 is a plus.
- Working knowledge of Microsoft Azure cloud networking and security services (VNets, NSGs, Azure Firewall, Entra ID, Defender for Cloud).
- undefined
- Experience with BESS, Container Management Systems, or other industrial control system environments including their communication network architecture and cybersecurity requirements is a plus.
Skills
- Hands-on proficiency configuring, troubleshooting, and hardening Layer 2/3 managed network switches and firewalls (policies, routing, VLAN tagging, fiber network technology).
- undefined
- Proficient administering the Ignition SCADA/HMI platform, including scripting and security configuration.
- undefined
- Proficient with SIEM tooling (e.g., Splunk, Microsoft Sentinel, or similar) for building detections, dashboards, and alerting.
- undefined
- Proficient with Microsoft Azure networking and security services; working knowledge of Azure AD/Entra ID administration.
- undefined
- Proficient supporting cybersecurity compliance activities, including documentation, evidence gathering, and audit support for frameworks such as IEC 62443 and NERC CIP.
- Proficient with Modbus and/or OPC-UA industrial protocols.
- undefined
- Basic / Foundational experience with Python or PowerShell scripting for automation and log analysis.
- undefined
- Basic / Foundational experience with vulnerability scanning and assessment tooling.
- undefined
- Proficient in MS Office, Windows RDP, and remote administration tools.
- undefined
- Working knowledge of Linux OS, including command-line administration, service/log management, and basic hardening practices is a plus.
Abilities
- Able to define problems, collect data, establish facts, and draw valid conclusions. Able to interpret an extensive variety of technical instructions and read/understand network, control, and electrical drawings.
- undefined
- Communicate effectively with staff and management at all levels, including translating technical cybersecurity risk into business terms.
- undefined
- Always maintain the highest degree of honesty and integrity.
- undefined
- Lead proactive efforts to achieve departmental and company cybersecurity and compliance goals.
- undefined
- Ability to work under pressure and adapt to changing requirements with a positive attitude.
- undefined
- Protect confidential information by not communicating, disclosing to, or using it for the benefit of 3rd parties. Protection of the CMS/SCADA platform and its cybersecurity posture is of utmost importance.
- undefined
- Comply with all EHS policies, practices, and procedures, reporting all unsafe activities to Management and/or Human Resources.
- undefined
- Work in a global environment to maintain standards and latest cybersecurity practices.
- undefined
- Ability to work closely with and influence cross-functional teams (Controls, Software, IT, and Operations).
- undefined
- Self-directed project management skills to lead security initiatives to completion.
- Highly competitive, self-starter that can work both individually and in a group setting.
- undefined
- Ability to work flexible hours and be independent in the field during commissioning support.
Education & Experience
- Bachelor's degree in cybersecurity, computer engineering, electrical engineering, computer science, or a related field, with a minimum of five (5) years of related experience in OT/ICS or IT network security.
- undefined
- Demonstrated familiarity with and hands-on experience supporting NERC CIP compliance requirements (e.g., asset identification/categorization, electronic and physical security perimeters, access control, and audit evidence/documentation) is required.
- undefined
- Hands-on experience configuring and troubleshooting managed network switches and firewalls in a production or industrial environment is required.
- undefined
- Experience administering or supporting a SCADA/HMI platform (Ignition preferred) is required.
- undefined
- Experience with SIEM deployment, tuning, or monitoring is required.
- undefined
- Experience with Microsoft Azure networking, security, and identity services is preferred.
- undefined
- Familiarity with IEC 62443 industrial cybersecurity standards is required.
- undefined
- Experience supporting cybersecurity compliance programs more broadly (NIST 800-82) is preferred.
- Relevant certifications a plus: CISSP, GICSP, CCNA/CCNP Security, CompTIA Security+, Microsoft Certified: Azure Security Engineer Associate, or Certified SCADA Security Architect.
- undefined
- Experience with inverter-based technology projects, especially involving Battery Energy Storage Systems or PV, is considered an asset.
- Experience reading and understanding project drawings, network diagrams, and technical documentation.
- s (e.g., SAP, Oracle) and E Procurement tools (e.g., Coupa, Ariba).
Physical Requirements & Work Environment
The physical demands and work environment characteristics described herein are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Ability to travel up to 20% of the time, including occasional international travel, to support commissioning and network/cybersecurity configuration of BESS sites.
- undefined
- Regularly required to sit and use a computer for extended periods; occasionally required to stand, walk, and move equipment in switchgear/network rooms.
- undefined
- Occasionally lift and/or move up to 25 pounds (networking hardware, laptops, test equipment).
- undefined
- The noise level in the work environment is usually low to moderate in office settings, and moderate to loud during site visits.
- undefined
- Our Lake Mary, FL office is conveniently located near Orlando International Airport (MCO), with a modern floor plan including a Diagnostics Operations Center (DOC) and SCADA provisioning room embedded in the design. This role would be either Remote or Hybrid (2-3 days a week) in the office, depending on the situation.
- undefined
- Work Environment Conditions
- Work is performed in a climate-controlled office environment with standard lighting and noise levels. During occasional site visits, the employee may be exposed to outdoor weather conditions, industrial noise levels requiring hearing protection, and energized electrical equipment requiring appropriate PPE. Site visits may require hands-on network/cybersecurity configuration, installation, or troubleshooting work.
- undefined
- PPE Requirements (if applicable)
- Standard office attire applies for daily work. When visiting operational sites, the employee must wear employer-provided PPE including: hard hat, safety glasses, steel-toed footwear, high-visibility vest, and hearing protection as posted. Arc flash rated PPE is not required as this position does not perform energized electrical work.
- undefined
- Travel Requirements (if applicable)
- Travel up to 20% of the time, including occasional international travel, to support network and cybersecurity configuration during BESS commissioning.
At Nextpower, we are driving the global energy transition with an integrated clean energy technology platform that combines intelligent structural, electrical, and digital solutions for utility-scale power plants. Our comprehensive portfolio enables faster project delivery, higher performance, and greater reliability, helping our customers capture the full value of solar power. Our talented worldwide teams are redefining how solar power plants are designed, built, and operated every day with smart technology, data-driven insights, and advanced automation. Together, we’re building the foundation for the world’s next generation of clean energy infrastructure.
Nextpower is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
We are NextpowerSkills Required
- Bachelor’s degree in cybersecurity, computer engineering, electrical engineering, computer science, or a related field
- Minimum five years of related experience in OT/ICS or IT network security
- Hands-on experience supporting NERC CIP compliance requirements
- Hands-on experience configuring and troubleshooting managed network switches and firewalls in a production or industrial environment
- Experience administering or supporting a SCADA/HMI platform, preferably Ignition
- Experience with SIEM deployment, tuning, or monitoring
- Experience with Microsoft Azure networking, security, and identity services
- Familiarity with IEC 62443 industrial cybersecurity standards
- Experience supporting cybersecurity compliance programs such as NIST 800-82
- Relevant certifications such as CISSP, GICSP, CCNA/CCNP Security, CompTIA Security+, Microsoft Certified Azure Security Engineer Associate, or Certified SCADA Security Architect
- Experience with inverter-based technology projects, especially Battery Energy Storage Systems or photovoltaic systems
- Experience reading and understanding project drawings, network diagrams, and technical documentation
Nextracker Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Nextracker and has not been reviewed or approved by Nextracker.
-
Retirement Support — A 401(k) with company match is offered. The company stood up its own plan in 2023 alongside additional welfare benefits in early 2024.
-
Wellbeing & Lifestyle Benefits — Wellness offerings include yoga and meditation classes, onsite chair massages and bicycles, commuter/rideshare support, and EV charging at some locations. These extras supplement the core medical, dental, and vision coverage.
-
Parental & Family Support — Paid parental and family medical leave are included alongside PTO and paid holidays. This complements the broader U.S. benefits menu.
Nextracker Insights
What We Do
Since day one, Nextracker’s mission has been to transition the world to affordable, renewable power, by developing the highest-performing and resilient solar tracking technologies and software in the market for our customers. From sustainable tracker solutions that conform to uneven terrain and withstand extreme weather, Nextracker systems have resilience built in. Nextracker leads the solar industry with solar tracker technologies that optimize and increase energy production while reducing costs for significant plant ROI
.png)





