Security Architecture Engineer II

Location(s): 

White Plains, NY, US, NY 10606 White Plains, NY, US, NY 10606 White Plains, NY, US, NY 10606 Austin, TX, US, 78701 Chicago, IL, US, 60654 Austin, TX, US, 78701 Chicago, IL, US, 60654 Chicago, IL, US, 60654 Austin, TX, US, 78701


RWE Americas, LLC
To start as soon as possible, full time, permanent

Functional area: IT / Digital
Remuneration: Exempt

 

Join RWE Americas' OT Security team and take architectural ownership of the security controls protecting our grid-scale generation fleet. As the Security Architecture Engineer II, you will design and build the defenses standing between live industrial control systems and the threats targeting them, across 160+ wind, solar, and battery storage sites plus natural gas-powered generation in 27 states.

 

The Security Architecture Engineer II's core focus will be maturing a defensible, standards-based OT security architecture and the platform stack that enforces it. Acting as the technical design authority for operational technology, you will set the reference architectures and secure baselines that every new project is built to, and own the OT security toolchain end to end.

 

Role Responsibilities:

  • Security Architecture & Platform Ownership:
    • Own the architecture and operation of the OT security toolset — asset visibility and access control, monitoring and SIEM, vulnerability management, endpoint protection, and ICS-aware detection. Define how each platform is laid out and behaves across the fleet, including sensor placement, data flows, policy and enforcement structures, and integration into enterprise security systems, then configure, tune, and lifecycle-manage the platforms and set a repeatable deployment standard for new and acquired sites
  • Standards, Baselines & Documentation: 
    • Maintain OT security standards, secure configuration baselines, and hardening requirements aligned to ISA/IEC 62443 and CIS Benchmarks, along with version-controlled reference architectures, connectivity maps, and network diagrams reflecting current and planned state
  • Threat Detection & Monitoring: 
    • Onboard OT logs and telemetry into enterprise monitoring platforms with reliable normalization and event forwarding, build and tune OT-specific detection content, and partner with the SOC on use cases, alert routing, and escalation paths
  • Risk Assessment & Vulnerability Management:
    • Perform in-depth OT risk assessments using MITRE ATT&CK for ICS to map attack paths and control gaps, operate a risk-based vulnerability remediation cadence with plant teams, and validate fixes in staging environments ahead of production rollout
  • Incident Resolution:
    • Act as technical escalation point for OT security incidents, leading investigation, threat hunting, and root-cause analysis, and shaping containment plans that respect operational safety and availability constraints
  • Access & Third-Party Assurance:
    • Define least-privilege roles, privileged account controls, access reviews, and MFA where feasible; design secure remote access for internal engineers and vendors; and review OEM- and vendor-supplied designs and third-party connectivity into OT environments, recommending mitigations for identified gaps
  • Security Requirements in Projects & Procurement:
    • Embed OT security requirements into new-build and repowering projects, acquisitions, and OEM and EPC contracts, and review proposed designs and connectivity before commitments are made
  • Cross-Functional Partnership:
    • Serve as the OT security point of contact for OT, plant operations, asset management, project engineering, and the SOC — sequencing security work around maintenance windows and outages, and translating risk into terms each audience can act on
  • Team Enablement & Knowledge Transfer:
    • Produce the runbooks and technical guidance the team runs on, provide informal mentorship to junior analysts and engineers, and deliver hands-on training so site and operations personnel can support OT security controls locally
  • Compliance & Audit Support:
    • Support audit and compliance activity across NERC CIP (as applicable to in-scope assets), TSA security directives, NIST SP 800-82, and ISA/IEC 62443, providing evidence and remediation input as required

 

Job Requirements and Experience:

  • Bachelor's degree in Engineering, Computer Science, Cybersecurity, IT, or related fields — or equivalent proven track record of security engineering excellence in complex industrial environments
  • Minimum of 5 years in cybersecurity, network engineering, or control systems engineering, including at least 3 years focused on OT/ICS/SCADA environments, working independently within defined processes and providing informal technical guidance to junior team members
  • Strong interpersonal skills, with ability to manage customer relationships
  • Demonstrated desire to learn about the Company and the renewables space
  • Excellent proficiency with Microsoft Office (Excel, Word, PowerPoint, Outlook) and Teams
  • Strong leadership and communication, and ability to meet deadlines
  • Strong organization skills and ability to coordinate multiple tasks and deliverables
  • Ability to multi-task, while working independently and as part of a team
  • Motivated self-starter, goal-oriented, and strong problem-solving abilities
  • Proven ability to empathize, build relationships, and effectively communicate with people from a diverse set of backgrounds
  • Responds well to direction, is easy to challenge and develop, and is coachable
  • Is detail-oriented, has strong business acumen, and a sound understanding of business concepts
  • This position is an office-based role with some travel and visits to other RWEA offices and field locations
  • Must be able to sit, walk, or stand for long durations of time

 

Applicants must be legally authorized to work in the United States. RWE Americas is unable to sponsor or take over sponsorship of employment visas at this time.

 

Pay range: The annual base salary range for this position in Illinois or New York is $105,000- $141,000. The listed salary range represents our good faith estimate for this position and represents the range for new hire salaries across all U.S locations. Please note that the salary information is a general guideline only. RWE considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s education & work experience, training & certifications, and key skills as well as market and business considerations at the time of the offer.

 

Benefits offered: Medical, Dental, Vision, Life Insurance, Short-Term Disability, Long-Term Disability, 401(k) match, Flexible Spending Accounts, EAP, Education Assistance, Parental Leave, Paid time off, and Holidays. Eligible employees also participate in short-term incentives, in addition to salary.

 

Apply with just a few clicks: ad code 93444. Any questions? Contact HR:  rwe_americas_recruiting@rwe.com

 

We look forward to meeting you. Of course, you can find us on LinkedIn, Instagram, Facebook, YouTube and Xing, too.

 

All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status.

 

RWE Americas, a subsidiary of RWE, is a US-based energy company that is helping to meet the growing demand for energy across the United States. Backed by RWE’s 125-year global legacy of managing diverse power assets, RWE Americas operates approximately 13 GW of power projects across 27 states. With a talented workforce of 2,000 employees, RWE Americas develops, constructs and operates wind, solar and battery storage projects that safely deliver affordable, reliable electricity to our customers. Committed to responsible development, RWE Americas invests in local and rural communities, creating jobs and partnering with stakeholders to support and strengthen the places where we live and work. Learn more about how RWE Americas is generating impact at americas.rwe.com.

 

At RWE Americas, we foster a culture defined by our Essential Behaviors – Have Courage, Create Impact and Actively Collaborate. We encourage bold thinking and continuous learning, and we value ownership, resilience and inclusion in everything we do. When you join us, you become part of a team that supports your development, respects your contributions and celebrates shared success. This is a place where you can grow your career and make a meaningful difference.

Yes


Job Segment: Controls Engineer, Computer Science, Network Engineer, Project Engineer, Systems Engineer, Engineering, Technology