Cybersecurity Engineer
Summary
Cybersecurity Engineer securing IT and OT environments at a distributed energy company through security engineering, GRC, vulnerability management, incident response, and tuning of SIEM/EDR/IDS-IPS, aligned to NIST and NERC CIP frameworks including SCADA/ICS controls.
We are ERock!
ERock is a leader and innovator in distributed energy. ERock has responded to long-term trends in electricity by becoming the first smart-grid supplier to US energy consumers. The company installs, operates, and integrates its highly flexible, low-cost, and quick-response distributed generation to increase reliability and stability, reduce costs and decrease carbon footprint.
At ERock, our backup generators ensure that customers will never be without power, allowing their business to operate normally when there is an outage in the area. Our innovative approach provides customers with highly reliable, ultra-clean backup generation at a fraction of the cost of traditional backup solutions. We seek those who share our commitment to customer service, innovation, and ingenuity.
Role Overview:
We are seeking a Cybersecurity Engineer to help secure our organization’s systems and data through a combination of hands-on engineering and governance, risk, and compliance (GRC) practices. In this role, you will apply cybersecurity best practices, risk management, and vulnerability management to protect the organization’s confidentiality, integrity, and availability. You will identify threats and risks, implement effective security controls, and support monitoring and incident response activities.
You will operate with a high degree of independence, designing and executing enterprise-grade security solutions aligned with regulatory requirements and industry frameworks. The ideal candidate is both technical and analytical, capable of translating compliance requirements into practical solutions while driving continuous improvement across security operations. This role reports to the Sr. Cybersecurity Manager and follows a hybrid work model.
Key Responsibilities:
- Design, implement, and maintain enterprise-grade security solutions aligned with regulatory requirements and frameworks (e.g., NIST, NERC CIP)
- Operate with a high degree of independence, driving security initiatives end-to-end from design through implementation
- Monitor, detect, and respond to cyber threats and vulnerabilities across IT and OT environments
- Lead or support incident response activities, ensuring timely containment, remediation, and documentation
- Maintain and improve incident response playbooks, runbooks, and tabletop exercises
- Conduct risk assessments, vulnerability scans, and remediation tracking, focusing on measurable risk reduction
- Track emerging threats and translate threat intelligence into improved detections and controls
- Perform and support security validation activities, including penetration testing and control testing
- Translate GRC requirements into practical technical controls and sustainable processes
- Support and enforce security policies, standards, and procedures, ensuring audit readiness
- Contribute to and evolve security architecture across identity, network, cloud, and OT environments
- Collaborate with IT and business teams to embed security into systems and operations
- Implement, tune, and optimize security technologies (SIEM, EDR, IDS/IPS, etc.)
- Analyze logs and alerts to identify and investigate suspicious activity
- Support implementation of data protection and encryption controls
- Prepare and maintain security documentation and audit artifacts
- Support third-party risk management and vendor security reviews
- Provide technical guidance and mentor team members, acting as a deputy when needed
- Promote a culture of security awareness and continuous improvement
- Support security of OT/ICS environments, including SCADA systems and NERC CIP-aligned controls