Cybersecurity Engineer

Description
We are ERock!
ERock is a leader and innovator in distributed energy. ERock has responded to long-term trends in electricity by becoming the first smart-grid supplier to US energy consumers. The company installs, operates, and integrates its highly flexible, low-cost, and quick-response distributed generation to increase reliability and stability, reduce costs and decrease carbon footprint.
At ERock, our backup generators ensure that customers will never be without power, allowing their business to operate normally when there is an outage in the area. Our innovative approach provides customers with highly reliable, ultra-clean backup generation at a fraction of the cost of traditional backup solutions. We seek those who share our commitment to customer service, innovation, and ingenuity.
What you’ll do:
We are seeking a Cybersecurity Engineer to help secure our organization’s systems and data through a combination of hands-on engineering and governance, risk, and compliance (GRC) practices. In this role, you will apply cybersecurity best practices, risk management, and vulnerability management to protect the organization’s confidentiality, integrity, and availability. You will identify threats and risks, implement effective security controls, and support monitoring and incident response activities.
You will operate with a high degree of independence, designing and executing enterprise-grade security solutions aligned with regulatory requirements and industry frameworks. The ideal candidate is both technical and analytical, capable of translating compliance requirements into practical solutions while driving continuous improvement across security operations. This role reports to the Sr. Cybersecurity Manager and follows a hybrid work model.
Key Responsibilities:
- Design, implement, and maintain enterprise-grade security solutions aligned with regulatory requirements and frameworks (e.g., NIST, NERC CIP)
- Operate with a high degree of independence, driving security initiatives end-to-end from design through implementation
- Monitor, detect, and respond to cyber threats and vulnerabilities across IT and OT environments
- Lead or support incident response activities, ensuring timely containment, remediation, and documentation
- Maintain and improve incident response playbooks, runbooks, and tabletop exercises
- Conduct risk assessments, vulnerability scans, and remediation tracking, focusing on measurable risk reduction
- Track emerging threats and translate threat intelligence into improved detections and controls
- Perform and support security validation activities, including penetration testing and control testing
- Translate GRC requirements into practical technical controls and sustainable processes
- Support and enforce security policies, standards, and procedures, ensuring audit readiness
- Contribute to and evolve security architecture across identity, network, cloud, and OT environments
- Collaborate with IT and business teams to embed security into systems and operations
- Implement, tune, and optimize security technologies (SIEM, EDR, IDS/IPS, etc.)
- Analyze logs and alerts to identify and investigate suspicious activity
- Support implementation of data protection and encryption controls
- Prepare and maintain security documentation and audit artifacts
- Support third-party risk management and vendor security reviews
- Provide technical guidance and mentor team members, acting as a deputy when needed
- Promote a culture of security awareness and continuous improvement
- Support security of OT/ICS environments, including SCADA systems and NERC CIP-aligned controls
Requirements
Required Qualification & Experience:
- Bachelor’s degree in computer science, Information Systems, or equivalent education or work experience
- 4+ years of prior relevant experience
- Hold Cybersecurity certifications (Security+, SSCP, GSEC, CRISC) and/or specific training and certification in security risk management and IT controls frameworks, such as NIST 800-39, 800-30, 800-53, or CSF.
Competency in:
- Strong written and verbal communication (technical + non-technical audiences)
- Project and initiative ownership
- Attention to detail with an audit and risk mindset
- Critical thinking and problem-solving
- Ability to mentor and uplift team members
- Comfortable operating both independently and as part of a team
Required Skills, Knowledge, and Abilities:
- Advanced understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth, and common security elements.
- Deep understanding of networking (TCP/IP, ports, protocols, OSI model, traffic flows)
- Hands-on experience with log analysis, threat investigation, and incident response
- Experience with vulnerability management platforms and remediation workflows
- Proficiency with security tools such as:
o EDR / MDR
o SIEM (engineering, tuning, and use cases)
o IDS/IPS
o Endpoint and network forensics tools
- Strong understanding of modern security architecture (identity, cloud, endpoint, network)
- Experience supporting or operating security monitoring and detection capabilities at scale
Physical requirements and working conditions: Must possess mobility to work in a standard office setting and to use standard office equipment, including a computer, stamina to maintain attention to detail despite interruptions, strength to lift and carry [computer equipment weighing up to 20lbs]; vision to read printed materials and a computer screen, and hearing and speech to communicate in person and over the telephone.
Preferred Qualifications:
- Bring a strong GRC foundation but can translate governance requirements into real technical controls
- Have hands-on experience with NERC CIP or regulated environments
- Can independently drive risk, compliance, and security improvement initiatives end-to-end
- Naturally operate as a technical leader and mentor, even without formal direct reports
- Balance strategic thinking with hands-on execution
What Success Looks Like:
- Security controls are effectively implemented, monitored, and continuously improved, reducing overall organizational risk.
- Cybersecurity initiatives are delivered end-to-end with minimal oversight, demonstrating strong ownership and accountability.
- Threats and vulnerabilities are identified early and addressed proactively, with measurable improvements in detection and response times.
- Incident response is well-coordinated, documented, and repeatable, with clear lessons learned driving ongoing improvements.
- Compliance requirements (e.g., NERC CIP, NIST) are translated into sustainable, auditable technical controls with minimal operational friction.
- Security tools (SIEM, EDR, etc.) are well-tuned and producing high-quality, actionable alerts rather than noise.
- Risk assessments and remediation efforts result in clear, measurable risk reduction across IT and OT environments.
- Security documentation, runbooks, and audit artifacts are accurate, up-to-date, and audit-ready at all times.
- Cross-functional teams actively engage with and trust cybersecurity, reflecting strong collaboration and practical security integration.
- The individual is recognized as a go-to technical leader and mentor, capable of stepping in to lead initiatives or guide the team when needed.
Your Rewards!
- Medical, Dental, Vision, and Prescription Drug Insurance
- Company-Paid Life Insurance
- Flexible Spending Account (FSA)
- Wellness Programs and Incentives
- 401(k) Retirement Plan & Company Match
- Paid Time Off – Sick & Vacation Time
- Paid Holidays
- Hybrid Work Schedule!
- Cool Open-Office Concept
Do you have what it takes to join the ERock team? Send us your resume today.
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
ERock is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
At ERock, we embrace diversity, including all the unique characteristics that make us human: race, age, sexual orientation, gender identity, religion, disability, and education — to name a few. We understand and recognize that diverse backgrounds and perspectives strengthen our teams and our business. The foundation of our diversity efforts is closely tied to our core values specifically our value of “The Team” which includes “Mutual Respect, Openness, and Honesty.”
You'll be redirected to
the company's application page