OT GRC Specialist

Date: Sep 1, 2023

Location: Bethpage, NY, US

Company: PSEG

Requisition: 74947

PSEG Company: PSEG Long Island    

Salary Range: $ 79,800 - $ 131,700 

Incentive: PIP 10%   

Work Location Category: Remote Local  

PSEG operates under a Flexible Work Model where flexible work is offered when job requirements allow. In support of this model, roles have been categorized into one of four work location categories: onsite roles, hybrid roles that are a blend of onsite and remote work, remote local roles that are primarily home-based but require some level of purpose-driven in-person interaction and living within a commutable distance, and remote non-local roles that can be effectively performed remotely with the ability to work in approved states.

PSEG offers a unique experience to our more than 12,000 employees – we provide the resources and opportunities for career development that come with being a Fortune 500 company, as well as the attention, camaraderie and care for one another you might typically associate with a small business. Our focus on combatting climate change through clean energy technology, our new net zero climate vision for 2030 and enhanced commitment to diversity, equity and inclusion; and supporting the communities we serve make this a particularly exciting time to join PSEG.

Job Summary

This position is an experienced, senior level, hands-on technical lead, performing OT security functions and maintaining systems, while providing technical guidance to the team.  Manages OT Governance, Risk and Compliance capabilities including as OT Vulnerability & Risk Compliance, OT Cyber Governance, OT Cyber Strategy, OT Cyber & 3rd Party Risk, & OT Security Architecture, as well as security policies and procedures, and incident response as needed.  Provides technical expertise and support OT management and staff in cybersecurity threat risk assessments, development, testing and the implementation and operation of appropriate information security plans, procedures, and control techniques designed to prevent, minimize or quickly recover from cyber-attacks or other serious events.

Job Responsibilities

Responsibilities include:
•    Manages OT GRC capabilities including Vulnerability & Risk Compliance, Cyber Governance, Awareness, & Strategy, Cyber & 3rd Party Risk, & Security Architecture.
•    Provides technical expertise and support to OT management and staff in cybersecurity threat risk assessments, development, testing and the implementation and operation of appropriate information security plans, procedures, and control techniques designed to prevent, minimize or quickly recover from OT cyber-attacks or other serious events.
•    Has strong incident response and threat analysis experience,.  Proficient in defining processes and procedures for incident response.  
•    Follows cyber security news and alerts, understands complex attack vectors and risks, and identifies and evaluates emergent cyber security threats and vulnerabilities.  Recommends appropriate corrective actions for information security incidents and provides risk mitigation recommendations to management and team.
•    Designs process flows to be implemented to respond to threats quickly and effectively.
•    Reviews complex architecture design diagrams and documents for new technologies and changes to existing technologies to determine risks and provide recommendations and mitigations.
•    Works independently with little or no supervision.

Job Specific Qualifications

•    Bachelor's degree in Computer Science, Information Systems, Cyber Security, Math or Engineering and  a minimum of 4 years of experience in Information Security
•    In lieu of a degree, a minimum of 8 years of experience in Information Security
•    Must demonstrate strong verbal and written communication skills.
•    Must demonstrate excellent leadership, technical teamwork, and interpersonal skills.
•    Must be willing to work in strong team environment, constantly teaching and learning from other team members.
•    Demonstrated ability to foster working relationships with the team, IT Management and Client departments.
•    Demonstrated ability to explain technical concepts to the business users in the context of business requirements.
•    Must demonstrate technical experience including: OT / data / network / computer security design, administration and/or assessment.
•    Must demonstrate broad knowledge of information systems including Windows security, network security, systems development, communication networks, security software/hardware and operating systems.
•    Must have experience with key information security technologies such as SIEM, firewalls, intrusion detection/prevention systems, vulnerability assessment, encryption, identity and access control systems, anti-malware, and security event analysis.
    Must demonstrate strong organizational, managerial, and financial management skills.
•    Must demonstrate the ability to communicate effectively with both technical and non-technical individuals.

•    Experience in Operational Technology (OT) Security is a plus
•    ISC2 Certified Information Systems Security Professional (CISSP) or equivalent
•    Programming Experience in Python

•    Approximately 5% Travel required
•    Please note if NERC CIP position, requires NERC CIP background investigation prior to start


Minimum Years of Experience

4 years of experience




None Noted


Certain positions at the Company may require you to have access to Part 810-Controlled Information.  Under the law, the Company is limited in who it can share this information with and in certain circumstances it is necessary to obtain specific authorization before the Company can share this information.  Accordingly, if the position does require access to this information, you must complete a 10 CFR Part 810 Export Control Compliance Nationality Request Form, a copy of which will be provided to you by Talent Acquisition if an offer is made.  If there is a need for specific authorization, due to the time it takes to obtain authorization from the government, we will likely not be able to further proceed with an offer.

Candidates must foster an inclusive work environment and respect all aspects of diversity. Successful candidates must demonstrate and value differences in others' strengths, perspectives, approaches, and personal choices.

As an employee of PSE&G or PSEG LI, you should be aware that during storm restoration efforts, you may be required to perform functions outside of your routine duties and on a schedule that may be different from normal operations.

Certain positions at the Company may require you to have access to 10 CFR Part 810 controlled information.  If the position does require access to this information, the Talent Acquisition representative will provide further details upon making an offer.

PSEG is an equal opportunity employer, dedicated to a policy of non-discrimination in employment, including the hiring process, based on any legally protected characteristic. Legally protected characteristics include race, color, religion, national origin, sex, age, marital status, sexual orientation, disability or veteran status or any other characteristic protected by federal, state, or local law in locations where PSEG employs individuals.

Business needs may cause PSEG to cancel or delay filling position at any time during the selection process.

This site (http://www.pseg.com) is strictly for candidates who are not currently PSEG employees. PSEG employees must apply for jobs internally through emPower which can be accessed through sharepoint.pseg.com by clicking on the emPower icon, then selecting careers.



PSEG is committed to providing reasonable accommodations to individuals with disabilities.  If you have a disability and need assistance applying for a position, please call 973-430-3845 or email accommodations@pseg.com.  If you need to request a reasonable accommodation to perform the essential functions of the job, email accommodations@pseg.com. Any information provided regarding a disability will be kept strictly confidential and will not be shared with anyone involved in making a hiring decision.



Know your Rights: Workplace Discrimination is Illegal

Pay Transparency Nondiscrimination Provision

Nearest Major Market: New York City

Job Segment: Recruiting, Information Security, Testing, Information Systems, Environmental Engineering, Human Resources, Technology, Engineering