×
Register Here to Apply for Jobs or Post Jobs. X

Engineer​/Senior Engineer, Firewall

Job in New York, New York County, New York, 10261, USA
Listing for: Brookfield Renewable US
Full Time position
Listed on 2026-01-14
Job specializations:
  • Engineering
    Cybersecurity, Systems Engineer
Job Description & How to Apply Below
Location: New York

Engineer/Senior Engineer, Firewall

Location:

Terra Form Power Remote Operation Center, Albany NY

Employment Type:

Full-time

Travel:
Ability to travel to remote sites (10–20%)

About Us

Terra Form Power (“TERP”), a platform company of Brookfield, attracts high-performing individuals who are driven to make an impact in a fast-paced and collaborative environment. We offer unparalleled opportunities to lead and manage one of the largest renewable energy businesses with decades of history, while contributing to the global need for sustainable energy.

The company is committed to employee development, encouraging curiosity, ownership, and continuous learning. You’ll be empowered to take initiative, contribute ideas, and grow your career within a supportive and ambitious organization. This position will be based in remote.

Job Summary

This is an Operational Technology (OT) role embedded in the Terra Form Power Remote Operations Centre, responsible for designing, implementing, and maintaining secure network perimeters for wind, solar, and battery storage operations with a focus on NERC CIP compliant architecture. The Firewall Engineer will work in close partnership with the TERP Cybersecurity Manager, Compliance and Operations Centre staff to ensure robust, compliant, and resilient OT network security across all sites and control centers.

Responsibilities

Architecture, Design & Implementation
  • Design and implement OT network security controls, such as perimeter firewalls, internal segmentation, site‑to‑site and remote‑access VPNs, and WAFs.
  • Build secure network solutions that align with system architecture for wind, solar, and BESS facilities, EMS/SCADA, and the system control centers.
  • Define network security zones and conduits for OT, corporate IT, and cloud environments; enforce least privilege and micro‑segmentation.
  • Engineer solutions using Cisco (ASA/Firepower/FTD) and Check Point (CCSA/CCSE) platforms; integrate with management consoles and policy orchestration tools.
  • Implement secure remote access for operators, vendors, and field technicians using MFA, bastion/Jump hosts, and role‑based access.
Operations, Monitoring & Incident Response
  • Administer firewall policies, objects, NAT, routing (OSPF/BGP), and HA/cluster configurations; manage rule lifecycle and clean‑up.
  • Maintain WAF protections (e.g., F5, Fortinet, Check Point, or cloud WAF) including rule tuning, bot mitigation, and API security.
  • Operate and improve monitoring and control tools (SIEM/SOAR, Net Flow, packet capture, IDS/IPS); build dashboards and alerts for NERC systems.
  • Conduct log analysis, threat hunting, and participate in incident triage and response; provide on‑call support for critical events.
  • Perform regular firewall health checks, performance tuning, firmware/OS upgrades, and vulnerability remediation.
  • Support occasional after‑hours maintenance windows on an as needed basis.
Compliance & Change Management (NERC Focus)
  • Implement and maintain controls aligned to NERC CIP standards applicable to Low Impact sites and Medium Impact control centers (e.g., CIP‑003, CIP‑005, CIP‑007, CIP‑008, CIP‑009, CIP‑010, CIP‑011, CIP‑013).
  • Serve as the technical owner for firewall‑related CIP controls (for example CIP‑005, CIP‑007, CIP‑010), including configuration baselines, access controls, logging, and evidence collection.
  • Establish and enforce configuration baselines, access controls, evidence collection, and audit‑ready documentation.
  • Run structured change management programs for firewall and WAF policies, including risk assessment, testing, approvals, and post‑implementation review.
  • Support audits, self‑assessments, and impact ratings; assist with personnel risk assessment and vendor risk management where applicable.
  • Collaborate with OT, IT, Compliance, Engineering, and Plant Operations to ensure controls meet operational needs without compromising reliability.
Collaborative Responsibilities
  • Work in close partnership with the TERP Cybersecurity Manager to align firewall, VPN, and WAF controls with OT/IT cybersecurity strategy, incident response protocols, and compliance requirements.
  • Participate in joint incident response, risk assessments, and continuous…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary