waypointjobs

TerraForm Power

Engineer/Senior Engineer, Firewall

new york, NY

Check who can apply and the requirements below before continuing.

About this opportunity

TerraForm Power lists this Engineer/Senior Engineer, Firewall opportunity in new york, New York. Review the employer’s description below for duties, qualifications and application requirements.

Job description

Overview

Location: TerraForm Power Remote Operation Center, Albany NY

Employment Type: Full-time

Travel: Ability to travel to remote sites (10–20%)

About Us

TerraForm Power (“TERP”), a platform company of Brookfield, attracts high-performing individuals who are driven to make an impact in a fast-paced and collaborative environment. We offer unparalleled opportunities to lead and manage one of the largest renewable energy businesses with decades of history, while contributing to the global need for sustainable energy.

The company is committed to employee development, encouraging curiosity, ownership, and continuous learning. You’ll be empowered to take initiative, contribute ideas, and grow your career within a supportive and ambitious organization. This position will be based in remote.

Job Summary

This is an Operational Technology (OT) role embedded in the TerraForm Power Remote Operations Centre, responsible for designing, implementing, and maintaining secure network perimeters for wind, solar, and battery storage operations with a focus on NERC CIP compliant architecture. The Firewall Engineer will work in close partnership with the TERP Cybersecurity Manager, Compliance and Operations Centre staff to ensure robust, compliant, and resilient OT network security across all sites and control centers.

Responsibilities

Architecture, Design & Implementation

Design and implement OT network security controls, such as perimeter firewalls, internal segmentation, site‑to‑site and remote‑access VPNs, and WAFs.

Build secure network solutions that align with system architecture for wind, solar, and BESS facilities, EMS/SCADA, and the system control centers.

Define network security zones and conduits for OT, corporate IT, and cloud environments; enforce least privilege and micro‑segmentation.

Engineer solutions using Cisco (ASA/Firepower/FTD) and Check Point (CCSA/CCSE) platforms; integrate with management consoles and policy orchestration tools.

Implement secure remote access for operators, vendors, and field technicians using MFA, bastion/Jump hosts, and role‑based access.

Operations, Monitoring & Incident Response

Administer firewall policies, objects, NAT, routing (OSPF/BGP), and HA/cluster configurations; manage rule lifecycle and clean‑up.

Maintain WAF protections (e.g., F5, Fortinet, Check Point, or cloud WAF) including rule tuning, bot mitigation, and API security.

Operate and improve monitoring and control tools (SIEM/SOAR, NetFlow, packet capture, IDS/IPS); build dashboards and alerts for NERC systems.

Conduct log analysis, threat hunting, and participate in incident triage and response; provide on‑call support for critical events.

Perform regular firewall health checks, performance tuning, firmware/OS upgrades, and vulnerability remediation.

Support occasional after‑hours maintenance windows on an as needed basis.

Compliance & Change Management (NERC Focus)

Implement and maintain controls aligned to NERC CIP standards applicable to Low Impact sites and Medium Impact control centers (e.g., CIP‑003, CIP‑005, CIP‑007, CIP‑008, CIP‑009, CIP‑010, CIP‑011, CIP‑013).

Serve as the technical owner for firewall‑related CIP controls (for example CIP‑005, CIP‑007, CIP‑010), including configuration baselines, access controls, logging, and evidence collection.

Establish and enforce configuration baselines, access controls, evidence collection, and audit‑ready documentation.

Run structured change management programs for firewall and WAF policies, including risk assessment, testing, approvals, and post‑implementation review.

Support audits, self‑assessments, and impact ratings; assist with personnel risk assessment and vendor risk management where applicable.

Collaborate with OT, IT, Compliance, Engineering, and Plant Operations to ensure controls meet operational needs without compromising reliability.

Collaborative Responsibilities

Work in close partnership with the TERP Cybersecurity Manager to align firewall, VPN, and WAF controls with OT/IT cybersecurity strategy, incident response protocols, and compliance requirements.

Participate in joint incident response, risk assessments, and continuous improvement initiatives with the Cybersecurity Manager and Operations Centre leadership.

Coordinate with Operations Centre, plant operators, and engineering teams to ensure security controls support operational reliability and compliance.

Technology Evaluation & Continuous Improvement

Evaluate new firewall, WAF, VPN, and OT security technologies; lead POCs and make data‑driven recommendations.

Identify opportunities to enhance resilience (segmentation, Zero Trust, SD‑WAN security, secure cloud connectivity), and automate repeatable tasks (e.g., policy linting, backup/restore, compliance evidence collection).

OT-Specific Duties

Manage vendor and contractor access for maintenance and commissioning, ensuring robust controls for temporary access and logging.

Design solutions that address site-specific challenges, including limited bandwidth, remote access constraints, and environmental factors.

Support operational resilience by coordinating change windows with grid operations and implementing failsafe configurations to avoid plant outages.

Education & Certifications

Bachelor’s degree in Computer Science, Electrical/Computer Engineering, Information Security, or related field; or equivalent experience.

Relevant certifications preferred:

• Cisco: CCNP Security, CCIE (Security) (plus)

• Check Point: CCSA/CCSE

• Others, a plus

Industry‑Specific (Renewable Energy & OT/ICS) Requirements

Experience with the secure transport of with SCADA/EMS, plant DCS/RTUs/PLCs, and OT protocols (OPC, DNP3, Modbus).

Understanding of interconnections between substations, collector systems, BESS EMS, and corporate networks; secure data flows to forecasting, trading, and asset performance platforms.

Knowledge of telecom links common in renewables (leased lines, microwave, LTE/private cellular) and secure backhaul to control centers.

Awareness of site conditions (limited bandwidth, remote access constraints, environmental factors) and designing resilient, maintainable solutions.

Vendor and contractor access management for maintenance, OEM support, and commissioning activities, with strong control over temporary access and logging.

Safety and reliability mindset: change windows coordinated with grid operations, rollback plans, and fail‑safe configurations to avoid plant outages.

Compensation: $120,000-$140,000 USD, bonus eligible

#J-18808-Ljbffr

Worksite address

new york, NY, 10261, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

Annapurna Labs (u.s.) Inc.

WhatJobs

PD Engineer, Annapurna Labs

cupertino, CA

Salary not specified

As a member of the Cloud-Scale Machine Learning Acceleration team you'll be responsible for the design and optimization of Hardware in our data c…

Last received from source 2026-10-07View job

Amazon.com Services Llc - A57

WhatJobs

Senior Automation Engineer

suffolk, VA

Salary not specified

Operations is at the heart of Amazon's business. We are known for our speed, accuracy, and exceptional service. Our buildings deliver tens of tho…

Last received from source 2026-10-07View job

Annapurna Labs (u.s.) Inc.

WhatJobs

DFT Design Engineer, Machine Learning Acceleration

austin, TX

Salary not specified

Custom SoCs (System on Chip) are at the heart of AWS Machine Learning servers. As a member of the Cloud-Scale Machine Learning Acceleration team,…

Last received from source 2026-10-07View job