SCS Technology Security
Enterprise Security Architecture
Cybersecurity Solution Architect
Schedule: M-F
Location: Primarily remote/hybrid 20% in office – Atlanta or Birmingham
Position Summary:
Southern Company, a major U.S. energy firm, is seeking an experienced security architect and technical leader, to design creative solutions and reduce risk. The candidate will directly support the company’s efforts to mitigate real and potential cyber threats to the company’s facilities, personnel, technology, operations, and brand – including critical electric and gas utility infrastructure and its privately owned telecommunications network. In this role, the potential for individual impact is substantial and has high visibility within the corporate leadership and governance.
This role will have responsibility for designing and implementing technology and processes that support the strategic direction for the Enterprise Security Architecture team. This role will focus on modern network and infrastructure security and execute projects that align with the strategic roadmap. Interested applicants should be well rounded in their understanding and application of different security and technology platforms; in areas such as identity, networking, endpoint, data, monitoring, cloud, and/or application security. Qualified candidates need to be able to align strategy and execution to increase cybersecurity maturity, anticipate future requirements for complex traditional, hybrid, and multi-cloud environments, drive initiatives via influence and relationships into business processes, keep up with current security trends, be focused on results, and be a self-starter.
This position is responsible for ensuring the confidentiality, integrity, and availability of the company’s information assets. This will be accomplished by:
- Establishing and implementing an information security framework and technical architecture.
- Designing, developing, and implementing information security solutions.
- Driving modern network and infrastructure security practices, such as IaC, SDN, SSE, etc.
- Providing information security expertise and consulting.
While Southern Company is headquartered in Atlanta, we bring energy to homes and businesses across the country. We’ve made our name as a leading producer of clean, safe, reliable, and affordable energy, and we approach each day as a vital step in building the future of energy. We’re always looking ahead, and our innovations in the industry—from new nuclear to deployment of electric transportation and renewables —help brighten the lives and businesses of millions of customers nationwide. Our team is critical to building the future of energy with secure, resilient, and sustainable cyber solutions.
Job Responsibilities:
- Design and implement guardrails to secure modern networking and infrastructure via automation with tools such as Ansible/Python, Puppet/Ruby, PowerShell, Terraform, or similar.
- Continuously seek opportunities to enhance the security posture of network-based technologies, including but not limited to: Secure Service Edge (SSE), Software-Defined Networking (SDN), and Infrastructure as Code (IaC).
- Align forward thinking strategy with business goals to integrate and raise the bar on security practices and solutions.
- Assist in the ongoing development of Southern Company’s security architecture – identify areas of opportunity, research alternatives, and recommend solutions.
- Develop creative solutions to meet business needs while ensuring appropriate security controls and best practices are implemented.
- Partner with others to identify and resolve information security issues.
- Plan, coordinate, and lead information security projects.
- Help customers understand and apply information security concepts, processes, and technologies.
- Maintain current knowledge of information security concepts, technologies, and practices.
- Mentor others to strengthen cybersecurity principles and best practices to outside operational areas.
- Establish and maintain excellent working relationships and partnerships across the Technology Organization, business partners, and external vendors and suppliers.
- Create an environment that fosters accountability, innovation, and engagement at all levels.
Requirements and qualifications:
Minimum
- Hands on experience with modern networking and infrastructure software and tools such as Ansible/Python, Puppet/Ruby, PowerShell, Terraform, etc.
- Working knowledge of Network Overlay/SDN Overlay design and practice.
- Management of Infrastructure as Code (IaC) and associated tooling.
- Hands-on experience designing, architecting, and implementing various information security tools/products such as PKI, Static or Dynamic Code Analysis, Next-Generation Firewalls, HSM’s, SIEM, Multi-Factor Authentication, IPS, Database Encryption, Privileged Identity Management, Cloud Posture Management, etc.
- Competency in APIs (Rest, Graph) and/or JavaScript/JSON/Kubernetes/SQL.
- Experience promoting security as a business enablement function using influence, metrics, documentation, strong verbal communication, and presentation skills.
- Working knowledge of cloud and traditional security network architectures.
- Ability to lead a project from concept through implementation and anticipate potential problems.
- Experience prioritizing and executing with minimal direction or oversight.
- Ability to perform detailed information security risk assessments and recommend mitigating controls.
- Must pass NERC CIP & Insider Threat Protection background checks.
Preferred Qualifications
- Experience with software development and programing.
- Technical knowledge of application development practices, CI/CD pipelines, various cloud platforms including Azure, AWS, or GCP, modern operating systems, networking protocols and designs, and identity management.
- Proficiency in one or more coding languages, such as C#, Python, Java, or Java Script
- Azure certifications preferred.
- Industry certifications such as: CISSP, CCSP, CISA, GIAC, OSCP, CRISC, CCNP, etc.
- At least 5 years of experience playing a key role in building technical programs.
- Experience with information security frameworks such as: NIST, OWASP, etc.
- Familiarity with nation state, sophisticated criminal, and supply chain threats.
- Up-to-date knowledge of current hacking techniques, vulnerability disclosures, and data breach incidents.
- Experience with cybersecurity analysis and analytic tradecraft.