Posting Title
ETAC Threat Analysis Researcher
.
Location
CO - Golden
.
Position Type
Regular
.
Hours Per Week
40
.
Working at NREL
The National Renewable Energy Laboratory (NREL), located at the foothills of the Rocky Mountains in Golden, Colorado is the nation's primary laboratory for research and development of renewable energy and energy efficiency technologies.
From day one at NREL, you’ll connect with coworkers driven by the same mission to save the planet. By joining an organization that values a supportive, inclusive, and flexible work environment, you’ll have the opportunity to engage through our ten employee resource groups, numerous employee-driven clubs, and learning and professional development classes.
NREL supports inclusive, diverse, and unbiased hiring practices that promote creativity and innovation. By collaborating with organizations that focus on diverse talent pools, reaching out to underrepresented demographics, and providing an inclusive application and interview process, our Talent Acquisition team aims to hear all voices equally. We strive to attract a highly diverse workforce and create a culture where every employee feels welcomed and respected and they can be their authentic selves.
Our planet needs us! Learn about NREL’s critical objectives, and see how NREL is focused on saving the planet.
Note: Research suggests that potential job seekers may self-select out of opportunities if they don't meet 100% of the job requirements. We encourage anyone who is interested in this opportunity to apply. We seek dedicated people who believe they have the skills and ambition to succeed at NREL to apply for this role.
Job Description
The Cybersecurity Threat Analysis Group (CTAG), within NREL’s Energy and Security Resilience Center, performs research to better understand the threats, detection strategies and mitigation opportunities for renewable energy infrastructure and distributed energy resources. Our efforts include technical assessments of existing technologies and near-term innovations, research into Industrical Control Systems (ICS) communications technologies, network architectures and protocols, as well as informing the development and application of cybersecurity frameworks and policy. CTAG researchers collaborate with government and industry partners to contribute to a more secure and resilient renewable energy infrastructure with global impact.
Cybersecurity Threat Analysis Group cybersecurity researchers perform hands-on technical research and assessments. Researchers have the opportunity to drive NREL research in ICS security as well as help build a red team capability to support a rapidly growing cybersecurity portfolio. Team members work alongside current NREL cybersecurity research staff to utilize the best-in-class Cyber Range to deploy applicable large scale test environments, perform hardware-in-the-loop technology assessments, research into ICS threats, detection, and mitigation as it pertains to renewable energy. Research will span across ICS and renewable energy technologies and include collaboration and partnership with utility and cyber security solution providers as well as government stakeholders.
The CTAG group has a need for a cybersecurity research team member who will provide support of real world threat analysis for the Energy Threat Analysis Center (ETAC). The successful candidate will be a key member of the ETAC team and collaborate with threat emulation team members, analysis and reporting researchers, power systems engineers, and the NREL cyber range team. Beyond ETAC, the candidate will have the opportunity to contribute to a variety of cybersecurity research efforts and develop experience with a wide range of virtualization, orchestration and threat emulation tools.
Responsibilities at either level:
Create and support threat emulation plans in relation to current threat actor campaigns
Collaborate with colleagues to develop and deploy complex virtual environments including communications, power systems, hardware-in-the-loop and security technologies
Coordinate with NREL cyber range team to ensure virtual environment networkconnectivity, operation, and reliability
Assist analysis and reporting team in the creation of deliverables to appropriate sponsors
Create memos, hunting guides and other communication vehicles in support of the ETAC
Additional responsibilities for Level III Include:
Leading, tasking and advising leadership on cost schedule performance
Mentoring Jr staff members
Developing statements of work
Presenting to customers
.
Basic Qualifications
Researcher III - Relevant PhD . Or, relevant Master's Degree and 3 or more years of experience . Or, relevant Bachelor's Degree and 5 or more years of experience . Demonstrates broad understanding and wide application of engineering technical procedures, principles, theories and concepts in the field. General knowledge of other related disciplines. Demonstrates leadership in one or more areas of team, task or project lead responsibilities. Demonstrated experience in management of projects. Very good writing, interpersonal and communication skills.
Researcher II - Relevant Master's Degree . Or, relevant Bachelor's Degree (preferred) and 2 or more years of experience . Or, relevant cybersecurity program and certification(s). General knowledge and application of engineering technical standards, principles, theories, concepts and techniques. Training in team, task or project leadership responsibilities. Intermediate abilities and knowledge of practices and techniques. Beginning experience in project management. Good writing, interpersonal and communication skills.
Must be able to obtain and maintain a security clearance.
Eligibility requirements: To obtain a clearance, an individual must be at least 18 years of age; U.S. citizenship is required except in very limited circumstances. See DOE O 472.2A for additional information.
* Must meet educational requirements prior to employment start date.
Additional Required Qualifications
Preferred Qualifications
Experience with threat emulation frameworks such as MITRE ATT&CK and Atomic Red Team
•Experience working with orchestration tools and virtualized environments such as Docker, KVM hypervisor & Packer image creator
Experience with Git and utilizing CI/CD pipelines Knowledge of mimimega and phenix VM orchestration tools
Experience with Elasticsearch, Kafka or MongoDB or MySQL
Experience with Windows system administration and network configuration
.
Job Application Submission Window
The anticipated closing window for application submission is up to 30 days and may be extended as needed.
Annual Salary Range (based on full-time 40 hours per week)
Job Profile: Researcher III / Annual Salary Range: $79,600 - $143,300
Job Profile: Researcher II / Annual Salary Range: $73,200 - $120,800
NREL takes into consideration a candidate’s education, training, and experience, expected quality and quantity of work, required travel (if any), external market and internal value, including seniority and merit systems, and internal pay alignment when determining the salary level for potential new employees. In compliance with the Colorado Equal Pay for Equal Work Act, a potential new employee’s salary history will not be used in compensation decisions.
Benefits Summary
Benefits include medical, dental, and vision insurance; short- and long-term disability insurance; pension benefits; 403(b) Employee Savings Plan with employer match; life and accidental death and dismemberment (AD&D) insurance; personal time off (PTO) and sick leave; paid holidays; and tuition reimbursement. NREL employees may be eligible for, but are not guaranteed, performance-, merit-, and achievement- based awards that include a monetary component. Some positions may be eligible for relocation expense reimbursement. Limited-term positions are not eligible for long-term disability or tuition reimbursement.
* Based on eligibility rules
Drug Free Workplace
NREL is committed to maintaining a drug-free workplace in accordance with the federal Drug-Free Workplace Act and complies with federal laws prohibiting the possession and use of illegal drugs. Under federal law, marijuana remains an illegal drug.
If you are offered employment at NREL, you must pass a pre-employment drug test prior to commencing employment. Unless prohibited by state or local law, the pre-employment drug test will include marijuana. If you test positive on the pre-employment drug test, your offer of employment may be withdrawn.
Submission Guidelines
Please note that in order to be considered an applicant for any position at NREL you must submit an application form for each position for which you believe you are qualified. Applications are not kept on file for future positions. Please include a cover letter and resume with each position application.
.
EEO Policy
NREL is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard basis of age (40 and over), color, disability, gender identity, genetic information, marital status, domestic partner status, military or veteran status, national origin/ancestry, race, religion, creed, sex (including pregnancy, childbirth, breastfeeding), sexual orientation, and any other applicable status protected by federal, state, or local laws.
EEO is the Law (http://www.dol.gov/ofccp/regs/compliance/posters/ofccpost.htm) | Pay Transparency Nondiscrimination (https://www.dol.gov/ofccp/pdf/pay-transp_English_unformattedESQA508c.pdf) | Reasonable Accommodations (http://www.nrel.gov/careers/employment-policies.html)
E -Verify www.dhs.gov/E-Verify For information about right to work, click here (http://www.justice.gov/sites/default/files/crt/legacy/2013/08/13/FinalOSCPosterEN08_01_2013.pdf) for English or here (http://www.justice.gov/crt/file/813271/download) for Spanish.
E-Verify is a registered trademark of the U.S. Department of Homeland Security. This business uses E-Verify in its hiring practices to achieve a lawful workforce.
The National Renewable Energy Laboratory (NREL) is a leader in the U.S. Department of Energy’s effort to secure an environmentally and economically sustainable energy future. With locations in Golden and Boulder, Colorado, and a satellite office in Washington, D.C., NREL is the primary laboratory for research, development, and deployment of renewable energy technologies in the United States.
NREL is subject to Department of Energy (DOE) access restrictions. All candidates must be authorized to access the facility per DOE rules and guidance within a reasonable time frame for the specified position in order to be considered for an interview. DOE rules for site access during the interview process are the same regardless of whether the candidate is interviewed on-site, off-site, or via telephone or videoconference. Additionally, DOE contractor employees are prohibited from participating in certain Foreign Government Talent Recruitment Programs (FGTRPs). If a candidate is currently participating in an FGTRP, they will be required to disclose their participation after receiving an offer of employment and may be required to disengage from participation in the FGTRP prior to commencing employment. Any offer of employment is conditional on the ability to obtain work authorization and to be granted access to NREL by the Department of Energy (DOE).
Drug Free Workplace
NREL is committed to maintaining a drug-free workplace in accordance with the federal Drug-Free Workplace Act and complies with federal laws prohibiting the possession and use of illegal drugs. Under federal law, marijuana remains an illegal drug.
If you are offered employment at NREL, you must pass a pre-employment drug test prior to commencing employment. Unless prohibited by state or local law, the pre-employment drug test will include marijuana. If you test positive on the pre-employment drug test, your offer of employment may be withdrawn.
Please review the information on our Hiring Process (https://www.nrel.gov/careers/hiring-process.html) website before you create an account and apply for a job. We also hope you will learn more about NREL (https://www.nrel.gov/about/) , visit our Careers site (https://www.nrel.gov/careers/) , and continue to search for job opportunities (https://nrel.wd5.myworkdayjobs.com/NREL) at the lab.