2022 Exelon Hiring Update
Our hiring process looks a bit different today as a result of the COVID-19 pandemic, with virtual interviewing and other solutions in place to facilitate proper social distancing, we remain focused on powering possibilities for new talent who are ready to join us in making a difference.

Exelon was recently separated into two publicly traded companies, Exelon and Constellation. Exelon is the parent company for our fully regulated transmission and distribution utilities, delivering electricity and natural gas to more than 10 million customers. Constellation is the largest supplier of clean energy and sustainable solutions to homes, businesses and public-sector customers across the continental U.S., backed by more than 31,000 megawatts of generating capacity consisting of nuclear, wind, solar, natural gas and hydro assets. If you are looking for career opportunities in commercial, generation or home services, please visit jobs.constellationenergy.com for more information.

Prin OT Cyber Security Architect

This job posting is no longer active.

Location: PHILADELPHIA, PA, United States
Organization: Exelon Business Servcs Co, LLC
Job ID: 246982
Date Posted: Apr 13, 2023
Job: Security

Share: mail

Job Description


We're powering a cleaner, brighter future.

Exelon is leading the energy transformation, and we're calling all problem solvers, innovators, community builders and change makers. Work with us to deliver solutions that make our diverse cities and communities stronger, healthier and more resilient.

We're powered by purpose-driven people like you who believe in being inclusive and creative, and value safety, innovation, integrity and community service. We are a Fortune 200 company, 19,000 colleagues strong serving more than 10 million customers at six energy companies -- Atlantic City Electric (ACE), Baltimore Gas and Electric (BGE), Commonwealth Edison (ComEd), Delmarva Power & Light (DPL), PECO Energy Company (PECO), and Potomac Electric Power Company (Pepco).

In our relentless pursuit of excellence, we elevate diverse voices, fresh perspectives and bold thinking. And since we know transforming the future of energy is hard work, we provide competitive compensation, incentives, excellent benefits and the opportunity to build a rewarding career.

Are you in?


The Principal Operational Technology (OT) Cyber Security Architect (OT PCSA) partners with OT and business teams to provide expert leadership to drive security technology and security reference architecture solutions by weighing the advantages of security technology standards, market availability of products, and risks and benefits of security technology introduction into Exelons computing environments. The OT PCSA provides comprehensive consultation to business units and OT management and staff at the highest technical level for all aspects of the security architecture domain. The OT PCSA develops and maintains business, systems, and OT processes to support enterprise mission needs and requirements; translates technology and environmental conditions (e.g., law and regulation) into OT rules and requirements that describe baseline and target security architectures. The OT PCSA designs enterprise and systems security throughout the development lifecycle; translates technology and environmental conditions (e.g., law and regulation) into security designs and processes. The OT PCSA operates independently with little or no direct supervision.


  • Provide technical and security expertise to OT and business teams to identify security technology solutions and develop security reference architectures and strategies to achieve business results. Ensure appropriate implementation of security technology and reference architectures within both the development and production environments. Analyze user needs and requirements to plan architecture. 
  • Design and develop enterprise-wide security architecture and strategy for all aspects of the security domain in alignment with the business strategy and goals. Develop/integrate cybersecurity designs for systems and networks with multilevel security requirements or requirements. Provide input on security requirements to be included in statements of work and other appropriate procurement documents. 
  • Provide technical guidance and security expertise in the areas of secure application development, security architecture risk management and assessment, security policies and standards, security architectures and implementations. 
  • Provide technology and security expertise and advice to OT leadership in the development of strategic security technology and plans to support business strategies. Translate proposed capabilities into technical requirements. 
  • Establish, maintain, and enhance relationships with business and OT partners. Communicate status to key stakeholders on a regular basis. 
  • Maintain awareness of trends and issues in area of security expertise, evaluate new security technologies or technology opportunities, and provide analysis of their potential impact to advantage the business. 


The OT Principal Cyber Security Architect (OT PCSA) provides cyber and information security architecture expertise in the analysis, assessment, development, and evaluation of security solutions and architectures to secure applications, operating systems, databases, and networks. The OT PCSA develops security architecture requirements, conducts security architecture risk assessments, designs security solutions, evaluates application and system architectures, and develops and reviews appropriate security architecture policies and standards. The OT PCSA leads and manages the cyber and information security architecture aspects of OT and business initiatives and projects to assist in mitigating security risks for operational applications and systems. This role serves as a senior technical staff member who provides technical cyber and information security architecture expertise and guidance to team members and collaborates with other OT teams to address and resolve security issues.


  • Bachelors Degree in Computer Science, Information Technology (IT), or a related discipline, and typically 8 or more years of solid, diverse experience in cyber security architecture and design, or equivalent combination of education and work experience.
  • At least 5 years of demonstrated experience in the energy sector
  • Appropriate technical skills and in-depth knowledge of business unit functions and applications, including:
  • Knowledge of authentication, authorization, and access control methods.
  • Knowledge of computer algorithms
  • Knowledge of encryption algorithms
  • Knowledge of cryptography and cryptographic key management concepts
  • Knowledge of database systems
  • Knowledge of embedded systems
  • Knowledge of system fault tolerance methodologies
  • Knowledge of how system components are installed, integrated, and optimized
  • Knowledge of human-computer interaction principle
  • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
  • Ability to design architectures and frameworks
  • Skill in applying cybersecurity methods, such as firewalls, demilitarized zones, and encryption
  • Knowledge of network access, identity, and access
  • Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services
  • Knowledge of network design processes, to include understanding of security objectives, operational objectives, and tradeoffs
  • Knowledge of parallel and distributed computing concepts
  • Knowledge of key concepts in security management (e.g., Release Management, Patch Management).
  • Knowledge of configuration management techniques
  • Knowledge of cloud computing
  • Comprehensive understanding of change management techniques associated with new technology implementation.
  • Demonstrated experience producing an economic business case.
  • Demonstrated leadership ability.
  • Proven analytical, problem solving, and consulting skills.
  • Excellent communication skills and the proven ability to work effectively with all levels of IT and business management.

  • Graduate degree in cyber security or related area of expertise.
  • Relevant security certifications (CISSP, SABSA, GIAC, GICSP, CSSA, GCIP)
  • At least 5 years of experience as part of an electric utility
  • Appropriate technical skills and in-depth knowledge of business unit functions and applications, including:
  • Demonstrated experience and subject matter knowledge in cyber and information security for applications, web architectures, operating systems, databases, and networks.
  • Demonstrated experience and subject matter knowledge of SCADA, ICS, Distribution Automation, Smart Grid, DMS, and EMS systems architecture.
  • Experience and proven capabilities in application risk assessment, application security architecture development, web application security, and application security testing.
  • Demonstrated experience in security architecture risk assessment, requirements development, secure design analysis, architecture assessment and development, and security testing of applications and systems.
  • Extensive experience developing, evaluating, and implementing cyber and information security architectures, technologies, standards, and practices to secure applications and OT systems.
  • Demonstrated knowledge and experience in the implementation of NIST cyber security framework.
  • Demonstrated experience in addressing regulatory compliance for the security requirements in applicable laws and regulations, such as NERC CIP.
  • Solid understanding and experience with security development lifecycle (SDL) processes for internally developed applications, including the web-based and Internet facing components.
  • Knowledge and experience in application security standards, methodologies, and technologies.
  • Solid capability to assess application and web architectures and operating systems for vulnerabilities and develop appropriate security countermeasures.
  • Solid knowledge and experience with IT security aspects of operating systems, Active Directory, database (SQL) access, LDAP, Microsoft SharePoint, and web server configurations.
  • Experience in assessing, configuring, and testing security applications and systems, such as firewalls, security appliances, IDS/IPS, SSL or TLS, IPSec, and web services security.
  • Ability to demonstrate analytical skills, technical knowledge, and practical application of cyber and information security principles to business leaders and technical staff.

Share: mail

Frequent Job Searches

Recently Viewed Jobs

Most Recent Job Searches

Relevant Jobs

Personalize this site