About Stem - Driven by human and artificial intelligence – Stem is unlocking energy intelligence. Stem is a global leader reimagining technology to support the energy transition. Turning complexity into clarity, and potential into performance. We help asset owners, operators and stakeholders benefit from the full value of their energy portfolio by enabling the intelligent development, deployment, and operation of clean energy assets. Our integrated software suite, PowerTrack, is the industry standard and best-in-class for asset monitoring, supported by professional and managed services, under one roof. Meant to tackle challenges as seamlessly as possible, Stem shows the information needed clearly and accurately and helps harness raw data to inform actionable insight. With global projects managed in 55 countries – from Germany to Japan and across North America – customers have relied on Stem for nearly 20 years to maximize the value of their clean energy projects. Stem’s culture embodies diversity & inclusion beyond the traditional facets of gender, ethnicity, age, disabilities, and sexual orientation to include experience, personality, communication, work styles, and more. At our core, Stem is at the momentous intersection of clean energy and software technology where diverse ideas, experiences, and professional skills converge to make the inclusive culture we have today. Together, we are turning old school thoughts about software and energy into progressive, collaborative, and innovative solutions. By joining our team, you will be collaborating with data scientists, energy experts, skilled salespeople, thought-leading executives and more from a range of backgrounds. This intersection of ideas, beliefs, and skills is what makes us unique enough to lead the world’s largest network of digitally connected energy storage systems. About the Role: The Staff Network Engineer is the senior technical authority for the network and OT cybersecurity architecture underlying STEM's PowerTrack platform for grid-connected battery energy storage and solar sites. This role owns the design, evolution, and field implementation of STEM's five-tier Layered Cybersecurity Architecture international standard requirements. The Staff Network Engineer leads high-visibility initiatives, including cybersecurity development efforts, sets technical direction for the broader development, design, and project engineering teams, and represents STEM in customer, vendor, and audit-facing conversations on network security architecture. Responsibilities: Owns and evolves STEM's Layered Cybersecurity Architecture across the product lines, ensuring segmentation, zone/conduit design, and architecture remain current against ISO/IEC 27001, IEC 62443, and NERC CIP. Leads design, configuration, and troubleshooting of network infrastructure including dual Palo Alto firewall deployments, Moxa managed switch segmentation, and DMZ Server/Jump Host configurations. Directs the technical design and field rollout of the Operational Technology (OT) Server (SIEM and backup-server functions) and Intrusion Detection System (IDS) capabilities in STEM’s architecture, including log correlation/alerting pipelines, Syslog and time-series archiving (Synology NAS), and protocol-aware passive network monitoring across DNP3, Modbus, IEC 61850, IEC 60870, and OPC UA. Serves as senior technical lead on vendor RFPs and evaluations for OT/IT network security capabilities (SIEM, IDS, firewall, DMZ infrastructure), authoring technical scope and requirements, scoring proposals against compliance and architecture criteria, and leading vendor selection and onboarding. Designs and maintains Interactive Remote Access, jump-server-mediated access models, Domain Controller/identity management, patch management (WSUS), and malware protection to satisfy CIP-005 R2 and CIP-007 R2/R3/R5. Leads security event monitoring, Internal Network Security Monitoring (INSM), and backup/recovery architecture to meet CIP-007 R4, CIP-009, and CIP-015 obligations for Medium and High Impact Bulk Electric System (BES) Cyber Systems. Partners with Product, Compliance, and customer-facing teams to translate NERC CIP, IEC 62443, and ISO/IEC 27001 requirements into deployable network architecture, and advises customers and account teams on the appropriate tier for a given site. Provides technical leadership, design review, and mentorship for various team members, including architecture review and onboarding support. Leads root-cause analysis and remediation for complex network security incidents, escalations, and audit findings across the customer fleet, coordinating with Engineering, Field Service, Support, and Security teams. Drives standardization of network architecture patterns, zone/conduit mapping, and compliance cross-reference documentation for reuse across customer engagements, RFPs, and future architecture tiers. Represents STEM’s network security architecture in customer, vendor, and auditor-facing conversations, including NERC CIP audit support as needed. Supports critical-site commissioning and escalations, with occasional travel up to 20% of the time. Other duties as assigned. Technical Knowledge: 8+ years of network engineering experience, including experience architecting and securing OT/ICS or industrial control system networks. Deep working knowledge of NERC CIP standards (CIP-002, CIP-004, CIP-005, CIP-007, CIP-009, CIP-010, CIP-015), with hands-on experience supporting compliance audits for Medium and/or High Impact BES Cyber Systems. Expert-level knowledge of IEC 62443 zone/conduit architecture and Security Level target definitions. Working knowledge of ISO/IEC 27001 Annex A controls, particularly those governing monitoring, backup, network segregation, and access/identity management. Hands-on experience configuring and hardening enterprise/industrial firewalls (Palo Alto preferred) and managed switch infrastructure (Moxa or equivalent) for zone segmentation. Experience designing or deploying SIEM platforms (log collection, correlation, alerting, retention) and IDS/INSM solutions in OT/ICS environments, including protocol-aware detection. Experience with jump-server/bastion-mediated remote access architectures, Domain Controller/identity management, patch management (e.g., WSUS), and malware protection at scale. Experience with DMZ architecture design, including single and redundant (dual-DMZ) topologies. Familiarity with Industrial SCADA/EMS platforms; Inductive Automation’s Ignition platform and cloud-based site monitoring platforms are a plus. Experience with SQL databases and time-series/log data stores (e.g., Synology, InfluxDB, or equivalent). Competency in scripting or programming for network automation and tooling (Python, PowerShell, or similar). Experience integrating industrial networking hardware, serial communications, and virtualization technologies. Demonstrated experience leading vendor RFP processes, technical evaluations, and cross-functional stakeholder alignment. Qualifications : Bachelor’s degree in engineering, computer science, network engineering, or a related field, and a minimum of 8 years of relevant experience, or an equivalent combination of education and experience. Relevant certifications a plus (e.g., CISSP, GICSP, CCNP, PCNSE). Demonstrated ability to operate as a senior technical authority with minimal supervision, setting technical direction for a team or program area. Strong written and verbal communication skills; able to translate complex network security and compliance concepts for technical and non-technical audiences, including executives, customers, and auditors. Proven mentorship and technical leadership experience. Ability to manage multiple concurrent, high-visibility initiatives and drive them to completion with minimal oversight. Location : Hybrid in our Broomfield, CO office Please Note: Applicants must be legally authorized for full-time employment in the United States without the need for current or future employer-sponsored work authorization. The Company cannot offer employment for this role to F-1 (student) visa holders who require employer sponsorship in the future or cannot work now on a full-time basis. To learn more about Stem, visit our stem.com where you’ll find information about our solutions, technology, partners, case studies, resources, latest news and more. Here are some relevant links: Company Overview Newsroom Insights LinkedIn What We Offer: At Stem, you will work in a growing, innovative, mission-driven company with talented colleagues that have a passion for building renewable energy systems. Stem offers competitive compensation as well as a comprehensive set of benefits to support the health and wellness of our employee including: A competitive compensation package, including eligibility for a bonus or commission based on the role. Full health benefits on the first day of employment (several medical plan options-HDHP and PPO, dental plans, FSA/HSA-with employer contribution, employer paid vision/LTD/STD/Life, variety of voluntary coverage) 401k (pre- or post-tax) on first day of employment 12 paid calendar holidays per year Flexible time-off Stem, Inc . is an equal opportunity employer committed to diversity in the workplace and does not discriminate against any employee or applicant for employment because of race, color, sex, pregnancy, religion, national origin, ethnicity, citizenship, sexual orientation, gender identity, age, marital status, disability, genetic information, military status, protected veteran status or any other factor protected by applicable federal, state or local laws.
Network Engineer 3
Huntington
Senior Network Engineer
Ford
Network Engineers, Senior Engineers & Architects (CBP)
Agile Defense
Senior Network Engineer
Vamonos IT
Network Automation Engineer II
Astreya
Network Operations Engineer
John Staurulakis (jsitel.com)