Role Overview
Duke Energy is hiring a mid-level Cybersecurity Firewall Analyst. This is a full-time role in Charlotte. Part of Duke Energy's Risk hiring, posted yesterday. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Salary Context
Salary is not disclosed in this posting. Market median for Mid-level Risk roles is $100k-$140k (based on 315 comparable listings). Many employers share specifics during the interview process or after an initial screen.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Job description
Important Application Submission Information
In order to ensure your application is successfully received before the job posting expires, please submit your application by 11:59 PM on Saturday, August 1, 2026More than a career - a chance to make a difference in people's lives.
Build an exciting, rewarding career with us – help us make a difference for millions of people every day. Consider joining the Duke Energy team, where you'll find a friendly work environment, opportunities for growth and development, recognition for your work, and competitive pay and benefits.
Position Summary
The Cybersecurity Network Defense Analyst (CNDA) is responsible for protecting Operational Technology (OT) environments, including substation networks, against unauthorized cyber activity through the governance, validation, and continuous monitoring of network defense controls. This role ensures that security technologies, access controls, and network segmentation strategies are implemented and maintained in alignment with NERC CIP standards (e.g., CIP-005, CIP-007, CIP-010), TSA Security Directives, SOX controls, and PCI-DSS requirements.
The CNDA operates within a compliance-driven, risk-based framework, with primary accountability for independent validation and oversight of firewall configurations, rule changes, and network security controls. This includes reviewing and approving firewall rule sets, verifying adherence to least privilege and segmentation requirements, and ensuring all changes are properly authorized, documented, and auditable. The role emphasizes control effectiveness validation rather than direct implementation, ensuring separation of duties and alignment with audit expectations.
This position supports OT/substation defense operations by maintaining strong visibility into Electronic Security Perimeters (ESPs), External Routable Connectivity (ERC), and access pathways into critical infrastructure environments. Responsibilities include control testing, evidence generation, and audit support, as well as identifying and remediating compliance gaps through structured corrective actions. In addition, the CNDA contributes to incident response, event analysis, and service disruption investigations, performing root cause analysis with a focus on control effectiveness and preventive improvements. The role actively participates in CIP-010 baseline management and change validation processes, ensuring that all network security modifications are properly assessed, validated, and reflected in system baselines. The CNDA also supports project-based initiatives related to substation defense, firewall deployments, and network segmentation enhancements, providing oversight to ensure solutions are implemented in accordance with regulatory requirements and internal security standards. This includes maintaining accurate documentation and artifacts required to demonstrate compliance during internal and external audits. Candidates with a strong background in network engineering, OT networking, or infrastructure design who are transitioning into cybersecurity will be considered, particularly those with the ability to apply technical expertise within a highly regulated, audit-focused environment.
Responsibilities
Perform day-to-day oversight and validation of firewall policy administration, including review, approval, and lifecycle management of network access control rules on specialized cyber defense systems
Review, validate, and govern network access control lists (ACLs) to ensure alignment with least privilege, segmentation requirements, and regulatory expectations
Participate in security improvement and optimization initiatives, providing recommendations to enhance control effectiveness, resiliency, and compliance posture
Maintain accurate and up-to-date documentation of network security infrastructure, configuration changes, and security strategies to support audit readiness and operational transparency
Develop and support testing and validation procedures for network security controls, ensuring changes are properly assessed and meet compliance requirements prior to implementation
Collaborate with security architecture and engineering teams to interpret, apply, and enforce security requirements within OT and substation environments
Provide oversight of network defense system lifecycle activities (installation, configuration, testing, and maintenance), ensuring implementations meet regulatory and internal standards
Support and provide regulatory guidance for project-based firewall and network security deployments
Proactively identify security risks, control gaps, and compliance issues, and recommend corrective actions aligned with NERC CIP, TSA, SOX, and PCI requirements
Participate in or lead MREE and TSA audit requests and interviews.
Required/Basic Qualifications
Bachelors degree in Computer Science, Cybersecurity, Information Technology, or Other Related Degree
2 years related work experience
In lieu of Bachelors degree(s) AND 2 year(s) related work experience listed above, High School/GED AND 6 year(s) related work experience
Desired Qualifications
CCNP and/or CISSP and/or GCIH and/or GIAC Information Security Professional and/or CompTIA Security+ and/or SANS
Additional Preferred Qualifications
Experience in Cybersecurity preferably with firewall and proxy technology, event logging and detection mechanisms. Knowledge of foundational computer elements from the operating system, TCP/IP, routing and network topology.
Knowledge of cybersecurity and privacy principles.
Knowledge of the application firewall concepts and functions (e.g., Single point of authentication/audit/policy enforcement, message scanning for malicious content, data anonymization for PCI and PII compliance, data loss protection scanning, accelerated cryptographic operations, SSL security, REST/JSON processing).
Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
Skill in configuring and utilizing network protection components (e.g., Firewalls, VPNs, network intrusion detection systems).
Skill in performing packet-level analysis.
Ability to apply network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
Knowledge of web filtering technologies
Diagnose and resolve customer reported system incidents, problems, and events.
Direct background or exposure to cyber security operations
Experience with IDPS functionality.
Experience with Palo Alto Firewalls.
1-5 years of relevant work experience in Information Technology.
Compliance experience (PCI/SOX).
Experience with Syslog, TACACS, Radius, and SNMP.
Ability to perform self-directed work.
Experience in networking protocols: DNS, HTTP, SSL, SMTP, TCP
Experience working with Hardware Security Models
Experience in Web security and compliance experience (e.g., Firewalls, IDS/IPS systems, DDOS prevention and PCI, HIPAA, FIPS, etc.)
Strong Linux or Windows system administrator skills
Working Conditions
Hybrid Mobility Classification – Work will be performed from both remote and onsite locations after the onboarding period. However, hybrid employees should live within a reasonable daily commute to a Duke Energy facility.
Office Environment
On Call Rotation
Event Response
Occasional Minor lifting at the waist of 25-50 pounds
Travel Requirements
5-15%Relocation Assistance Provided (as applicable)
NoRepresented/Union Position
NoVisa Sponsored Position
No. This is not a Visa Sponsored Position. This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future.Please note that in order to be considered for this position, you must possess all of the basic/required qualifications.
Privacy
Do Not Sell My Personal Information (CA)
Terms of Use
Accessibility
About Duke Energy
Duke Energy
duke-energy.com
30 other open roles at Duke Energy on TryApplyNow.
Frequently Asked Questions
How do I apply for the Cybersecurity Firewall Analyst position at Duke Energy?
Use the Apply button above to submit your application directly to Duke Energy. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Where is the Cybersecurity Firewall Analyst position at Duke Energy located?
This position is based in Charlotte. Duke Energy has not indicated remote or hybrid options for this role, so candidates should plan for on-site work.
What does a Cybersecurity Firewall Analyst at Duke Energy earn?
Duke Energy has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the Cybersecurity Firewall Analyst role at Duke Energy posted?
This role was posted on July 22, 2026 (yesterday). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
Similar Jobs
Continuous Improvement Project Manager
Achieve
Senior Data Scientist (Credit Risk)
Achieve
Risk Analyst
Deluxe
Pre-Sales Solution Specialist, Treasury & Payments
Fidelity National Information Services
Simulator Operations Technical Training Specialist
Boeing
More Jobs at Duke Energy
View all →AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get started freeNo credit card to start