Purpose: This position is responsible for supporting the confidentiality, integrity, and availability of the company’s information assets and meeting NERC CIP Cyber Security compliance. This will be accomplished by:  Developing IT processes and procedures to support NERC CIP cyber security standards  Implementing security technologies and solutions to meet regulatory compliance with NERC CIP cyber security standards  Implementing and supporting IT security technologies, tools, and processes for Generation and Transmission Assets  Providing information security expertise and consulting focused on power plant and substation operations

Education / Experience:  Bachelor’s degree or equivalent experience in a computer or engineering field  Knowledge and understanding of information security concepts and best practices  Familiarity with information security regulation as it applies to the energy and electric utility industry a plus especially NERC CIP and/or NRC  Industry certifications a plus (CISSP, CISA, GIAC, MCITP, CCNP, CCSP)  Experience with one or more of the following: o Network infrastructure o Cisco© network and security infrastructure, specifically ASA, ACS, and CSM o Implementing NERC CIP Cyber Security standards o Developing technical documentation to support NERC CIP Cyber Security compliance  Experience with one or more of the following a plus: o Technical security tools like Tufin, Infoblox, IDS/IPS, antivirus a plus o Modern operating systems, database applications, web applications and other computing technologies o Electric generation or substation business and concepts a plus o Large scale projects with a cross-functional team a plus

Job Responsibilities:  Understand, relate and transform cyber security regulatory requirements into cyber security policy, standards, procedures and guidelines  Evaluate NERC CIP requirements related to Physical Security Perimeter(s) and Electronic Access Point(s) to develop recommendations  Assist in the configuration, deployment and maintenance of the Electronic Access Point(s) required for NERC CIP assets  Assist in the identification and deployment of the Physical Security Perimeter(s) required for NERC CIP assets  Develop documentation required for cyber assets associated with compliance of NERC CIP Cyber Security standards  Assist in the maintenance of the defined NERC CIP repository(s) and compliance tool(s)  Travel on site to plants and substations throughout the Southern Company system to implement security designs  Help customers understand and apply information security concepts, processes and technologies  Maintain current knowledge of information security concepts, technologies and practices  Work closely with Operations Compliance, Generation Technical Services, IT Security, IT Infrastructure Services, Substation Integration & Automation, plant support team members, and customers to ensure all work assignments are completed on time, on budget and with the highest level of quality

Job Requirements:  Strong understanding of compliance requirements which apply to the electric utility industry  Awareness of energy industry trends, opportunities and challenges  Strong technical consulting experience; the ability to understand business requirements and present appropriate solutions  Ability to work within an internal cross-functional team environment to collaborate on project implementations  Demonstrated critical, independent thinking; demonstrated ability to conceive and present creative solutions  Demonstrated people skills that result in successful working relationships with customers, peer team members, and business partners internal and external to Southern Company

Competencies:  Behavior consistent with Southern Style philosophy – Unquestionable Trust, Superior Performance and Total Commitment  Flexibility to quickly adapt to changing requirements and environments  Excellent interpersonal skills; strong oral & written communication skills; able to communicate effectively with all levels of employees, clients and IT management  Ability to convey complex technical issues in business terms  Ability to negotiate and influence others  Ability to function both independently and as a team member  Demonstrated analysis and problem-solving skills  Ability to learn and apply new technologies and concepts  Comprehensive customer service skills  Ability to prioritize work and complete assignments with little direction  Ability to think outside the box by providing innovative, creative solutions to complex issues Must be able to pass Southern Company NERC CIP background requirements and training. This position requires frequent (up to 30%) travel to company locations. Overnight travel is expected.