About the Role
As the NPP technology and cybersecurity SME, you would be the team's authority on how nuclear plant systems work and how NRC cybersecurity requirements apply to them.
Requirements
Key Responsibilities:
Assess existing literature and technical basis on AI/ML use in the nuclear industry and identify representative use cases. The NRC has clarified it wants deeper analysis of a smaller number of use cases rather than a broad survey.
Identify unique cybersecurity considerations: new attack vectors, vulnerabilities, and mitigation strategies for AI/ML in critical digital assets.
Evaluate those considerations against Regulatory Guide 5.71, identifying where controls could be enhanced and where gaps exist.
Contribute to a draft evaluation framework covering criteria for secure AI/ML use, applicable security controls, and any control tailoring. The framework should account for guidance in RG 5.71 and requirements in proposed 10 CFR 73.110.
Contribute to interim letter reports and the final technical letter report.
Qualifications:
Demonstrated experience performing work related to NPP cybersecurity, including regulation, research, evaluation, or implementation of NPP cybersecurity programs
Demonstrated knowledge of NPP systems and the application of cybersecurity programs to those systems
Detailed knowledge of NRC NPP cybersecurity regulations and guidance (10 CFR 73.54, RG 5.71; familiarity with the proposed Part 53 / 73.110 framework is valuable)
Hands-on experience physically working inside a nuclear power plant, not only classroom or desk-based exposure
Direct experience identifying digital assets subject to 10 CFR 73.54
Direct experience mapping those assets against RG 5.71 appendix controls
A track record of producing findings packages delivered to regulatory staff
This experience can come from a consulting firm, a utility, or a lab — what matters is having actually applied these controls in a real plant
Time Commitment & Logistics:
Period of performance: immediately through 26 August 2027
Level of effort: Part-time
Location: Remote with one (1) possible travel to customer site
Clearance/access: No clearance or plant site access is required
About Def-Logix, Inc.
Def-Logix, Inc. is an 8(a)-certified, Veteran-Owned Small Business headquartered in San Antonio, Texas. We specialize in cutting-edge cybersecurity research and development, including offensive and defensive cyber capabilities, custom software engineering, and AI-driven solutions. Our clients include government agencies, defense contractors, and enterprise organizations seeking advanced, tailored cybersecurity solutions.
