EMS Compliance Manager
The EMS Compliance Manager is responsible for providing vision, direction, leadership and management for a team of Analysts responsible for Compliance and Quality Assurance for systems critical to the reliable operations of the bulk power system.
The position provides leadership for compliance, testing, QA, cyber security expertise and guidance to minimize risk and protect the confidentiality, integrity, and availability of Transmission’s cyber-related assets.
JOB REQUIREMENTS:
- Bachelor’s or advanced degree in the field of computer science, engineering, information systems and cyber security training, or significant prior experience in information security or information security compliance assurance / auditing required.
- Knowledge, understanding, and experience with NERC CIP Standards, SOX and cyber security audit evidence requirements and best practices required.
- Substantial knowledge and understanding of cyber security concepts and best practices required; CISSP, CISM, or CISA certification preferred.
- Understanding of technology in control systems in real time and near real time environments required.
- Knowledge and understanding of bulk power operations required.
- Knowledge and understanding of disaster recovery and business continuity for real and near real time systems required.
- Experience in developing and monitoring compliance assurance controls for the cyber security and protection of real time operational transmission systems preferred.
- Working knowledge and understanding of existing and emerging technologies and industry cyber security concepts and practices is required. Ability to determine their impact on cyber security compliance risk and their potential applications and compliance controls required.
- Demonstrated ability to provide direction, empower, motivate, and develop others required.
Knowledge, Skills and Abilities:
- Strong oral and written communications skills.
- Strong organizational and documentation skills.
- Strong facilitation & meeting management skills.
- Strong project management experience.
- Strong prioritization and reprioritization skills
- Flexibility, stress tolerance, and integrity
- Ability to communicate issues, policies, and changes clearly, concisely, and effectively at all levels.
- Ability to bring consensus and buy-in among people with different views and agendas and to manage productively in a fast-paced, constantly changing technical environment.
- Ability to manage and prioritize multiple projects and produce timely results.
- Ability to attract, hire, develop and manage a highly effective, diverse workforce of technical individuals highly skilled in required disciplines.
- Ability to establish and maintain excellent working relationships/partnerships with the management team throughout the organization, as well as external peers, strategic vendors and suppliers.
- Ability to present recommendations to executive management and system sponsors and influence outcomes that are beneficial for Southern Company’s Transmission organization.
MAJOR JOB RESPONSIBILITIES:
- Provide consistent ongoing performance feedback, leadership and appropriate developmental opportunities for staff members.
- Manage activities in a manner to ensure success with audits, compliance reviews, and reporting for Sarbanes-Oxley, NERC CIP, and Internal Auditing.
- Lead the periodic review of all EMS policy and procedure documentation. Provide for training as needed for any new or updated policies.
- Ensure data retention/retrieval/access in compliance with FERC orders.
- Manage the organization as a business with emphasis on effective planning, budgeting and cost control that meets customer needs in a changing business environment.
- Review processes and procedures and documentation to identify and implement changes that enhance EMS’s ability to generate consistent Change Control and Configuration Management documentation as part of normal activities.
- Define and implement processes to ensure vendor releases are evaluated, tested and documented in appropriate time frames prior to deployment.
- Ensure coordination across multiple EMS Teams to execute appropriate testing.
- Review and coordinate the evaluation of products and tools which enhance the overall quality assurance and testing program.
- Ensure the design and implementation of long-term strategic goals and short-term tactical plans for EMS Compliance and QA.
- Ensure new products and technologies conform to EMS compliance policies, standards, and best practices.
- Provide leadership for the EMS SOX internal controls testing, external audits, periodic policy compliance reviews and compliance related information collection and dissemination.
- Develop, monitor, and maintain documentation associated with NERC CIP standards compliance to produce and archive consistent and accurate documentation in accordance with EMS and Southern Co policies.
- Provide leadership, research vision, strategic interpretation, and technology development to
- ensure that EMS Systems comply with existing and future NERC CIP requirements and/or other Federal regulations.
- Participate in applicable industry working groups to contribute and influence industry direction.
- Maintain knowledge of information security concepts, technologies and practices.
About Southern Company
Southern Company (NYSE: SO) is a leading energy provider serving 9 million customers across the Southeast and beyond through its family of companies. Providing clean, safe, reliable and affordable energy with excellent service is our mission. The company has electric operating companies in three states, natural gas distribution companies in four states, a competitive generation company, a leading distributed energy solutions provider with national capabilities, a fiber optics network and telecommunications services. Through an industry-leading commitment to innovation, resilience and sustainability, we are taking action to meet customers' and communities' needs while advancing our goal of net-zero greenhouse gas emissions by 2050. Our uncompromising values ensure we put the needs of those we serve at the center of everything we do and are the key to our sustained success. We are transforming energy into economic, environmental and social progress for tomorrow. Our corporate culture has been recognized by a variety of organizations, earning the company awards and recognitions that reflect Our Values and dedication to service. To learn more, visit www.southerncompany.com.
Southern Company invests in the well-being of its employees and their families through a comprehensive total rewards strategy that includes competitive base salary, annual incentive awards for eligible employees and health, welfare and retirement benefits designed to support physical, financial, and emotional/social well-being. This position may also be eligible for additional compensation, such as an incentive program, with the amount of any bonus/awards subject to the terms and conditions of the applicable incentive plan(s). A summary of the benefits offered for this position can be found here https://seo.nlx.org/southernco/pdf/SOCO-Benefits.pdf. Additional and specific details about total compensation and benefits will also be provided during the hiring process.
Skills Required
- Bachelor's or advanced degree in computer science, engineering, information systems, or equivalent prior experience in information security/compliance auditing
- Experience in information security or information security compliance assurance / auditing
- Knowledge and experience with NERC CIP standards, SOX, and cyber security audit evidence requirements and best practices
- Substantial knowledge and understanding of cybersecurity concepts and best practices
- CISSP, CISM, or CISA certification
- Understanding of control system technologies in real-time and near real-time environments
- Knowledge and understanding of bulk power operations
- Knowledge of disaster recovery and business continuity for real and near real time systems
- Experience developing and monitoring compliance assurance controls for cyber security protection of real-time operational transmission systems
- Working knowledge of existing and emerging technologies and industry cyber security concepts and practices, and ability to assess their compliance impact
- Demonstrated ability to provide direction, empower, motivate, and develop others (staff leadership and people management)
- Strong oral and written communication, organizational, facilitation, meeting management, and documentation skills
- Strong project management experience and ability to manage/prioritize multiple projects
- Ability to present recommendations to executive management and influence outcomes
What We Do
Southern Company Services, Inc., headquartered in Birmingham, Alabama, is the shared services division of Southern Company.







