Senior NERC CIP Compliance Analyst

Posted 5 Hours Ago
Be an Early Applicant
3 Locations
Hybrid
130K-160K Annually
Senior level
Energy
The Role
Leads NERC CIP cybersecurity compliance at generating stations, including asset and baseline management, audit preparation, access controls, patch management, incident response drills, vulnerability assessments, information protection, supply chain risk, and self-assessments. Serves as the primary site liaison for Regional Entities, coordinates RFIs and remediation, delivers personnel training, maintains evidence, and ensures continuous audit readiness. The role is full-time on-site, involves industrial environments and occasional travel, and requires substantial power utility or industrial cybersecurity experience.
Summary Generated by Built In
The Sr. NERC CIP Compliance Specialist provides critical on-site leadership to protect and maintain the integrity of control and business networks at our Low and medium-impact generating stations. This role drives continuous compliance with NERC CIP cybersecurity standards, leads site security initiatives, and serves as the primary subject matter expert for station personnel. Operating as a key liaison, this position partners with cross-functional stakeholders to enforce a secure operational environment and ensure continuous audit readiness through rigorous evidence management.

Essential Duties and Responsibilities

  • Program Ownership: Build, optimize, and maintain on-site processes and documentation to ensure continuous adherence to NERC CIP standards.
  • Asset & Baseline Management: Maintain accurate cyber asset inventories and manage baseline change control workflows.
  • Audit Leadership: Lead RSAW/ERT preparation and submission for Regional Entity audits, spot checks, and compliance investigations.
  • Access Control: Maintain compliant physical and electronic security perimeters and access controls for all site assets.
  • Routine Compliance: Execute daily, monthly, quarterly, and annual CIP compliance activities in accordance with program procedures.
  • Liaison & RFI Coordination: Serve as the primary site contact for Regional Entities; coordinate cross-functional teams to fulfill RFIs and remediate findings.
  • Training Delivery: Deliver and support mandatory NERC CIP cybersecurity compliance training programs for site personnel.
  • Patch Management: Direct the end-to-end patch management lifecycle, ensuring BES Cyber Assets are monitored and updated within regulatory timelines.
  • Incident Response & Drills: Lead the annual testing, documentation, and reporting of the Cyber Security Incident Response Plan (CIP-008) and Recovery Plans (CIP-009).
  • Vulnerability Assessments (CIP-010): Orchestrate annual Critical Vulnerability Assessments (CVAs) while ensuring zero adverse impact to operational BES infrastructure.
  • Information Protection: Oversee the identification, classification, and secure handling of Bulk Electric System (BES) Cyber System Information (BCSI) to prevent unauthorized disclosure.
  • Supply Chain Risk (CIP-013): Lead supply chain risk assessments and collaborate with procurement/legal to enforce cybersecurity contract clauses.
  • Self-Assessments & Mitigation: Conduct proactive internal compliance self-assessments; manage the identification, self-logging, and mitigation of compliance deviations.

Qualifications and Skills

  • Bachelor’s degree in Engineering, Computer Science, IT, Cybersecurity, or a related technical discipline (equivalent direct experience considered).
  • Minimum of 5–10 years of professional experience in regulatory compliance, power utility operations, or industrial cybersecurity.
  • At least 5 years of hands-on experience implementing and managing a NERC CIP compliance program across Medium or High-impact assets.
  • Demonstrated success drafting RSAWs, preparing ERT responses, and managing RFIs during Regional Entity audits or spot-checks.
  • Deep operational understanding of the 35-day patch/baseline lifecycle (CIP-007/010), security perimeters (CIP-005/006), and supply chain management (CIP-013).
  • Ability to successfully pass a mandatory NERC CIP-004 Personnel Risk Assessment and background check.
  • Ability to work full-time on-site at the designated facility, travel up to 25% as needed, and safely navigate physical plant environments.
  • Ability to perform physical job duties, including lifting to 25 pounds, climbing, bending, and working in industrial environments (Use of PPE is required).
  • Preferred Skills and Certifications

  • Prior experience working directly within a power generation plant, transmission control center, or EMS/GMS environment.
  • NERC Certified Compliance Professional (NCCP) designation.
  • CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), or CISM (Certified Information Security Manager).
  • SANS GIAC certifications, specifically GCIP (GIAC Critical Infrastructure Protection) or GICSP (Global Industrial Cyber Security Professional).
  • Established working relationships and direct audit experience with our specific Regional Entity (e.g., SERC, WECC, NPCC, RF, MRO, Texas RE).
  • Commitment to cybersecurity excellence and regulatory compliance is a must.

Applicants must possess a valid driver's license and maintain a clean driving record, as this position requires occasional travel for company business. Candidates should be comfortable operating a vehicle as part of their job responsibilities and must meet any applicable company and insurance requirements.

CAMS offers a variety of excellent benefits. Full-time employees are offered the following: medical, dental, vision, LTD, STD, and Life insurance plans. You can even select additional “a la carte” benefits to meet all your needs. You can also enroll in our 401k, flex spending accounts for medical and childcare needs, and participate in our employee referral and tuition reimbursement programs.

Qualified Applicants must be legally authorized for employment in the United States. Qualified Applicants will not require employer sponsored work authorization now or in the future for employment in the United States.

We believe in transparency and providing candidates with important information to make informed decisions. The salary range for this position is commensurate with experience, qualifications, and location. Actual compensation will be determined based on several factors, including but not limited to skills, experience, and relevant qualifications.

This range represents the base salary and does not include other forms of compensation, such as bonuses, benefits, or equity, which may be offered in addition to the base pay. The company reserves the right to modify compensation ranges at any time in accordance with business needs and market conditions.

Skills Required

  • Bachelor’s degree in Engineering, Computer Science, IT, Cybersecurity, or a related technical discipline, or equivalent direct experience
  • 5-10 years of professional experience in regulatory compliance, power utility operations, or industrial cybersecurity
  • At least 5 years of hands-on experience implementing and managing NERC CIP compliance programs across Medium- or High-impact assets
  • Experience drafting RSAWs, preparing ERT responses, and managing RFIs during Regional Entity audits or spot-checks
  • Operational understanding of NERC CIP patch and baseline lifecycle, security perimeters, and supply chain requirements
  • Ability to pass a mandatory NERC CIP-004 Personnel Risk Assessment and background check
  • Ability to work full-time on-site at the designated facility
  • Ability to travel up to 25% as needed
  • Ability to navigate physical plant environments and perform duties involving lifting up to 25 pounds, climbing, and bending
  • Valid driver’s license and clean driving record
  • Prior experience in a power generation plant, transmission control center, or EMS/GMS environment
  • NERC Certified Compliance Professional designation
  • CISSP, CISA, or CISM certification
  • SANS GIAC GCIP or GICSP certification
  • Direct audit experience with the applicable Regional Entity
  • Legal authorization to work in the United States without current or future employer sponsorship
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Houston, TX
1,077 Employees
Year Founded: 2007

What We Do

Consolidated Asset Management Services, LLC (CAMS) provides disciplined and diligent asset management and operations services. As one of the highest quality, lowest cost providers of asset management services in the industry, we contribute significantly to our clients’ bottom line results. We maximize the value of our clients’ assets by providing superior operational performance, tactical commercial optimization and strict financial controls. CAMS employs methodical and proven processes while exercising informed decision-making. Our experienced team treats every asset under our management as if it were our own. At CAMS, we have a reputation for being creative implementers, flexible problem-solvers, and responsive troubleshooters. If there is an opportunity, we recognize and seize it. If there is a problem, we identify and solve it.

Similar Jobs

Octus Logo Octus

Operations Associate

Fintech • News + Entertainment • Software • Database • Financial Services
Easy Apply
Hybrid
New York, NY, USA
808 Employees
63K-70K Annually

CoreWeave Logo CoreWeave

Senior Special Projects Manager

Cloud • Information Technology • Machine Learning
In-Office
2 Locations
1450 Employees
149K-198K Annually

Headway Logo Headway

Senior Engineering Manager

Consumer Web • Healthtech • Professional Services • Social Impact • Software
In-Office
3 Locations
819 Employees
265K-332K Annually

ServiceNow Logo ServiceNow

Enterprise Sales Director - Telecommunications

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Hybrid
New York, NY, USA
29000 Employees
171K-240K Annually

Similar Companies Hiring

UL Solutions Thumbnail
Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Chicago, IL
15000 Employees
Runwise Thumbnail
Greentech • Hardware • Real Estate • Software • Energy • PropTech
New York, NY
199 Employees
Energy CX Thumbnail
Greentech • Professional Services • Business Intelligence • Consulting • Energy • Financial Services • Utilities
Chicago, IL
108 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account