Job Description
Job Description
CIP ANALYST
POSITION DESCRIPTION
Under the direction of the Manager, CIP Compliance, the CIP Analyst is responsible for participating as a compliance monitoring team member in making determinations of compliance with NERC Critical Infrastructure Protection (CIP) Standards and, under certain circumstances, NERC Operations and Planning (O&P) Standards. While this position is posted at the Senior Analyst level, we may consider filling it at the Analyst level depending on the qualifications and experience of the selected candidate.
KEY RESPONSIBILITIES
Evaluates Registered Entity evidence, as an Audit Team member, to determine compliance with applicable NERC CIP Reliability Standards.Serves as the Audit Team Lead when assigned.Reviews the facts and circumstances of audit findings to provide input on initial root cause and risk to the Bulk Power System.Assesses the maturity of Registered Entities internal controls as part of document and evidentiary reviews.Creates sufficient documentation to support NPCC’s compliance determinations and ensures that a complete and final record exists.Supports the Manager, CIP Compliance with the creation and maintenance of compliance monitoring documentation, records, and metrics.Maintains awareness of NERC Rules of Procedure, NERC Reliability Standards, NERC Reliability Standards under development, and related projects and activities.Supports efforts to identify cyber and physical security trends within NPCC, and development of “lessons learned” or other analysis documents.Provides subject matter expertise to the Entity Risk Assessment and Enforcement departments on completed compliance monitoring engagements; assessment and risk of potential non-compliances; and mitigation activities.Provides training, education, and communications to NPCC staff, Registered Entities, and ERO Enterprise staff.Attends ERO compliance monitoring related task forces and working groups.EDUCATION AND CERTIFICATION / LICENSE CREDENTIALS
Bachelor’s degree in Information Systems, Computer Science, Electrical Engineering, or industry-related field of study with 3 or more years related industry experience; or equivalent combination of education and related industry experience showing the ability to perform major duties.3 - 5 years of experience in the electric utility industry or related technical industry in at least one of the following discipline areas :Desktop and systems design
Information security concepts and practicesEMS and SCADA systemsNetworkingSystems architectureWindows and Linux operating systemsNERC CIP standards and related internal controlsNERC / NPCC Compliance Monitoring and Enforcement ProgramsFUNCTIONAL COMPETENCIES
Able to develop and deliver professional presentations.Able to effectively engage and participate in discussions with stakeholders.Ability to work on many projects simultaneously with only periodic guidance.Ability to complete tasks in a timely and efficient manner.Strong verbal and written communication skills, including presentation skills.Strong interpersonal and conflict resolution skills.Strong organizational skills and attention to detail, including project management skills.Strong analytical and problem-solving skills.Strong supervisory and leadership skills.Strong teamwork skills.PHYSICAL REQUIREMENTS
Ability to sit for long periods of time, ability to communicate verbally, and in writing, and ability to handle long periods of screen time.Ability to work and travel within the U.S. and travel to Canada.EEOC AND DISCLAIMER
NPCC is proud to be an Equal Opportunity Employer committed to diversity and inclusion in the workplace. Employment, including the decision to hire, promote, discipline or discharge, will be solely based on competence, performance, and business needs. We prohibit discrimination on the basis of the individual’s actual or perceived disability, protected veteran status, race, color, sex, age, national origin, religion, sexual orientation, gender, gender identity, gender expression, genetic information, marital status, citizenship, domestic violence victim status, or any other status protected under federal, state or local law.