Jobs · OTHR · Texas

Director, NERC CIP Compliance

NRG Energy · Texas, United States · Yesterday
OTHRFull-time

Job Summary

This position is part of the Regulatory Compliance team within the NRG Legal Department. NERC CIP Regulatory Compliance executes on the implementation of a framework to ensure OT security practices remain observant of all compliance directives, specifically the NERC Critical Infrastructure Protection (CIP) Standards. This role owns program governance and oversight, standards interpretation, internal control development and testing, evidence collection and verification, and corrective action implementation and tracking. This position serves as the primary Subject Matter Expert for all applicable NERC CIP requirements and ensures adoption of emergent and ever-changing cyber security regulations while working to continually strengthen NRG’s audit-ready regulatory compliance posture.

Responsibilities

  • Provide oversight for all aspects of the NERC CIP program and maintain a strong compliance posture by ensuring that all periodic requirements, reviews, testing, and evidence collection activities are completed timely and in a manner that ensures a constant state of audit readiness.
  • Act as the primary Regulatory Compliance liaison with auditors, regulators, and all company stakeholders for NERC CIP matters.
  • Interpret NERC CIP and other applicable cyber security standards and evaluate the business implications of existing, new, and revised NERC, Regional, Federal (CISA, TSA, etc.) standards; coordinate reviews of new/revised standards with internal stakeholders and formulate collective feedback to be provided to appropriate regulatory bodies.
  • Manage the NERC standards development process and act as the company’s primary voting/balloting representative for all matters CIP.
  • Serve as the primary point of contact for all NERC CIP-related compliance matters and act as a trusted advisor across Plant Management, Plant NERC Compliance, IT, Engineering, Commercial Operations, Enterprise Security, and OT Security to ensure strict compliance with NERC CIP standards.
  • Monitor and assist in the development of internal controls necessary to maintain adherence to NERC CIP requirements, internal policies, and other applicable cyber security standards.
  • Assess compliance evidence gathered by technical subject matter experts to determine applicability and completeness and demonstrate compliance to NERC and Regional Regulatory bodies.
  • Identify and investigate potential anomalies and/or non-compliances and escalate, as necessary; perform root cause analyses and develop corrective actions to mitigate the potential reoccurrence of near-misses and/or non-compliances.
  • Prepare and submit self-reports as necessary.
  • Partner closely with OT Security, Plant Operations, Commercial Operations, and Enterprise Security in the development of any policies, procedures, plans, or work instructions necessary to support NERC, Regional, and Federal (CISA, TSA, etc.) standards.
  • Create and maintain metrics and reporting mechanisms that provide leadership with clear visibility into the status of the NERC CIP program, including compliance statuses, trends, risks, and any remediation efforts.
  • Prepare, draft, and coordinate all materials responsive to self-certifications, spot checks, audits (internal and external), Inherent Risk Assessments, Entity Risk Profile Questionnaires, and other Requests for Information.
  • Create and maintain defensible, repeatable processes necessary to achieve a high standard of both compliance and audit-readiness for the company.
  • Conduct periodic CIP compliance assessments of NRG’s program and accompanying internal documentation, identify and communicate any potential deficiencies, areas for continuous improvement, and/or other findings.
  • Complete compliance reviews (including zero-day compliance evaluations), evidence gathering, and holistic gap analyses pertaining to any asset acquisitions, divestitures or new asset CIP impact categorizations.
  • Perform other duties as assigned by Sr. Director, Regulatory Compliance – Head of NERC Compliance.

Qualifications

  • Bachelor’s degree in computer science, cyber security, business administration, or related field. Experience may be considered in lieu of college degree requirement.
  • At least 8-10 years of direct work experience in regulatory compliance, audit, or cyber security within the electric utility or IPP sector.
  • Proven experience implementing, managing, and/or maintaining a CIP program for an integrated utility or IPP.
  • Demonstrated comprehension of the NERC CIP standards; experience writing audit-ready policies and procedures for a NERC CIP program; experience with the NERC CIP audit process, including drafting RSAWs, preparing evidentiary documentation, and presenting to regulators.
  • Ability to translate regulatory requirements and technical controls into easily understood concepts and effectively communicate such concepts across stakeholders at all levels.
  • Assertive, results-driven leader with a strong attention to detail that takes ownership of a program, requires minimal oversight, and is adept at problem solving.
  • Analytical self-starter that exercises sound business judgment and excels in a fast-paced, high pressure, multi-task environment.
  • Experience interfacing directly with and presenting to external regulators (NERC, ReliabilityFirst, TexasRE, SERC, etc.).
  • Experience with NERC-specific tools, such as Align, SEL, SBS, etc.; experience with compliance management software/GRC tools, such as Sigmaflow or RSA Archer.
  • Professional certification such as CISA, CISM, CISSP, or CRISC (preferred).
  • Understanding of one or more of the following cyber security frameworks: NIST CSF, ISO 27001, NIST 800-53, COBIT, HITRUST.
  • Familiarity with networking, change management, anti-malware, configuration baselines, patching or other OT security practices. Knowledge of firewalls, switches, routers, IPS/IDS, Windows, Unix/Linux operating systems.
  • Strong organizational and project management skills.
  • Strong interpersonal skills, including the ability to facilitate, coordinate and lead work teams.
  • Proficiency in Microsoft Office Suite software (Word, PowerPoint, Excel).

Similar jobs

Director, NERC Compliance

Southwest Power PoolLittle Rock, AR· 2 mo ago
Management$175k–$231k/yrapply on recruiting2.ultipro.com