CybersecurityJobs.io
← Back to all jobs

Job Description

Support NERC Critical Infrastructure Protection (CIP) compliance and OT cybersecurity for reliable electric generation and power operations.

Responsibilities

  • Own and support day-to-day NERC CIP compliance activities across applicable standards, including:
    • BES Cyber System identification and categorization
    • Security management controls
    • Personnel and training
    • Electronic and physical access
    • System security management
    • Incident response and recovery
    • Configuration management
    • Vulnerability assessments
    • Information protection
    • Communications
    • Supply chain risk management
  • Maintain accurate inventories and classifications for:
    • BES Cyber Systems and BES Cyber Assets
    • Electronic Access Control or Monitoring Systems
    • Physical Access Control Systems
    • Protected Cyber Assets
    • Related infrastructure
  • Develop, implement, and maintain NERC CIP policies, procedures, technical standards, control narratives, and evidence packages that are clear, repeatable, and aligned with operating practices.
  • Coordinate recurring compliance activities such as:
    • Access reviews
    • Account management
    • Patch evaluations
    • Malicious code prevention
    • Security event monitoring
    • Ports and services reviews
    • Backup and recovery testing
    • Vulnerability assessments
    • Change-control evidence
  • Prepare for and support internal assessments, mock audits, spot checks, self-certifications, data requests, and regulatory audits by organizing evidence, validating completeness, identifying gaps, and tracking corrective actions to closure.
  • Partner with plant operations, controls, electrical engineering, IT, legal, physical security, and compliance to resolve findings while managing operational risk.
  • Conduct OT cybersecurity risk assessments and design reviews for control systems, generation assets, plant networks, remote access, vendor connections, and new projects or modifications.
  • Apply secure architecture and defense-in-depth in industrial environments including network segmentation, firewalls, jump hosts, identity and access management, logging, time synchronization, endpoint controls, backup and recovery, and secure remote access.
  • Support cybersecurity incident response and recovery exercises covering OT and applicable NERC CIP reporting, escalation, evidence preservation, and lessons learned.
  • Evaluate vendors and service providers for NERC CIP supply chain risk; document security requirements and support contract, procurement, and remote-access reviews.
  • Monitor changes to NERC CIP standards, implementation plans, guidance, and enforcement trends; assess organizational impact and plan timely implementation, including emerging internal network security monitoring needs.
  • Mentor technical and compliance stakeholders, deliver role-based training, and promote respectful collaboration, accountability, and continuous improvement.

Requirements

  • Minimum 7 years of experience in operational technology, industrial control systems, electric utility cybersecurity, regulatory compliance, or a closely related field.
  • Minimum 5 years of direct, hands-on experience implementing, operating, assessing, or auditing NERC CIP compliance controls in an electric utility, generation, transmission, balancing authority, or similarly regulated environment.
  • Working knowledge of NERC CIP standards, including interpreting requirements, implementation guidance, evidence expectations, and applicability within real operating environments.
  • Ability to build and maintain audit-quality evidence, compliance calendars, control ownership, gap assessments, remediation plans, and management reporting.
  • Practical knowledge of OT/ICS technologies including DCS, SCADA, PLCs, HMIs, historians, engineering workstations, relays, plant networks, industrial protocols, and vendor remote-access solutions.
  • Understanding of OT network architecture and security controls including TCP/IP, routing, switching, VLANs, firewalls, Active Directory, authentication, logging, vulnerability management, and backup and recovery.
  • Ability to work safely around critical infrastructure and operating generation facilities, balancing cybersecurity and compliance objectives with availability, reliability, and safety requirements.
  • Strong written and verbal communication skills; sound judgment; attention to detail; ability to explain regulatory and technical issues to technical and nontechnical stakeholders.
  • Ability to manage multiple priorities, work independently, collaborate across disciplines, and travel to project or plant locations as required.
  • Bachelor’s degree in cybersecurity, information systems, computer science, electrical engineering, controls engineering, or a related technical discipline is preferred, not required. Equivalent combinations of relevant OT, electric-sector, NERC CIP, military, apprenticeship, and industry experience will be considered; advanced technical training or an associate degree with substantial hands-on experience is acceptable.

Technologies

  • NERC Critical Infrastructure Protection (CIP)
  • BES Cyber System, BES Cyber Assets
  • Electronic Access Control or Monitoring Systems, Physical Access Control Systems
  • Protected Cyber Assets
  • DCS, SCADA, PLCs, HMIs, historians, engineering workstations, relays
  • TCP/IP, routing, switching, VLANs, firewalls
  • Active Directory, authentication, logging
  • Vulnerability management, backup, recovery
  • Network segmentation, jump hosts, identity and access management
  • Time synchronization, endpoint controls, secure remote access
  • Malicious code prevention, security event monitoring
  • Ports and services reviews, change-control evidence
  • Security information and event management, asset discovery, privileged access, configuration monitoring
  • NIST Cybersecurity Framework, NIST SP 800-82
  • ISA/IEC 62443
  • CISA guidance
  • GICSP, GRID, CISSP, CISM, CRISC, CISA
  • NERC compliance credentials

Benefits

  • Medical, dental, vision, and basic life insurance
  • 401(k) plan
  • Paid time off
  • Ability to purchase company stock at a discount
  • Eligible employees may also enroll in a deferred compensation plan or the Executive Deferral Plan
  • Merit increases, performance discretionary bonus, and stock (certain roles may be eligible)

Location and Setup

  • Houston, Texas, United States
  • Office/Onsite
  • Industry: Advanced Manufacturing

Compensation

  • Base salary range: USD 150,000 to 175,000 per year
  • Posted salary range minimum: 150,000.00
  • Posted salary range upper: 175,000.00

Posted

  • Job posted on August 28, 2026
  • Open for at least 3 days

Preferred Qualifications

  • Experience with NERC compliance monitoring and enforcement processes, Regional Entity engagements, Reliability Standard Audit Worksheets, self-certifications, spot checks, or formal audits.
  • Experience supporting Generator Owner and Generator Operator functions, including gas turbine, steam turbine, reciprocating engine, renewable, battery storage, microgrid, or behind-the-meter generation environments.
  • Experience with OT security monitoring, asset discovery, security information and event management, privileged access, vulnerability assessment, and configuration monitoring technologies.
  • Familiarity with NIST Cybersecurity Framework, NIST SP 800-82, ISA/IEC 62443, CISA guidance, and risk-based security program development.
  • Relevant certifications such as GICSP, GRID, CISSP, CISM, CRISC, CISA, ISA/IEC 62443, or comparable NERC compliance credentials.
  • Experience leading projects, mentoring team members, or coordinating multidisciplinary remediation efforts.

Similar Jobs