Senior OT Cybersecurity Specialist - NERC CIP
Job Description
Support NERC Critical Infrastructure Protection (CIP) compliance and OT cybersecurity for reliable electric generation and power operations.
Responsibilities
- Own and support day-to-day NERC CIP compliance activities across applicable standards, including:
- BES Cyber System identification and categorization
- Security management controls
- Personnel and training
- Electronic and physical access
- System security management
- Incident response and recovery
- Configuration management
- Vulnerability assessments
- Information protection
- Communications
- Supply chain risk management
- Maintain accurate inventories and classifications for:
- BES Cyber Systems and BES Cyber Assets
- Electronic Access Control or Monitoring Systems
- Physical Access Control Systems
- Protected Cyber Assets
- Related infrastructure
- Develop, implement, and maintain NERC CIP policies, procedures, technical standards, control narratives, and evidence packages that are clear, repeatable, and aligned with operating practices.
- Coordinate recurring compliance activities such as:
- Access reviews
- Account management
- Patch evaluations
- Malicious code prevention
- Security event monitoring
- Ports and services reviews
- Backup and recovery testing
- Vulnerability assessments
- Change-control evidence
- Prepare for and support internal assessments, mock audits, spot checks, self-certifications, data requests, and regulatory audits by organizing evidence, validating completeness, identifying gaps, and tracking corrective actions to closure.
- Partner with plant operations, controls, electrical engineering, IT, legal, physical security, and compliance to resolve findings while managing operational risk.
- Conduct OT cybersecurity risk assessments and design reviews for control systems, generation assets, plant networks, remote access, vendor connections, and new projects or modifications.
- Apply secure architecture and defense-in-depth in industrial environments including network segmentation, firewalls, jump hosts, identity and access management, logging, time synchronization, endpoint controls, backup and recovery, and secure remote access.
- Support cybersecurity incident response and recovery exercises covering OT and applicable NERC CIP reporting, escalation, evidence preservation, and lessons learned.
- Evaluate vendors and service providers for NERC CIP supply chain risk; document security requirements and support contract, procurement, and remote-access reviews.
- Monitor changes to NERC CIP standards, implementation plans, guidance, and enforcement trends; assess organizational impact and plan timely implementation, including emerging internal network security monitoring needs.
- Mentor technical and compliance stakeholders, deliver role-based training, and promote respectful collaboration, accountability, and continuous improvement.
Requirements
- Minimum 7 years of experience in operational technology, industrial control systems, electric utility cybersecurity, regulatory compliance, or a closely related field.
- Minimum 5 years of direct, hands-on experience implementing, operating, assessing, or auditing NERC CIP compliance controls in an electric utility, generation, transmission, balancing authority, or similarly regulated environment.
- Working knowledge of NERC CIP standards, including interpreting requirements, implementation guidance, evidence expectations, and applicability within real operating environments.
- Ability to build and maintain audit-quality evidence, compliance calendars, control ownership, gap assessments, remediation plans, and management reporting.
- Practical knowledge of OT/ICS technologies including DCS, SCADA, PLCs, HMIs, historians, engineering workstations, relays, plant networks, industrial protocols, and vendor remote-access solutions.
- Understanding of OT network architecture and security controls including TCP/IP, routing, switching, VLANs, firewalls, Active Directory, authentication, logging, vulnerability management, and backup and recovery.
- Ability to work safely around critical infrastructure and operating generation facilities, balancing cybersecurity and compliance objectives with availability, reliability, and safety requirements.
- Strong written and verbal communication skills; sound judgment; attention to detail; ability to explain regulatory and technical issues to technical and nontechnical stakeholders.
- Ability to manage multiple priorities, work independently, collaborate across disciplines, and travel to project or plant locations as required.
- Bachelor’s degree in cybersecurity, information systems, computer science, electrical engineering, controls engineering, or a related technical discipline is preferred, not required. Equivalent combinations of relevant OT, electric-sector, NERC CIP, military, apprenticeship, and industry experience will be considered; advanced technical training or an associate degree with substantial hands-on experience is acceptable.
Technologies
- NERC Critical Infrastructure Protection (CIP)
- BES Cyber System, BES Cyber Assets
- Electronic Access Control or Monitoring Systems, Physical Access Control Systems
- Protected Cyber Assets
- DCS, SCADA, PLCs, HMIs, historians, engineering workstations, relays
- TCP/IP, routing, switching, VLANs, firewalls
- Active Directory, authentication, logging
- Vulnerability management, backup, recovery
- Network segmentation, jump hosts, identity and access management
- Time synchronization, endpoint controls, secure remote access
- Malicious code prevention, security event monitoring
- Ports and services reviews, change-control evidence
- Security information and event management, asset discovery, privileged access, configuration monitoring
- NIST Cybersecurity Framework, NIST SP 800-82
- ISA/IEC 62443
- CISA guidance
- GICSP, GRID, CISSP, CISM, CRISC, CISA
- NERC compliance credentials
Benefits
- Medical, dental, vision, and basic life insurance
- 401(k) plan
- Paid time off
- Ability to purchase company stock at a discount
- Eligible employees may also enroll in a deferred compensation plan or the Executive Deferral Plan
- Merit increases, performance discretionary bonus, and stock (certain roles may be eligible)
Location and Setup
- Houston, Texas, United States
- Office/Onsite
- Industry: Advanced Manufacturing
Compensation
- Base salary range: USD 150,000 to 175,000 per year
- Posted salary range minimum: 150,000.00
- Posted salary range upper: 175,000.00
Posted
- Job posted on August 28, 2026
- Open for at least 3 days
Preferred Qualifications
- Experience with NERC compliance monitoring and enforcement processes, Regional Entity engagements, Reliability Standard Audit Worksheets, self-certifications, spot checks, or formal audits.
- Experience supporting Generator Owner and Generator Operator functions, including gas turbine, steam turbine, reciprocating engine, renewable, battery storage, microgrid, or behind-the-meter generation environments.
- Experience with OT security monitoring, asset discovery, security information and event management, privileged access, vulnerability assessment, and configuration monitoring technologies.
- Familiarity with NIST Cybersecurity Framework, NIST SP 800-82, ISA/IEC 62443, CISA guidance, and risk-based security program development.
- Relevant certifications such as GICSP, GRID, CISSP, CISM, CRISC, CISA, ISA/IEC 62443, or comparable NERC compliance credentials.
- Experience leading projects, mentoring team members, or coordinating multidisciplinary remediation efforts.