Manager, OT Security & Compliance at LS Power Development, LLC | Texas | Rezi

Manager, OT Security & Compliance at LS Power Development, LLC

Manager, OT Security & Compliance

LS Power Development, LLC · Texas

1 months ago

Manager, OT Security & Compliance

LS Power Development, LLC · Texas

2 months ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

LS Power Grid is seeking an Manager of OT Security & Compliance to lead two closely aligned teams within our Operations Technology organization: the OT Compliance Engineering team, responsible for operating and maintaining our core security tooling, and the OT Governance, Risk & Compliance (GRC) team, responsible for the policy framework, risk management, and regulatory compliance program that governs our OT environment. A defining expectation for this role is the ability to bridge technical and non-technical worlds with equal precision, engaging directly with engineers on tool configurations and with senior leadership, regulators, or auditors to communicate subject matter in terms of business risk, program posture, and organizational impact.

Responsibilities

  • Directly manage a team of OT Compliance Engineers responsible for operating Splunk, Nessus/Tenable, and Tripwire in production OT environments.
  • Ensure tool outputs are fully operationalized: alerts are triaged and actioned, vulnerability findings are tracked through remediation, configuration baselines are enforced, and compliance evidence is generated consistently and on schedule.
  • Set performance expectations, conduct regular 1:1s and formal reviews, and develop engineers from compliance executors into deeper program owners with domain expertise.
  • Build a team culture of documentation discipline and continuous audit readiness; establish and maintain evidence quality standards so the program is always prepared.
  • Identify gaps in tooling coverage or team capability and develop justified proposals for headcount, tooling, or process improvements.
  • Lead audit preparation and direct engagement with TRE, FERC, and NERC; serve as the primary signatory and point of contact for all regulatory correspondence and submissions.
  • Own the full violation management lifecycle — self-identification, mitigation documentation, and corrective action plan development and tracking through closure.
  • Own end-to-end compliance with CIP-006, CIP-007, CIP-008, CIP-010, and CIP-011; serve as the authoritative interpreter of CIP requirements.
  • Monitor NERC, TRE, and FERC regulatory developments; assess impact of new or revised standards and drive program updates ahead of enforcement deadlines.
  • Directly manage a team of OT GRC Analysts responsible for policy management, risk assessment, control framework maintenance, audit evidence coordination, and regulatory reporting.
  • Own the OT GRC program end-to-end: policy library, standards, control framework, risk register, exception management, and governance reporting cadences.
  • Maintain a living OT security risk register; ensure risks are formally assessed, assigned to owners, tracked to resolution, and reported to leadership with clear business context and recommended disposition.
  • Develop and enforce OT security policies and procedures that satisfy regulatory obligations and are written to be operationally executable.
  • Support multi-entity expansion and new facility onboarding: manage compliance readiness for PSP and ESP certifications, NERC registration, and regulatory filings with long lead-time coordination across legal, engineering, and operations.
  • Communicate OT Security & Compliance topics effectively at every level of the organization: giving precise technical direction to engineers, coordinating with peer teams, and delivering clear business-risk framing to senior leadership.
  • Translate technical findings into language that non-technical stakeholders can act on, without sacrificing accuracy or context.
  • Serve as the organizational voice in external regulatory interactions, including TRE audit engagements, NERC inquiry responses, and FERC filings.
  • Produce written communications across a wide range of formats and audiences: regulatory correspondence, executive briefings, team-facing work instructions, and vendor accountability documentation.

Requirements

  • 5+ years of progressive OT or ICS cybersecurity experience, with direct ownership of a NERC CIP compliance program at a registered entity and a demonstrated record of successful audit outcomes.
  • Formal designation or functional experience as a manager or compliance program authority, with firsthand experience managing regulatory interactions with TRE, FERC, or NERC.
  • Direct, production hands-on experience operating Splunk, Nessus or Tenable, and Tripwire or equivalent security tooling in OT or ICS environments.
  • Proven experience directly managing both a technical operations team and an analyst/GRC team, including hiring, performance management, and developing staff into program ownership.
  • Demonstrated ability to communicate technical OT Security & Compliance topics with equal clarity to engineers, peer managers, auditors, and executive leadership — adjusting framing and depth without losing accuracy.
  • Strong working knowledge of CIP-006, CIP-007, CIP-008, CIP-010, and CIP-011, with the ability to interpret requirements, identify gaps, and build controls that satisfy both regulatory intent and operational reality.
  • Experience building and maintaining GRC program components: risk registers, control frameworks, policy libraries, and exception management workflows.
  • Excellent written communication skills across multiple document types: regulatory submissions, executive summaries, work instructions, and compliance evidence documentation.
  • 7+ years of experience in OT/ICS cybersecurity or critical infrastructure protection, with at least 3 years in a compliance program leadership role at a NERC-registered entity.
  • Named NERC CIP compliance program ownership with direct engagement in Regional Entity (TRE, WECC, RF, or equivalent) audit and enforcement processes.
  • Demonstrated experience managing Splunk, Nessus or Tenable, and Tripwire or equivalent OT security tooling.
  • Demonstrated experience managing both a technical security team and a GRC/analyst team simultaneously.
  • Demonstrated ability to communicate OT Security & Compliance topics clearly and accurately across all organizational levels: from engineering staff through executive leadership, and to external regulatory bodies.
  • Active security certification required: GICSP, CISSP, CISM, or GIAC equivalent.
  • Bachelor’s degree in computer science, Information Systems, Engineering, or a related field; in lieu of degree, 10+ years of directly applicable OT/ICS security and compliance experience.

Skills

  • Splunk
  • Nessus/Tenable
  • Tripwire
  • NERC CIP
  • OT Security
  • ICS Cybersecurity
  • GRC
  • Risk Management
  • Regulatory Compliance
  • FERC
  • NERC
  • TRE
  • CIP-006
  • CIP-007
  • CIP-008
  • CIP-010
  • CIP-011
  • IEC 62443
  • NIST SP 800-82
  • NIST CSF
  • AssurX
  • ServiceNow

Experience Level

  • 5+ years of progressive OT or ICS cybersecurity experience
  • 7+ years of experience in OT/ICS cybersecurity or critical infrastructure protection
  • at least 3 years in a compliance program leadership role at a NERC-registered entity
  • at least 3 years in a compliance program leadership role

Education Level

  • Bachelor’s degree in computer science, Information Systems, Engineering, or a related field
  • 10+ years of directly applicable OT/ICS security and compliance experience

Benefits

  • 100% employer paid premium healthcare
  • paid parental leave

About the Company

  • Founded in 1990, LS Power is a premier development, investment, and operating company focused on the North American power and energy infrastructure sector, with leading platforms across generation, transmission and energy expansion solutions.
  • Since inception, LS Power has developed or acquired 50,000 MW of power generation, including utility-scale solar, wind, hydro, battery energy storage, and natural gas-fired facilities.
  • Through its transmission business, LS Power Grid, the company built and operates 780+ miles of high-voltage transmission and 7 transmission utilities and has another 375+ miles currently in construction or development.
  • LS Power actively invests in and scales businesses that are meeting the growing needs of the energy expansion, including electric vehicle charging, demand response, microgrids, renewable fuels and waste-to-energy platforms.
  • Over the years, LS Power has raised more than $76 billion in debt and equity capital to support North American infrastructure.
  • Our Purpose is to solve complex energy problems that improve the world
  • Our Mission is to make lives better by developing a cleaner and more reliable energy ecosystem
  • Our Values are the willingness to participate in and help strengthen our culture of integrity, Innovation, Teamwork, and Taking Ownership
  • Our People create value and are our Most Valuable asset.
  • We take our values of Integrity, Innovation, Teamwork and Taking Ownership seriously and ask candidates to think about how they can help us further enhance our culture with their specific skillsets, capabilities and experiences.