Senior NERC CIP Compliance Analyst at CAMS - Texas | CT, US | Rezi

Senior NERC CIP Compliance Analyst at CAMS - Texas

Senior NERC CIP Compliance Analyst

CAMS - Texas · CT, US

2 weeks ago

Senior NERC CIP Compliance Analyst

CAMS - Texas · CT, US

20 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Senior NERC CIP Compliance Analyst role.

Rezi rewrites your resume against CAMS - Texas's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Senior NERC CIP Compliance Analyst posting at CAMS - Texas — free, in seconds.

About the Role

The Sr. NERC CIP Compliance Specialist provides critical on-site leadership to protect and maintain the integrity of control and business networks at our Low and medium-impact generating stations. This role drives continuous compliance with NERC CIP cybersecurity standards, leads site security initiatives, and serves as the primary subject matter expert for station personnel. Operating as a key liaison, this position partners with cross-functional stakeholders to enforce a secure operational environment and ensure continuous audit readiness through rigorous evidence management.

Responsibilities

  • Build, optimize, and maintain on-site processes and documentation to ensure continuous adherence to NERC CIP standards.
  • Maintain accurate cyber asset inventories and manage baseline change control workflows.
  • Lead RSAW/ERT preparation and submission for Regional Entity audits, spot checks, and compliance investigations.
  • Maintain compliant physical and electronic security perimeters and access controls for all site assets.
  • Execute daily, monthly, quarterly, and annual CIP compliance activities in accordance with program procedures.
  • Serve as the primary site contact for Regional Entities; coordinate cross-functional teams to fulfill RFIs and remediate findings.
  • Deliver and support mandatory NERC CIP cybersecurity compliance training programs for site personnel.
  • Direct the end-to-end patch management lifecycle, ensuring BES Cyber Assets are monitored and updated within regulatory timelines.
  • Lead the annual testing, documentation, and reporting of the Cyber Security Incident Response Plan (CIP-008) and Recovery Plans (CIP-009).
  • Orchestrate annual Critical Vulnerability Assessments (CVAs) while ensuring zero adverse impact to operational BES infrastructure.
  • Oversee the identification, classification, and secure handling of Bulk Electric System (BES) Cyber System Information (BCSI) to prevent unauthorized disclosure.
  • Lead supply chain risk assessments and collaborate with procurement/legal to enforce cybersecurity contract clauses.
  • Conduct proactive internal compliance self-assessments; manage the identification, self-logging, and mitigation of compliance deviations.

Requirements

  • Bachelor’s degree in Engineering, Computer Science, IT, Cybersecurity, or a related technical discipline (equivalent direct experience considered).
  • Minimum of 5–10 years of professional experience in regulatory compliance, power utility operations, or industrial cybersecurity.
  • At least 5 years of hands-on experience implementing and managing a NERC CIP compliance program across Medium or High-impact assets.
  • Demonstrated success drafting RSAWs, preparing ERT responses, and managing RFIs during Regional Entity audits or spot-checks.
  • Deep operational understanding of the 35-day patch/baseline lifecycle (CIP-007/010), security perimeters (CIP-005/006), and supply chain management (CIP-013).
  • Ability to successfully pass a mandatory NERC CIP-004 Personnel Risk Assessment and background check.
  • Ability to work full-time on-site at the designated facility, travel up to 25% as needed, and safely navigate physical plant environments.
  • Ability to perform physical job duties, including lifting to 25 pounds, climbing, bending, and working in industrial environments (Use of PPE is required).
  • Applicants must possess a valid driver's license and maintain a clean driving record.
  • Candidates should be comfortable operating a vehicle as part of their job responsibilities and must meet any applicable company and insurance requirements.
  • Qualified Applicants must be legally authorized for employment in the United States.
  • Qualified Applicants will not require employer sponsored work authorization now or in the future for employment in the United States.

Skills

  • NERC CIP compliance
  • Cybersecurity
  • Asset management
  • Baseline management
  • Audit preparation
  • Access control
  • Patch management
  • Incident response
  • Vulnerability assessments
  • Information protection
  • Supply chain risk management
  • Self-assessments
  • Mitigation
  • NERC Certified Compliance Professional (NCCP)
  • CISSP (Certified Information Systems Security Professional)
  • CISA (Certified Information Systems Auditor)
  • CISM (Certified Information Security Manager)
  • SANS GIAC certifications
  • GCIP (GIAC Critical Infrastructure Protection)
  • GICSP (Global Industrial Cyber Security Professional)

Location

  • On-site

Work Type

  • Full-time
  • On-site

Experience Level

  • 5-10 years professional experience
  • At least 5 years hands-on experience

Education Level

  • Bachelor’s degree in Engineering, Computer Science, IT, Cybersecurity, or a related technical discipline

Salary/Compensations

  • $130,000 - $160,000 a year

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • LTD insurance
  • STD insurance
  • Life insurance
  • Additional a la carte benefits
  • 401k
  • Flex spending accounts for medical needs
  • Flex spending accounts for childcare needs
  • Employee referral program
  • Tuition reimbursement program

About the Company

  • CAMS offers a variety of excellent benefits.

Equal Opportunity

  • Qualified Applicants must be legally authorized for employment in the United States. Qualified Applicants will not require employer sponsored work authorization now or in the future for employment in the United States.