CIP Enforcement Manager

Northeast Power Coordinating Council (NPCC)

New York (NY)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

NPCC seeks a CIP Enforcement Manager to oversee processing and resolution of NERC CIP noncompliance. You will ensure consistent application of standards, validate risk assessments, and oversee remediation actions with the enforcement team.

Under the Director of Enforcement, you will communicate findings to registered entities and the ERO Enterprise, crafting formal assessments to support enforcement dispositions. Travel to NPCC locations may be required.

Qualifications

  • Ability to communicate technical concepts to non-experts verbally and in writing.
  • Excellent organizational skills and ability to prioritize and manage multiple assignments.
  • Strong questioning attitude and attention to detail.
  • Strong analytical and problem-solving skills.
  • Strong interpersonal and conflict resolution skills.
  • Ability to mentor others.
  • Ability to learn and work in a variety of portals, software, and databases.
  • Proficient with Microsoft Office Suite or related software.

Responsibilities

  • Process and resolve noncompliance with NERC CIP standards under the Director of Enforcement.
  • Evaluate CIP noncompliance applicability using standards language and guidance.
  • Assess risk to the Bulk Power System and ensure defensible risk assessments.
  • Develop and review mitigating actions and evidence for remediation.
  • Provide formal written assessments supporting enforcement dispositions.
  • Lead CIP Enforcement Team and oversee enforcement activities.
  • Identify systemic compliance risks and trends across NPCC region.
  • Collaborate with monitoring teams to inform future audits and risk assessments.

Skills

Communication
Organization
Attention to detail
Analytical thinking
Interpersonal skills
Mentoring
Portal familiarity
MS Office

Education

Bachelor’s degree in cybersecurity or related field
7+ years in electric utility IT/security
CISSP
GICSP
CISA
CRISC
CISM
GCIP
CompTIA Security+

Job description

Position Summary

Under the Director of Enforcement, the primary responsibility of the Critical Infrastructure Protection (CIP) Enforcement Manager is to process and resolve noncompliance with NERC Reliability Standards. This includes ensuring consistent application of the standards, confirming that risk assessments are technically sound, verifying that corrective actions are developed, approved, and completed, and determining appropriate enforcement dispositions.

Enforcement Responsibilities
  • Evaluate applicability of NERC CIP Standard noncompliance by leveraging NERC Standards language and measures, Implementation Plans, ERO-developed practice guides, and industry-created implementation guidance.
  • Assess noncompliance for completeness of disclosure including but not limited to scope, duration, discovery, and accuracy of root cause.
  • Evaluate risk to the Bulk Power System of CIP Standard noncompliance to ensure risk assessments are technically sound and defensible.
  • Review and/or work with entities in developing mitigating actions to remediate and prevent recurrence.
  • Evaluate the quality and completeness of evidence submitted by registered entities in support of mitigation completion.
  • Assess an entity’s compliance history to determine repetitive conduct and/or programmatic failures.
  • Conduct peer reviews of dispositions drafted by other staff.
  • Triage incoming noncompliance to identify violation facts, preliminary risk assessment, and complexity of the noncompliance.
  • Communicate with registered entities and the ERO Enterprise as necessary, to investigate CIP noncompliance and issues, and to assure appropriate and informed enforcement actions.
  • Provide formal written assessments that serve as the technical basis for enforcement disposition recommendations.
  • Manage the CIP Enforcement Team, including oversight of enforcement-related activities and supervision of day-to-day team responsibilities.
  • Identify trends that may indicate systemic compliance risks across the NPCC region
  • Recommend conclusions for each noncompliance considering factors such as scope, duration, risk, mitigating factors, and compliance history.
  • Distinguish between isolated occurrences and systemic compliance program weaknesses.
  • Collaborate with CIP monitoring teams to ensure that noncompliance outcomes inform future audit scoping, sampling, and Inherent Risk Assessments.
  • Monitor emerging risks found in FERC Orders, Standards development, reliability guidance, and industry developments for implications to the enforcement risk posture.
  • Assist, from a technical perspective, in the negotiation of settlements.
  • Provide evidence, testimony, and documentation in support of Hearing Proceedings, as needed.
  • Provides training, education, and communications to NPCC staff, Registered Entities, and ERO Enterprise staff.
  • Ensure information and data placed into various portals, software, and databases are accurate and complete.
  • Participate in NPCC and ERO Enterprise meetings, workshops, task forces, committees, and forums.
  • Work closely with the Director, Enforcement, legal, and other NPCC staff to develop and/or review responses to oversight.
  • Provide CIP technical expertise to NPCC staff.
  • Develop and/or amend policies and procedures.
Education and Certification
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Engineering or other relevant Bachelor’s degree.
  • 7 or more years’ experience associated with computer systems used in the electric utility industry; or 7 or more years of experience in securing computer systems, including both physical and electronic security; or 7 or more years of experience working within an electric utility Control Center or Regulatory IT role.
  • One or more of the following certifications/licenses are strongly preferred:
    • (ISC)2 Certified Information Systems Security Professional (CISSP)
    • GIAC/SANS Global Industrial Cyber Security Professional (GICSP)
    • ISACA Certified Information Systems Auditor (CISA)
    • ISACA Certified in Risk and Information Systems Control (CRISC)
  • One or more of the following certifications/licenses are preferred:
    • ISACA Certified Information Security Manager (CISM)
    • GIAC/SANS GIAC Critical Infrastructure Protection (GCIP)
    • CompTIA Security+
Skills and Abilities
  • Ability to effectively communicate technical concepts to non-experts verbally and in writing.
  • Excellent organizational skills and ability to prioritize and to manage multiple assignments concurrently.
  • Strong questioning attitude and attention to detail.
  • Strong analytical and problem-solving skills.
  • Strong interpersonal and conflict resolution skills.
  • Ability to mentor others.
  • Ability to learn and work in a variety of portals, software, and databases.
  • Proficient with Microsoft Office Suite or related software.
Physical Requirements
  • Prolonged periods of working on a computer.
  • Travel to main office and in-person meetings, as required (barring no restrictions based on travel or health advisories, or occupancy restrictions).
  • Ability to work and travel within the U.S. and travel to Canada.
EEOC Disclaimer

NPCC is an Equal Opportunity Employer. Employment, including the decision to hire, promote, discipline or discharge, will be solely based on competence, performance, and business needs. We prohibit discrimination on the basis of the individual’s actual or perceived disability, protected veteran status, race, color, sex, age, national origin, religion, sexual orientation, gender, gender identity, gender expression, genetic information, marital status, citizenship, domestic violence victim status, or any other status protected under federal, state or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Security Analyst
Senior Cyber Security Analyst

Northeast Power Coordinating Council (NPCC) • New York (NY)

On-site
USD 90,000 - 120,000
Senior NERC CIP Compliance Analyst
Senior NERC CIP Compliance Analyst

CAMS • New Haven (CT)

On-site
USD 90,000 - 120,000
Medical insurance
401(k) plan
Tuition reimbursement
Director-NERC CIP Compliance
Director-NERC CIP Compliance

Tallgrass MLP Operations, LLC • Lakewood (CO)

On-site
USD 189,500 - 284,300
CIP Enforcement Lead: Critical Infrastructure Compliance
CIP Enforcement Lead: Critical Infrastructure Compliance

Northeast Power Coordinating Council (NPCC) • New York (NY)

On-site
USD 120,000 - 180,000
Senior RCR Analyst/ RCR Analyst
Senior RCR Analyst/ RCR Analyst

Northeast Power Coordinating Council (NPCC) • New York (NY)

On-site
USD 90,000 - 150,000
Critical Infrastructure Protection (CIP) Analyst
Critical Infrastructure Protection (CIP) Analyst

Phase2 Technology • Fort Worth (TX)

On-site
USD 60,000 - 80,000
NERC Compliance Associate
NERC Compliance Associate

Talen Energy • Byesville (OH)

On-site
USD 70,000 - 90,000
Senior NERC CIP Compliance Analyst
Senior NERC CIP Compliance Analyst

CAMS • City of Oswego (NY)

On-site
USD 120,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+7
Senior NERC CIP Compliance Analyst
Senior NERC CIP Compliance Analyst

CAMS • Houston (TX)

On-site
USD 120,000 - 160,000
Senior NERC CIP Compliance Analyst
Senior NERC CIP Compliance Analyst

GOEBEL FIXTURE COMPANY • City of Oswego (NY)

On-site
USD 130,000 - 160,000
Medical, dental, vision
LTD, STD, Life insurance
401k with company match
+3