Information Security Compliance Analyst

Eagle Creek Renewable Energy LLC

North Carolina

On-site

USD 70,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Eagle Creek Renewable Energy LLC in North Carolina is looking for an Information Security Compliance Analyst to ensure regulatory compliance and security across hydropower facilities. The role involves monitoring networks, investigating security breaches, and developing internal controls aligned with NERC CIP and NIST standards.

The ideal candidate will have a Bachelor's degree in a related field, proven regulatory experience, and excellent analytical skills. Join a dedicated team committed to safeguarding our critical assets while ensuring compliance with industry regulations.

Qualifications

  • Proven experience in regulatory compliance within regulated environments.
  • In-depth knowledge of NERC CIP and NIST frameworks.
  • Strong analytical and problem-solving skills.

Responsibilities

  • Monitor networks for security breaches and conduct investigations.
  • Perform gap analysis against regulatory changes.
  • Develop and test internal controls and compliance policies.
  • Collaborate cross-functionally to report compliance status.
  • Support operational security and incident response activities.

Skills

Network security monitoring
Investigating breaches
Regulatory compliance
Analytical skills
Written communication

Education

Bachelor’s degree in information security or related field

Tools

Firewalls
Intrusion detection systems
Vulnerability scanning tools

Job description

About the role:

Eagle Creek Renewable Energy is seeking an experienced Information Security Compliance Analyst to join our team and help safeguard our organization's regulatory standing and the security of the critical generation assets across our fleet of hydropower facilities. The ideal candidate will have a strong background in monitoring network security, investigating breaches, and implementing strategies to maintain a secure environment in support of regulatory compliance, with the ability to translate complex requirements into clear, defensible, and well‑documented controls. In addition, knowledge and experience with NERC CIP and NIST standards are essential for this role.

What You’ll Do:
  • Monitor networks for security breaches: Proactively monitor our organization's networks and systems to identify and respond to any security breaches or suspicious activities. Implement necessary measures to mitigate risks and ensure the integrity and confidentiality of our information. Conduct thorough investigations into security incidents, document findings, and create detailed reports for management. Collaborate with relevant teams to address identified vulnerabilities and recommend improvements to prevent future incidents.
  • Monitor regulatory change and perform gap analysis: Stay up to date with new and revised NERC standards, FERC orders, and relevant guidance, and assess their impact on our organization. Conduct gap analyses against current practice and translate regulatory change into actionable requirements for IT, security, and facility teams, tracking remediation to completion.
  • Develop and test internal controls and policies: Develop, maintain, and test internal controls and policies that demonstrate sustained compliance rather than point‑in‑time conformance.
  • Collaborate cross‑functionally and report compliance status: Partner within IT and with operational technology and facility personnel to ensure controls are implemented, documented, and audit‑ready. Produce compliance status reporting, metrics, and KPIs for leadership, and support incident reporting and recovery documentation requirements.
  • Support operational security and incident response: Support day‑to‑day security monitoring, vulnerability management, and the investigation of and response to security incidents, and help review proposed changes to systems and infrastructure for both security and compliance impact.
What Skills and Experience You’ll Need:
  • Education and Experience:
    • Bachelor’s degree in information security, information systems, business, engineering, or a related field, or equivalent experience.
    • Proven experience in regulatory compliance, audit, GRC, or internal controls, ideally in electric utility, energy, or another regulated or critical‑infrastructure environment.
    • Working knowledge of the NERC CIP compliance lifecycle, including self‑certification, self‑reporting, mitigation, and audit.
  • Compliance and Regulatory Knowledge:
    • In‑depth knowledge of security technologies, such as firewalls, intrusion detection systems, antivirus software, encryption methods, and vulnerability scanning tools.
    • Familiarity with industry security standards and frameworks, including NERC CIP and NIST.
  • Analytical Skills:
    • Excellent analytical and problem‑solving abilities to translate regulatory requirements into practical, defensible controls.
    • Ability to assess complex, multi‑site environments and identify compliance gaps and risks.
  • Communication and Collaboration:
    • Strong written communication and documentation discipline to produce audit‑ready evidence and clear compliance reporting.
    • Ability to collaborate and work cross‑functionally with teams such as IT, operational technology, physical security, legal, and management.
  • Certifications (preferred):
    • Certified Information Systems Security Professional (CISSP).
    • Certified Information Systems Auditor (CISA).
    • Certified in Risk and Information Systems Control (CRISC).
    • Global Industrial Cyber Security Professional (GICSP) or NERC CIP compliance training.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

NERC CIP InfoSec Compliance Analyst
NERC CIP InfoSec Compliance Analyst

Eagle Creek Renewable Energy LLC • North Carolina

On-site
USD 70,000 - 90,000
Senior NERC CIP Compliance Analyst
Senior NERC CIP Compliance Analyst

CAMS • New Haven (CT)

On-site
USD 90,000 - 120,000
Medical insurance
401(k) plan
Tuition reimbursement
Security Analyst (CIP Compliance) Oaks, PA
Security Analyst (CIP Compliance) Oaks, PA

JPC Partners • Pennsylvania

On-site
USD 95,000 - 120,000
Senior NERC CIP Compliance Analyst
Senior NERC CIP Compliance Analyst

CAMS • Houston (TX)

On-site
USD 120,000 - 160,000
Senior NERC CIP Compliance Analyst
Senior NERC CIP Compliance Analyst

CAMS • City of Oswego (NY)

On-site
USD 120,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+7
Critical Infrastructure Protection (CIP) Analyst
Critical Infrastructure Protection (CIP) Analyst

Phase2 Technology • Fort Worth (TX)

On-site
USD 60,000 - 80,000
Director-NERC CIP Compliance
Director-NERC CIP Compliance

Tallgrass MLP Operations, LLC • Lakewood (CO)

On-site
USD 189,500 - 284,300
Principal Cybersecurity Compliance Analyst
Principal Cybersecurity Compliance Analyst

GFT • Roseville (CA)

Hybrid
USD 150,000 - 200,000
Comprehensive benefits package including wellness programs
Tax-deferred 401(k) savings plan
Incentive compensation for eligible positions
Principal Cybersecurity Compliance Analyst
Principal Cybersecurity Compliance Analyst

GFT • Oakland (CA)

Hybrid
USD 150,000 - 200,000
Hybrid work environment
Comprehensive benefits package
401(k) savings plan
+2
Systems Administrator
Systems Administrator

Hi-Tech Solutions • Philadelphia

On-site
USD 70,000 - 90,000