Senior NERC CIP Compliance Analyst

Camstex

Middletown (CT)

On-site

USD 130,000 - 160,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
401k
Tuition reimbursement
Employee referral program

Job summary

Camstex in Middletown, CT seeks a Sr. NERC CIP Compliance Specialist to lead on-site compliance for Low/Medium‑impact generating stations. You will drive continuous NERC CIP standards, manage audits, and oversee training and evidence management.

The role requires 5–10 years in regulatory compliance or industrial cybersecurity, on-site work, and travel up to 25%. Strong RSAW/ERT experience is essential, with a focus on BES asset protection and risk management.

Qualifications

  • Bachelor’s degree in Engineering, Computer Science, IT, Cybersecurity, or a related technical discipline (equivalent direct experience considered).
  • Minimum of 5–10 years of professional experience in regulatory compliance, power utility operations, or industrial cybersecurity.
  • At least 5 years of hands‑on experience implementing and managing a NERC CIP compliance program across Medium or High‑impact assets.
  • Demonstrated success drafting RSAWs, preparing ERT responses, and managing RFIs during Regional Entity audits or spot‑checks.
  • Deep operational understanding of CIP‑007/010 lifecycle, CIP‑005/006 perimeters, and CIP‑013 supply chain management.
  • Ability to pass a mandatory NERC CIP‑004 Personnel Risk Assessment and background check.
  • Ability to work full‑time on‑site and travel up to 25%.
  • Ability to perform physical job duties in industrial environments.

Responsibilities

  • Build, optimize, and maintain on-site processes and documentation for ongoing NERC CIP adherence.
  • Maintain accurate cyber asset inventories and baseline change control workflows.
  • Lead RSAW/ERT preparation and submission for audits, spot checks, and investigations.
  • Maintain compliant physical and electronic security perimeters and access controls.
  • Coordinate RFIs and remediation efforts with cross‑functional teams.
  • Deliver and support mandatory NERC CIP cybersecurity training programs.
  • Direct patch management lifecycle for BES Cyber Assets within regulatory timelines.
  • Lead incident response drills and reporting for CIP-008 and CIP-009.
  • Orchestrate annual CVAs with no adverse impact to BES infrastructure.
  • Oversee handling of BES Cyber System Information (BCSI) securely.
  • Lead CIP-013 supply chain risk assessments with procurement/legal teams.
  • Conduct internal self-assessments and manage deviations.

Skills

NERC CIP compliance
Regulatory compliance
On-site leadership
Audit readiness
Cross-functional collaboration
Incident response planning
Patch management
Vulnerability assessments
Supply chain risk management
RSAW documentation

Education

Bachelor's degree in Engineering/CS/IT
Equivalent direct experience

Job description

The Sr. NERC CIP Compliance Specialist provides critical on-site leadership to protect and maintain the integrity of control and business networks at our Low and medium-impact generating stations. This role drives continuous compliance with NERC CIP cybersecurity standards, leads site security initiatives, and serves as the primary subject matter expert for station personnel. Operating as a key liaison, this position partners with cross-functional stakeholders to enforce a secure operational environment and ensure continuous audit readiness through rigorous evidence management.

Essential Duties and Responsibilities
  • Program Ownership: Build, optimize, and maintain on-site processes and documentation to ensure continuous adherence to NERC CIP standards.
  • Asset & Baseline Management: Maintain accurate cyber asset inventories and manage baseline change control workflows.
  • Audit Leadership: Lead RSAW/ERT preparation and submission for Regional Entity audits, spot checks, and compliance investigations.
  • Access Control: Maintain compliant physical and electronic security perimeters and access controls for all site assets.
  • Liaison & RFI Coordination: Serve as the primary site contact for Regional Entities; coordinate cross-functional teams to fulfill RFIs and remediate findings.
  • Training Delivery: Deliver and support mandatory NERC CIP cybersecurity compliance training programs for site personnel.
  • Patch Management: Direct the end-to-end patch management lifecycle, ensuring BES Cyber Assets are monitored and updated within regulatory timelines.
  • Incident Response & Drills: Lead the annual testing, documentation, and reporting of the Cyber Security Incident Response Plan (CIP-008) and Recovery Plans (CIP-009).
  • Vulnerability Assessments (CIP-010): Orchestrate annual Critical Vulnerability Assessments (CVAs) while ensuring zero adverse impact tooperational BES infrastructure.
  • Information Protection: Oversee the identification, classification, and secure handling of Bulk Electric System (BES) Cyber System Information (BCSI) to prevent unauthorized disclosure.
  • Supply Chain Risk (CIP-013): Lead supply chain risk assessments and collaborate with procurement/legal to enforce cybersecurity contract clauses.
  • Self-Assessments & Mitigation: Conduct proactive internal compliance self-assessments; manage the identification, self-logging, and mitigation of compliance deviations.
Qualifications and Skills
  • Bachelor’s degree in Engineering, Computer Science, IT, Cybersecurity, or a related technical discipline (equivalent direct experience considered).
  • Minimum of 5–10 years of professional experience in regulatory compliance, power utility operations, or industrial cybersecurity.
  • At least 5 years of hands‑on experience implementing and managing a NERC CIP compliance program across Medium or High‑impact assets.
  • Demonstrated success drafting RSAWs, preparing ERT responses, and managing RFIs during Regional Entity audits or spot‑checks.
  • Deep operational understanding of the 35‑day patch/baseline lifecycle (CIP‑007/010), security perimeters (CIP‑005/006), and supply chain management (CIP‑013).
  • Ability to successfully pass a mandatory NERC CIP‑004 Personnel Risk Assessment and background check.
  • Ability to work full‑time on‑site at the designated facility, travel up to 25% as needed, and safely navigate physical plant environments.
  • Ability to perform physical job duties, including lifting to 25 pounds, climbing, bending, and working in industrial environments (Use of PPE is required).
Preferred Skills and Certifications
  • Prior experience working directly within a power generation plant, transmission control center, or EMS/GMS environment.
  • NERC Certified Compliance Professional (NCCP) designation.
  • CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), or CISM (Certified Information Security Manager).
  • SANS GIAC certifications, specifically GCIP (GIAC Critical Infrastructure Protection) or GICSP (Global Industrial Cyber Security Professional).
  • Established working relationships and direct audit experience with our specific Regional Entity (e.g., SERC, WECC, NPCC, RF, MRO, Texas RE).
  • Commitment to cybersecurity excellence and regulatory compliance is a must.

$130,000 - $160,000 a year

Applicants must possess a valid driver's license and maintain a clean driving record, as this position requires occasional travel for company business. Candidates should be comfortable operating a vehicle as part of their job responsibilities and must meet any applicable company and insurance requirements.

CAMS offers a variety of excellent benefits.

  • Full-time employees are offered the following: medical, dental, vision, LTD, STD, and Life insurance plans.
  • You can even select additional “a la carte” benefits to meet all your needs.
  • You can also enroll in our 401k, flex spending accounts for medical and childcare needs, and participate in our employee referral and tuition reimbursement programs.

Qualified Applicants must be legally authorized for employment in the United States. Qualified Applicants will not require employer sponsored work authorization now or in the future for employment in the United States.

We believe in transparency and providing candidates with important information to make informed decisions. The salary range for this position is commensurate with experience, qualifications, and location. Actual compensation will be determined based on several factors, including but not limited to skills, experience, and relevant qualifications.

This range represents the base salary and does not include other forms of compensation, such as bonuses, benefits, or equity, which may be offered in addition to the base pay. The company reserves the right to modify compensation ranges at any time in accordance with business needs and market conditions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior NERC CIP Compliance Analyst
Senior NERC CIP Compliance Analyst

CAMS - Texas • City of Middletown (NY)

On-site
USD 130,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+6
Senior NERC CIP Compliance Analyst
Senior NERC CIP Compliance Analyst

CAMS - Texas • New Haven (CT)

On-site
USD 130,000 - 160,000
Medical
Dental
Vision
+2
Senior NERC CIP Compliance Analyst
Senior NERC CIP Compliance Analyst

CAMS • City of Oswego (NY)

On-site
USD 120,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+7
Senior NERC CIP Compliance Analyst
Senior NERC CIP Compliance Analyst

CAMS • Houston (TX)

On-site
USD 120,000 - 160,000
Senior NERC CIP Compliance Analyst
Senior NERC CIP Compliance Analyst

CAMS • New Haven (CT)

On-site
USD 90,000 - 120,000
Medical insurance
401(k) plan
Tuition reimbursement
NERC CIP Manager
NERC CIP Manager

Ethosenergy Power Solutions, LLC • Leesburg (VA)

On-site
USD 145,000 - 165,000
Employee Referral Bonus
Professional development
Entry-Level Electrical Engineer - NERC Complaince
Entry-Level Electrical Engineer - NERC Complaince

CAMS • Houston (TX)

On-site
USD 60,000 - 80,000
Medical insurance
Dental insurance
Vision insurance
+2
Director, NERC CIP Compliance
Director, NERC CIP Compliance

Nrg Bluewater Wind • Town of Texas (WI)

On-site
USD 125,000 - 180,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Northeast Power Coordinating Council (NPCC) • New York (NY)

On-site
USD 90,000 - 120,000
693/O&P NERC Regulatory Compliance Specialist
693/O&P NERC Regulatory Compliance Specialist

Camstex • Northern (KY)

Hybrid
USD 90,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+7