A Compliance Officer or Analyst monitors internal compliance with company policies and also company compliance with local, state and federal laws. Reviews company documents, including contracts and marketing materials; communicates with employees and develops training and internal policy materials.
Job Responsibilities Compliance Program Management Own and maintain the site's
NERC CIP
compliance program for all applicable standards, including CIP-002 (BES Cyber System Categorization), CIP-003 (Security Management Controls), CIP-004 (Personnel & Training), CIP-005 (Electronic Security Perimeters), CIP-006 (Physical Security), CIP-007 (System Security Management), CIP-008 (Incident Reporting & Response Planning), CIP-009 (Recovery Plans), CIP-010 (Configuration Change Management & Vulnerability Assessments), CIP-011 (Information Protection), and CIP-013 (Supply Chain Risk Management). Maintain the BES Cyber System (BCS) and BES Cyber Asset (BCA) inventory, ensuring accurate categorization and Impact Rating documentation. Develop, review, and update CIP and O&P policies, procedures, and work instructions on required review cycles. Track and manage evidence collection to demonstrate continuous compliance; maintain audit-ready documentation at all times. Audits, Self-Certifications & Reporting Serve as the primary liaison with the Regional Entity (e.g., SERC, WECC, RF, MRO, Texas RE) and NERC during audits, spot checks, and self-certifications. Lead internal mock audits and gap assessments to proactively identify and remediate compliance risks. Prepare and submit Self-Reports, Mitigation Plans, and evidence packages for any identified potential violations. Report compliance status, risks, and remediation progress to plant leadership and corporate compliance stakeholders. Cross-Functional Coordination Partner with IT, OT/ICS, engineering, and physical security teams to ensure CIP requirements are embedded in system design, procurement, and change management processes. Coordinate with HR and site security on personnel risk assessments, background checks, and access management required under CIP-004. Work with vendors and contractors to ensure supply chain risk management requirements (CIP-013) are met for new and existing systems. Support incident response exercises and tabletop drills in coordination with CIP-008 requirements. Training & Awareness Develop and deliver annual CIP training and security awareness programs for authorized personnel. Track training completion and access authorization records to ensure ongoing compliance with CIP-004. Continuous Improvement Monitor changes to
NERC CIP
standards, Requirements, and Regional Entity guidance; assess impact to the facility and update programs accordingly. Recommend and implement process improvements, automation, and tools to strengthen compliance posture and reduce manual effort. Maintain awareness of industry best practices, emerging threats, and lessons learned from other entities' violations (Lessons Learned, NERC Alerts). Required Skills / Knowledge Demonstrated working knowledge of
NERC CIP
Reliability Standards as applied to Medium Impact BES Cyber Systems. Experience preparing for and supporting Regional Entity or NERC compliance audits. Working knowledge of Generator Owner and Generator Operator NERC compliance activities as they pertain to
NERC O&P
Standards. Strong understanding of electronic and physical security perimeter concepts, access control, and change management in an OT/ICS environment. Excellent written communication skills, particularly around policy writing, audit evidence packages, and technical documentation. Ability to obtain and maintain unescorted access authorization per CIP-004 requirements, including successful completion of a personnel risk assessment (PRA). Demonstrated working knowledge of
NERC CIP
Reliability Standards as applied to Medium Impact BES Cyber Systems. Experience preparing for and supporting Regional Entity or NERC compliance audits. Working knowledge of Generator Owner and Generator Operator NERC compliance activities as they pertain to
NERC O&P
Standards. Strong understanding of electronic and physical security perimeter concepts, access control, and change management in an OT/ICS environment. Excellent written communication skills, particularly around policy writing, audit evidence packages, and technical documentation. Ability to obtain and maintain unescorted access authorization per CIP-004 requirements, including successful completion of a personnel risk assessment (PRA). Must be able to pass a personnel risk assessment (PRA), including criminal history background check, as required under
CIP-004-6/7. U.S.
work authorization required (or per applicable local employment law). Experience Minimum 5 years of experience in
NERC CIP
compliance, industrial control systems (ICS/OT) security, or utility regulatory compliance. Experience at a generation facility, transmission owner, or other registered NERC entity. Professional certifications such as CISSP, CISA, CISM, GICSP, or NERC-specific compliance training/certificates. Familiarity with compliance management software/GRC tools used for evidence tracking and audit management. Experience with High Impact BES Cyber Systems or transitioning a facility between impact categories. Project management experience (PMP or equivalent) for coordinating cross-departmental remediation efforts. Education Requirements Bachelor's degree in Cybersecurity, Information Technology, Engineering, or related field, or equivalent combination of education and experience. Subject to
NERC CIP
training and re-certification requirements on a recurring basis Physical Requirements Ability to walk, reach, climb, stoop and lift (up to 50 pounds). Primarily office-based at the generating facility with regular access to control rooms, substations, and secured areas requiring unescorted access authorization. Some travel may be required for Regional Entity audits, industry conferences, or corporate compliance meetings. On-call availability may be required to support incident response activities under CIP-008. What We Offer Annual Salary Range for this position is $145,000.00 - $165,000.00 based on experience and skills set Supportive company culture that values its employees Comprehensive Medical, Dental, Vision & 401 K Plan Paid Parental Leave, Time Off & Holidays Extra money in your paycheck - Employee Referral Bonus Personal Development & Career Succession Planning Company sponsored Perks & Discount programs