Security Control Assessor - Cybersecurity Regulatory Compliance (Onsite) jobs in United States
cer-icon
Apply on Employer Site
company-logo

Motus Recruiting and Staffing, Inc. · 3 hours ago

Security Control Assessor - Cybersecurity Regulatory Compliance (Onsite)

Motus Recruiting and Staffing, Inc. is representing a leading Pacific Northwest utility provider committed to public service and environmental preservation. They are seeking a Security Control Assessor for their Cybersecurity Regulatory Compliance team to support operational technology cybersecurity and compliance practices, review documentation, and assist in incident analysis and compliance activities.

Human ResourcesInformation Technology
Hiring Manager
Eric Duncan
linkedin

Responsibilities

Monitor, review, analyze and support Operational Technology Security Governance & Oversight compliance management processes including regulatory audits, investigations of potential violations, and mitigation of violations
Provide quality assurance reviews of NERC CIP compliance evidence, violation mitigation documentation, and cybersecurity controls documentation. Draft and present recommendations for improvement to documentation or artifacts
All materials related to audit responses must also be reviewed by management
Facilitate and coordinate efforts to maintain and improve documentation of program processes and procedures
Serve as a technical team member supporting Subject Matter Experts on cybersecurity compliance activities such as facilitating recurring cybersecurity processes and procedures; compile and submit compliance evidence in a Governance, Risk, and Compliance tool; and contribute to investigations into potential violations
Serve as a reliability compliance process point of contact for the organization, primarily supporting BES Cyber System Categorization and Physical Security of BES Cyber Systems
Draft documentation necessary for compliance reporting and audit requirements
Develop and recommend strategies and actions to improve incident response maturity
Develop reports, graphs, and other informational materials to support improvement recommendations
Review process and procedure documentation to identify gaps and potential improvement areas
Collaborate with internal stakeholders and facilitate information gathering and analysis using standard tools and approaches, or developing new methodologies when needed, to assess business operations and functions, documents, and map current and future states, perform gap analysis, identify, and evaluate solution alternatives, provide recommendations, and develop/draft associated processes and procedures for management approved direction
Recommend mitigation, countermeasures, or other options as needed
Identify potential impacts to Transmission programs and processes from new or modified NERC CIP standards and policies or Federal Information Security Modernization Act (FISMA) / National Institute of Standards and Technology (NIST) requirements
Provide recommendations to management to mitigate or comment on NERC proposed regulations and policies
Assist in developing solutions, processes, and procedures required to achieve and sustain NERC CIP compliance and effective NIST controls
Assist staff with the promotion and implementation of approved recommendations and/or adopted procedures
Upon request, provide stage-gate input into systems/software implementation projects for potential security or compliance risks and impacts
Assist in developing, drafting, and recommending training materials and job aids
Provide support and assistance to other Security Control Assessors, Cyber Security personnel and Operational Technology co-workers on a variety of ad hoc and standing projects requiring policy/procedure/process analysis

Qualification

Cybersecurity ComplianceOperational Technology SecurityIncident ResponseNERC CIP ComplianceNIST ControlsAnalytical SkillsResearch SkillsDocumentation SkillsTeam Collaboration

Required

A bachelor's degree in computer science, information technology management, Cyber Security, Forensics, or a closely related technical discipline is preferred
4 years of experience is required with an applicable bachelor's degree
6 years of experience is required with an applicable associate degree
8 years of experience is required without a degree or applicable degree
Experience should be consistent with the specific requirements of operations analysis, incident response, and progressively more technical in nature
Ability to research and maintain proficiency in tools, techniques, countermeasures, and trends in information security, computer and network vulnerabilities, data hiding, network security, and encryption
Ability to plan, execute and document compliance evaluations both independently and as a team member

Benefits

Employee benefits

Company

Motus Recruiting and Staffing, Inc.

twittertwitter
company-logo
Founded in 2006, Motus Recruiting is an award-winning firm in the Pacific Northwest specializing in accounting and finance, professional services, technology solutions, and executive search.

Funding

Current Stage
Growth Stage

Leadership Team

leader-logo
Orlando Williams
Chief Executive Officer
linkedin
Company data provided by crunchbase