North American Electric Reliability Corporation (NERC) · 1 day ago
Senior CIP Assurance Advisor
Maximize your interview chances
Non Profit
Comp. & BenefitsNo H1B
Insider Connection @North American Electric Reliability Corporation (NERC)
Get 3x more responses when you reach out via email instead of LinkedIn.
Responsibilities
Develop and manage compliance assurance activities, including associated project plans, to develop and implement a high-quality risk-based compliance monitoring and certification program.
Develop and execute oversight programs/processes/activities to evaluate Regional Entity adherence to the NERC Rules of Procedure, Compliance Monitoring and Enforcement Program, and delegation agreements.
Provide cyber subject matter expertise related to risk management, auditing, and internal controls in support of a high-quality risk-based compliance monitoring and certification program.
Identify, develop, and effectively deliver cyber security training and outreach to Regional Entities and industry participants.
Provide Compliance Assurance department leadership with recommendations to improve the regional compliance oversight program.
Proactively identify opportunities and assist in the ongoing development and improvement of NERC compliance monitoring and enforcement program policies, procedures, rules, and other activities.
Develop and manage relationships with NERC committees, subcommittees, working groups, and industry stakeholder groups.
Execute, control, and proactively manage to project schedules, including risk identification, risk mitigation, and change management.
Report on project status, risks, and achievement of key milestones.
Conduct Compliance Assurance activities in adherence with NERC Rules of Procedure.
Collect and analyze data to detect deficient controls and noncompliance with NERC rules and agreements.
Other duties as assigned.
Qualification
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Required
A Bachelor’s Degree from an accredited four-year college or university, or equivalent experience.
At least five years of progressive and successful experience leading cyber security projects, teams, and/or initiatives in a technically and operationally complex business/organization.
Progressive experience in auditing, internal controls, enterprise risk management, and related governance, risk and control (GRC) frameworks and standards.
Advanced project management and analytical experience.
Ability to work independently in a fast-paced environment with minimal direct supervision.
Competence in interpersonal communications, with the ability to interact diplomatically with people from many levels of industry and government.
Excellent oral and written communication skills, including editing and proofreading skills.
Proficiency in using Microsoft Office tools including Word, Outlook, Excel, and PowerPoint.
Demonstrated group facilitation skills.
Ability and willingness to travel regularly.
Preferred
Knowledge of the NERC Rules of Procedure, NERC Compliance Monitoring and Enforcement Program, and NERC Reliability Standards.
Prior experience in regulatory compliance oversight and enforcement within a recognized industry, government, or government-authorized agency, especially in conducting performance audits or analysis of program effectiveness of government agency operations (e.g., GAO or other federal or state-level equivalent experience).
One or more of the following, or related, professional certifications: Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA).
A master’s degree in a related field.
At least five years of technical cybersecurity security experience, preferably in the electricity sector, utility industry, or industrial control system environment.
Working knowledge in the critical infrastructure protection of the Bulk Electric System and supporting technologies.
Advanced knowledge and application of professional auditing standards and principles, such as COSO, GAGAS, and IIA.
Program design or procedure writing skills.
Company
North American Electric Reliability Corporation (NERC)
The North American Electric Reliability Corporation (NERC) is a not-for-profit international regulatory authority whose mission is to assure the reliability and security of the bulk power system in North America.