CIP Compliance Program Manager
Listed on 2026-02-16
-
IT/Tech
Cybersecurity -
Government
Cybersecurity
Posted Friday, February 6, 2026 at 9:00 AM | Expires Friday, February 27, 2026 at 8:59 AM
Notice to recruiters: Platte River Power Authority does not accept unsolicited resumes from headhunters, recruitment agencies or fee-based placement services. No agency emails, calls, or solicitations to staff are accepted without a valid agreement. Any unsolicited resume submitted to staff will be considered property of Platte River Power Authority and with no obligation to pay any referral fees.
Job summaryProvides governance, coordination, documentation, and compliance assurance for Platte River’s North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) program. Partners closely with Information Technology (IT), Operational Technology (OT), Physical Security, and business units to ensure applicable CIP requirements are implemented, evidenced, and audit-ready across Low and Medium Impact BES Cyber Systems.
The position resides within the Cybersecurity organization and serves as the primary point of coordination for CIP compliance activities, internal reviews, and audit preparation. The role works in close coordination with the Reliability Compliance organization to support regulatory compliance activities while remaining independent of the Registered Entity compliance function. System ownership and control implementation remain with IT, OT, and other designated control owners across the organization.
This role is critical to ensuring the secure and reliable operation of the Bulk Electric System by supporting compliance with evolving NERC CIP standards.
This posting will close no later than February 26.
Work environment and scheduleThis position works a typical workweek schedule (Monday through Thursday or Monday through Friday) in a general office environment and may be eligible for hybrid workdays. The successful candidate should reside within a commutable distance of Fort Collins. Performing this work requires occasional physical effort to lift and carry light objects and is primarily sedentary; minimal walking or standing is required on an as-needed basis.
Essentialduties and responsibilities
CIP compliance governance and coordination
- Provide governance and oversight for the execution of Platte River’s NERC CIP compliance program
- Serve as the central point of coordination for CIP-related compliance activities across applicable business units
- Establish and maintain CIP compliance schedules, milestones, and tracking mechanisms
- Partner with IT and OT control owners to interpret CIP requirements and define compliance expectations
- Identify, track, and escalate compliance risks, gaps, and material issues through established governance channels
CIP program documentation and evidence management
- Develop, maintain, and update CIP programs, procedures, and supporting documentation
- Coordinate document review, approval, and version control processes
- Establish and maintain a structured system for evidence collection, storage, retention, and retrieval
- Ensure evidence meets audit defensibility standards, including completeness, traceability, and timeliness
Compliance assurance and internal controls
- Perform periodic internal compliance reviews, validations, and spot checks
- Review completed compliance activities for accuracy and completeness
- Design, implement, and maintain internal compliance controls to support sustained compliance
- Provide independent compliance assurance activities in support of the Reliability Compliance function
- Support Low Impact attestations and Medium Impact self-certifications
Audits and regulatory interface
- Serve as the primary internal coordinator for NERC CIP audits, working in partnership with the Reliability Compliance organization
- Support Reliability Compliance with audit preparation, evidence readiness, interviews, and response development
- Collect, review, and format evidence for audit submissions
- Maintain and update Reliability Standard Audit Worksheets and Evidence Request Tool content
- Track mitigation activities, milestones, and closure documentation
IT and OT compliance interface
- Act as a liaison between compliance requirements and IT/OT implementation activities
- Provide…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).