Director-NERC CIP Compliance
Listed on 2026-09-25
-
IT/Tech
Cybersecurity
The Director, NERC CIP Compliance is responsible for establishing and leading the company's NERC CIP compliance program. This role owns program governance, standards interpretation, evidence management, internal controls testing, audit readiness, remediation tracking, and coordination with Cyber Security, IT, OT, Engineering, Operations, Legal, and Compliance teams.
The position serves as the primary subject matter expert for NERC CIP requirements and ensures the organization maintains a defensible, repeatable, and audit-ready compliance posture.
Education- Bachelor's degree from an accredited institution in Electrical Engineering, Law, Information Security, Engineering, Information Systems, Computer Science, or a related discipline; or equivalent experience.
JOB DESCRIPTION Primary purpose
The Director, NERC CIP Compliance is responsible for establishing and leading the company's NERC CIP compliance program. This role owns program governance, standards interpretation, evidence management, internal controls testing, audit readiness, remediation tracking, and coordination with Cyber Security, IT, OT, Engineering, Operations, Legal, and Compliance teams.
The position serves as the primary subject matter expert for NERC CIP requirements and ensures the organization maintains a defensible, repeatable, and audit-ready compliance posture.
Education- Bachelor's degree from an accredited institution in Electrical Engineering, Law, Information Security, Engineering, Information Systems, Computer Science, or a related discipline; or equivalent experience.
- Minimum of 10 years of experience leading, managing, or supporting NERC CIP compliance programs in power generation environments.
- Strong working knowledge of NERC CIP standards, compliance lifecycle, and audit expectations.
- Experience coordinating compliance activities across IT, OT, Engineering, and Operations teams.
- Familiarity with evidence management, internal controls testing, and audit readiness practices.
- Ability to translate regulatory requirements into practical, operationally feasible controls.
- Demonstrated ability to drive accountability across cross-functional teams without direct reporting authority.
- Must possess and maintain a valid driver's license and a driving record satisfactory to the company and its insurers (for travel).
- NERC-related or security certifications (e.g., CISSP, CISM, CISA, CRISC) preferred but not required.
- Strong organizational and attention-to-detail skills with the ability to manage multiple compliance activities and deadlines simultaneously.
- Effective written and verbal communication skills, including the ability to clearly explain regulatory requirements to technical and non-technical stakeholders.
- Ability to work collaboratively across functional boundaries and influence decisions without direct authority.
- Sound judgment and professionalism when handling regulatory, compliance, and audit-related matters.
- Ability to bring structure to ambiguity and maintain focus on the highest-priority risks and obligations.
All the physical requirements listed below are those that may be necessary for an employee to successfully perform the essential function of this job. Reasonable accommodations may be made for individuals with disabilities to perform the essential functions.
- Must be able to sit for prolonged periods of time.
- The employee is regularly required to use hands to type, touch, handle, or feel. The employee is required to talk and hear. The employee is frequently required to stand and reach with hands and arms. The employee is occasionally required to walk and climb or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).