NERC CIP Manager
Listed on 2026-09-10
-
IT/Tech
Cybersecurity
The NERC CIP Manager is responsible for developing, implementing, and maintaining the plant's compliance program with North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) Reliability Standards for a Medium Impact Bulk Electric System (BES) facility as well as the O&P Standards for Generator Owner (GO) and Generator Operator (GOP). This role owns the day-to-day administration of the CIP and O&P compliance program, coordinates with plant operations, IT/OT, physical security, and engineering teams, and serves as the primary point of contact for internal audits, self-certifications, and Regional Entity / NERC audits.
The CIP Manager ensures the facility's cyber and physical security controls, documentation, and evidence retention practices meet all applicable CIP standards and internal risk management expectations.
- Compliance Program Management
- Own and maintain the site's NERC CIP compliance program for all applicable standards, including CIP-002 (BES Cyber System Categorization), CIP-003 (Security Management Controls), CIP-004 (Personnel & Training), CIP-005 (Electronic Security Perimeters), CIP-006 (Physical Security), CIP-007 (System Security Management), CIP-008 (Incident Reporting & Response Planning), CIP-009 (Recovery Plans), CIP-010 (Configuration Change Management & Vulnerability Assessments), CIP-011 (Information Protection), and CIP-013 (Supply Chain Risk Management).
- Maintain the BES Cyber System (BCS) and BES Cyber Asset (BCA) inventory, ensuring accurate categorization and Impact Rating documentation.
- Develop, review, and update CIP and O&P policies, procedures, and work instructions on required review cycles.
- Track and manage evidence collection to demonstrate continuous compliance; maintain audit-ready documentation at all times.
Audits, Self-Certifications & Reporting - Serve as the primary liaison with the Regional Entity (e.g., SERC, WECC, RF, MRO, Texas RE) and NERC during audits, spot checks, and self-certifications.
- Lead internal mock audits and gap assessments to proactively identify and remediate compliance risks.
- Prepare and submit Self-Reports, Mitigation Plans, and evidence packages for any identified potential violations.
- Report compliance status, risks, and remediation progress to plant leadership and corporate compliance stakeholders.
- Partner with IT, OT/ICS, engineering, and physical security teams to ensure CIP requirements are embedded in system design, procurement, and change management processes.
- Coordinate with HR and site security on personnel risk assessments, background checks, and access management required under CIP-004.
- Work with vendors and contractors to ensure supply chain risk management requirements (CIP-013) are met for new and existing systems.
- Support incident response exercises and tabletop drills in coordination with CIP-008 requirements.
- Develop and deliver annual CIP training and security awareness programs for authorized personnel.
- Track training completion and access authorization records to ensure ongoing compliance with CIP-004.
- Monitor changes to NERC CIP standards, Requirements, and Regional Entity guidance; assess impact to the facility and update programs accordingly.
- Recommend and implement process improvements, automation, and tools to strengthen compliance posture and reduce manual effort.
- Maintain awareness of industry best practices, emerging threats, and lessons learned from other entities' violations (Lessons Learned, NERC Alerts).
- Demonstrated working knowledge of NERC CIP Reliability Standards as applied to Medium Impact BES Cyber Systems.
- Experience preparing for and supporting Regional Entity or NERC compliance audits.
- Working knowledge of Generator Owner and Generator Operator NERC compliance activities as they pertain to NERC O&P Standards.
- Strong understanding of electronic and physical security perimeter concepts, access control, and change management in an OT/ICS environment.
- Excellent written communication skills, particularly around policy writing, audit evidence packages, and technical documentation.
- Ability to obtain and maintain unescorted access authorization per CIP-004 requirements, including successful completion of a personnel risk assessment (PRA).
- Demonstrated working knowledge of NERC CIP Reliability Standards as applied to Medium Impact BES Cyber Systems.
- Experience preparing for and supporting…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).