Principal Analyst, CIP Compliance
Sierra Office
If you have what it takes to become part of the Vistra family and would like to start a promising career with a global leader, take a look at the exciting employment opportunities that are currently available and apply online.
Job Summary
The Principal Analyst CIP Compliance position will be responsible for providing direction, leadership, independent compliance oversight, guidance, and direction needed to maintain on-going compliance with all applicable NERC CIP Reliability Standards and internal policy in support of reliable and secure operations of the bulk power system. This position works directly with both internal operations and security teams and external regulatory organizations. This position will be ensuring that compliance drives operational best practices, delivering on agreed upon service expectations and procedures, and drive profitability improvement initiatives for Vistra. This position is a key member of the Legal & Regulatory Compliance CIP centralized and independent governance and oversight team within Vistra. Locations can include non-retiring plant sites and/or existing Vistra office sites.Job Description
Key Accountabilities
- Possesses strong technical cyber security and programmatic understanding of all NERC CIP standards.
- Lead, oversees and facilitates progress on all compliance related activities such as audits, self-certifications, mock-audits, that includes mitigation plan development and documentation of completion.
- Lead, oversees and facilitate response to regulatory compliance monitoring activities such as audits, self-certifications, mock-audits, enforcement actions, compliance filings, data reporting and data request.
- Provide direction and independent compliance oversight in developing, implementing, and executing project plans goals and timelines for implementation of internal controls.
- Lead, oversees and collaborate with process owners and other staff to provide input and technical support in the development and execution of CIP related projects implementing new or modified CIP standards. This may include supporting the formation and creation of new or modified CIP standards.
- Manage and facilitate violation determination and issue management process. Apply technical CIP expertise in problem solving and producing recommendations and alternative solutions to remediate the violation and to support on-going compliance.
- Oversees development and maintenance of documentation for CIP related programs, processes, and procedures.
Education, Experience, & Skill Requirements
- Experience gained through college degree programs and or certifications in engineering, business, technology, or other related fields
- 8-10 years of experience with an understanding in two or more of the following: NERC CIP, ERCOT Protocols, ISO 27001, NIST 800-53, SOX, PCI, NACHA, NRC.
- 3-5 years of relevant NERC CIP experience
- Must be able to manage multiple initiatives simultaneously in a dynamic, fast-paced environment
- Exceptional reading comprehension and written communication skills
- Experience with Security or Compliance best practices
- Experience with ICS devices, Generation or Transmission assets is preferred
- Professional certification a plus (e.g., PPM, CISM, CISA, CISSP, PE)
Key Metrics
- 100% - Meeting various regulatory reporting deadlines
- 100% - Meeting new or modified CIP standard implementation deadlines
- Meet or exceed compliance control deadlines
#LI-Hybrid
#LI-ND1
Job Family
Legal/ComplianceCompany
Vistra Corporate Services CompanyLocations
Irving, TexasTexasWe are a company of people committed to: Exceeding Customer Expectations, Great People, Teamwork, Competitive Spirit and Effective Communication. If this describes you, then apply today!
If you currently work for Vistra or its subsidiaries, please apply via the internal career site.
It is the policy of the Company to comply with all employment laws and to afford equal employment opportunity to individuals in all aspects of employment, including in selection for job opportunities, without regard to race, color, religion, sex, sexual orientation, gender identity, pregnancy, national origin, age, disability, genetic information, military service, protected veteran status, or any other consideration protected by federal, state or local laws.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits CISA CISM CISSP Compliance Governance ICS ISO 27001 Monitoring NERC CIP NIST NIST 800-53 SOX
Perks/benefits: Career development
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.