Compliance & Operations Analyst NERC CIP / OT
Employment Type: Full-Time
Work Environment: Regulated Utility / Critical Infrastructure
Experience Level: 5+ Years
Position Overview
We are seeking a
Compliance & Operations Analyst to support the daily operations, security, and regulatory compliance of a critical
Transmission Management System (TMS) environment.
This role will focus heavily on
NERC Critical Infrastructure Protection (CIP) compliance, operational technology (OT), cybersecurity controls, documentation, and process improvement. The ideal candidate will have experience working within a
regulated electric utility, transmission operations, or other critical infrastructure environment and understand how cybersecurity and compliance requirements are applied to operational systems.
The analyst will work cross-functionally with Operations, Cybersecurity, Engineering, Compliance, and business stakeholders to identify risks, maintain effective controls, support audits, and ensure operational changes are implemented in a secure and compliant manner.
Required Qualifications
- 5+ years of experience supporting regulated Operational Technology (OT), transmission operations, cybersecurity, NERC compliance, or electric utility environments.
- Working knowledge of NERC Critical Infrastructure Protection (CIP) standards and their application within electric utility environments.
- Experience developing, maintaining, and managing:
- Policies
- Plans
- Procedures
- Standards
- Compliance documentation
- Audit evidence
- Experience working with Transmission Management Systems (TMS), Energy Management Systems (EMS), OT, or other critical infrastructure environments.
- Understanding of cybersecurity practices including:
- Vulnerability management
- Patch management
- Access management
- Configuration/baseline management
- Experience supporting compliance audits, including evidence collection, documentation, and audit readiness.
- Strong understanding of change management within regulated or mission-critical environments.
- Demonstrated ability to identify compliance gaps, operational risks, and process improvement opportunities.
- Experience coordinating activities across technical teams, compliance teams, business stakeholders, and leadership.
- Strong written and verbal communication skills, including the ability to translate technical and regulatory requirements into clear business communications.
- Excellent organizational skills and attention to detail, particularly with compliance documentation and recordkeeping.
- Ability to manage multiple priorities and work effectively in a highly regulated, fast-paced environment.
- Ability to work independently while collaborating effectively across cross-functional teams.
Education
- Bachelors degree in Information Technology, Cybersecurity, Engineering, Computer Science, Business, or a related field.
- Equivalent professional experience may be considered in lieu of a degree.
Key Responsibilities
NERC CIP & Regulatory Compliance
- Maintain and enhance NERC CIP compliance policies, plans, procedures, standards, and supporting documentation.
- Monitor compliance with applicable NERC CIP, regulatory, cybersecurity, and organizational requirements.
- Maintain compliance evidence repositories and ensure documentation remains current and audit-ready.
- Support internal and external compliance audits, assessments, and evidence requests.
- Identify compliance gaps and assist in developing and implementing corrective actions.
- Help ensure cybersecurity and compliance controls remain effective and aligned with regulatory requirements.
TMS / OT Operations
- Support daily operational activities within the TMS environment.
- Work with Operations, Engineering, Cybersecurity, and other technical teams to support the reliability and security of critical systems.
- Support vulnerability management, patch management, and baseline configuration monitoring.
- Help identify and mitigate operational and cybersecurity risks within the environment.
Change Management
- Coordinate with technical and business stakeholders to evaluate proposed operational changes.
- Ensure changes are reviewed, implemented, and documented in accordance with security, compliance, and operational requirements.
- Support change management processes for critical OT/TMS systems.
- Ensure appropriate controls and documentation are in place before and after changes are implemented.
Process Improvement & Risk Management
- Analyze existing operational and compliance processes to identify opportunities for improvement.
- Drive initiatives that improve efficiency, standardization, risk reduction, and regulatory readiness.
- Identify operational and compliance risks and support appropriate mitigation strategies.
- Contribute to continuous improvement across the TMS/OT environment.
Stakeholder Coordination
- Serve as a liaison between technical teams, program/project leadership, compliance personnel, and business stakeholders.
- Communicate project milestones, risks, issues, deliverables, and escalations clearly and effectively.
- Translate complex technical, cybersecurity, and regulatory concepts into business-focused communications.
- Build strong working relationships across technical and business functions.
Ideal Candidate Profile
The strongest candidates will have:
- Direct experience with NERC CIP compliance in an electric utility or transmission environment.
- A solid understanding of OT/TMS/EMS environments and the unique cybersecurity requirements associated with critical infrastructure.
- Hands-on experience maintaining NERC CIP documentation and audit evidence.
- Experience working across Operations, Cybersecurity, Engineering, and Compliance teams.
- Strong documentation, organization, and analytical skills.
- The ability to balance regulatory requirements with operational reliability.
- A proactive approach to identifying risks and improving processes.
- Strong communication skills and the ability to work effectively with both technical and non-technical stakeholders.
Success in This Role
Success will be demonstrated through:
- Maintaining strong compliance with applicable NERC CIP and other regulatory requirements.
- Effective identification and mitigation of operational, cybersecurity, and compliance risks.
- Accurate, complete, and audit-ready documentation and evidence.
- Successful collaboration across technical, compliance, and business teams.
- Consistent support of reliable and secure TMS/OT operations.
- Effective communication of project milestones, risks, issues, deliverables, and escalations.
- Meaningful improvements to compliance processes, operational efficiency, and risk management.