Logo-of-Global-Talent-Resources-Corp-hiring-for-jobs-in-US-on-GrabJobs

NERC CIP Consultant

salary Salary :

$150,000 - 185,000 yearly

icon briefcase Job Type : Full Time
icon remote-alt Remote / Work from Home

Job Description - NERC CIP Consultant

Lead NERC CIP Analyst / Consultant

Location(s)

  • Remote - anywhere in the continental United States.
  • Occasional travel averaging approximately 15%-25% for site walkdowns, audit support, client workshops, and industry events.

Compensation

  • Base salary: $150,000-$185,000, plus an annual performance bonus.
  • Final compensation depends on experience, depth of NERC CIP background, certifications, and location.

Position Summary

The Lead NERC CIP Analyst / Consultant is a senior, client-facing technical leader responsible for delivering end-to-end NERC Critical Infrastructure Protection (CIP) compliance engagements. This hands-on role leads CIP applicability and categorization, program development, evidence preparation, audit and CMEP support, and practical implementation while mentoring less experienced consultants and helping shape a growing compliance practice.

Job Function

  • Serve as the technical lead on NERC CIP engagements, owning the scope, quality, and outcomes of the CIP workstream.
  • Perform CIP-002 applicability and impact-rating analyses, including BES Cyber System and BES Cyber Asset identification, categorization, and supporting rationale.
  • Advise clients on practical implementation of CIP-003 through CIP-015 requirements for Low, Medium, and High Impact environments.
  • Distinguish clearly between explicit regulatory requirements and supporting practices or industry guidance, with appropriate source support.
  • Translate regulatory requirements into sustainable controls, processes, and documentation for operations and IT/OT teams.
  • Develop and mature CIP programs, including policies, procedures, work instructions, control descriptions, and compliance calendars.
  • Build evidence packages and Reliability Standard Audit Worksheet (RSAW) responses alongside client personnel.
  • Design sustainable evidence-management and retention practices that support audit readiness.
  • Support implementation of cybersecurity awareness, physical and electronic access controls, incident response, transient cyber asset and removable media programs, and vendor electronic remote access controls.
  • Advise on network architecture, segmentation, remote access, access control, logging and monitoring, patch and vulnerability management, and configuration change management as they relate to CIP obligations.
  • Lead gap assessments, mock audits, internal control reviews, and compliance risk assessments for new and existing registered entities.
  • Support compliance due diligence for portfolio acquisitions, including compliance exposure assessments and realistic remediation roadmaps.
  • Prepare clients for and support Regional Entity audits, spot checks, self-certifications, data requests, walkthroughs, and auditor interviews.
  • Assist clients with evaluating potential noncompliance, developing self-reports and mitigation plans, and tracking remediation through closure.
  • Conduct on-site walkdowns to confirm that documented configurations, asset inventories, and physical and electronic access controls match field conditions.
  • Contribute to practice methodologies, templates, checklists, service offerings, delivery standards, and technical direction.
  • Mentor and review the work of less experienced consultants while remaining hands-on in client delivery.
  • Apply automation and AI-enabled tools where they improve speed and quality while maintaining regulatory accuracy.
  • Participate in NERC, Regional Entity, and industry forums and support constructive relationships with regulators.
  • Support scoping, estimating, proposal development, and identification of additional client service opportunities.

Education and Experience

  • Bachelor's degree in engineering, computer science, information systems, cybersecurity, or a related technical discipline, or equivalent professional experience.
  • Eight or more years of professional experience in the electric utility or energy sector, including at least five years focused specifically on NERC CIP compliance.
  • Demonstrated hands-on experience across the CIP standards, including asset categorization, evidence development, and audit readiness in a registered entity or consulting environment.
  • Direct experience supporting a Regional Entity audit, spot check, self-certification, or enforcement matter from the entity or consultant side.
  • Consulting or advisory experience serving multiple registered entities across more than one NERC Region is preferred.
  • Experience with inverter-based resources, including solar, storage, and wind, and first-time registrant onboarding is preferred.
  • Experience standing up a CIP program from the ground up, particularly a Low Impact program under CIP-003, is preferred.
  • Experience with Medium or High Impact environments, including Electronic Security Perimeters and associated CIP-005, CIP-007, and CIP-010 obligations, is preferred.
  • Experience with compliance due diligence for mergers, acquisitions, or portfolio transactions is preferred.

Qualifications

  • Working knowledge of operational technology (OT) and industrial control system (ICS) environments, including control systems, SCADA/EMS, industrial networking, segmentation, and remote access.
  • Understanding of how operational reliability affects the practicality of cybersecurity controls.
  • Strong writing skills with the ability to produce documentation that is clear to operational leaders and defensible to auditors.
  • Judgment, self-direction, and professional maturity to lead client workstreams with limited oversight and communicate difficult findings clearly and promptly.
  • Ability to distinguish regulatory requirements from supporting practice and industry guidance with precision.
  • Hands-on, ownership-oriented approach to consulting, including willingness to develop procedures, assemble evidence, and perform site walkdowns.
  • Familiarity with tools such as Tripwire, Splunk, Nessus/Tenable, or comparable configuration monitoring, log management, and vulnerability management platforms is preferred.
  • Familiarity with NERC systems and processes such as Align, Secure Evidence Locker, CORES, and self-report and mitigation plan workflows is preferred.
  • Certifications such as CISSP, GICSP, CISA, CISM, CRISC, ISA/IEC 62443, or a Professional Engineer license are preferred.
  • Working knowledge of adjacent frameworks, including NIST Cybersecurity Framework, NIST SP 800-82, and ISA/IEC 62443, is preferred.
  • Authorization to work in the United States without visa sponsorship.
  • Ability to pass a Personnel Risk Assessment consistent with CIP-004 requirements.

Benefits

  • Medical, dental, and vision coverage.
  • 401(k) with company match.
  • Paid time off and company holidays.
  • Professional development and certification support.
  • Home office arrangement.

By completing an application, you give us permission to send you text messages regarding this position and future opportunities. You can opt out at any time.

Global Talent Resources, Inc. (GTR) is a power industry recruiting firm specializing in substation, transmission, and distribution careers. With 15+ years of experience, we connect engineering and leadership professionals to top roles with leading utilities, cooperatives, EPCs, and consulting firms nationwide.

Many opportunities aren’t listed publicly. Contact the GTR team for insider access, expert guidance, and the next step in your electric utility career.

Original job NERC CIP Consultant posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

Similar NERC CIP Consultant Jobs in the US

GrabJobs is the no1 job portal in the US, connecting you to thousands of jobs fast! Find the best jobs in the US, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.