Senior Operational Compliance Analyst - NERC CIP Cybersecurity
Portland General ElectricAbout the role
At PGE, our work involves dreaming about, planning for, and realizing a smarter, cleaner, more enduring Oregon neighborhood. Its core to our DNA and we haven’t stopped since we started in 1888. We energize lives, strengthen communities and drive advancements in energy that promote social, economic and environmental progress. We’re always on the lookout for people passionate about leading and being a part of teams that are advancing innovative clean energy solutions that are also affordable and accessible to all.
Summary
In this role, you will have the unique opportunity to join our Governance, Risk and Compliance Cybersecurity (GRC) team! GRC is a department of dedicated Compliance Analysts and Cybersecurity Specialists that support Transmission & Distribution (T&D), Physical Security, Energy and Generation Cybersecurity and North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) compliance programs for PGE’s cyber assets.
Our team is responsible for subject matter expertise in Cybersecurity practices relevant to Operational Technology and for developing and overseeing the implementation of a roadmap to reduce the risk of Cybersecurity events impacting PGE’s operational systems. GRC Cybersecurity also oversees the development and operation of the NERC CIP compliance programs, interfacing with a wide range of teams who perform planning, design, and hands-on work to ensure the reliable operation of the Bulk Electric System.
In this role you will support the operational units by writing and establishing standards and procedures, gathering support documentation, and collaborating with other internal business units to ensure compliance with NERC CIP Cybersecurity reliability standards.
We're hiring for a position open to both staff operational compliance analyst and senior Operational Compliance analyst candidates. The level will be determined based on the successful applicant's qualifications, experience, and demonstrated skills during the interview process.
Staff Operational Compliance Analyst
Grade 7
Career Level: P3 Career Professional Requires in-depth knowledge and experience Uses best practices and knowledge of internal or external business issues to improve products or services Solves complex problems; takes a new perspective using existing solutions Works independently, receives minimal guidance Acts as a resource for colleagues with less experience.
Key Responsibilities
Executes operational procedures, processes and practices under supervision, researches and analyzes NERC CIP regulations, requirements and standards.
Provides guidance on implementation of NERC CIP Cybersecurity standards.
Drives implementation of new CIP standards in all business units using project management skills, tools, and techniques.
Coordinates with various business units to ensure consistent, efficient, and achievable practices.
Supports tracking and documentation of data related to compliance controls. Identifies gaps and suggests remediation strategies. Collaborates with Corporate Regulatory Compliance on companywide compliance reviews.
Responds to questions about CIP compliance standards and regulations, procedures and processes. Provides guidance and training to others within operational domain.
Researches changes in technology (with a focus on cybersecurity and operational technology (OT)) process or regulation. Analyzes implications. Determines which procedures may be impacted and how. Recommends changes to operational processes.
Assists with internal and external audits of federal regulatory compliance matters conducted throughout the company.
Qualifications
Requires a bachelor’s degree in finance, business, technical field or other related field or equivalent experience.
Typically, five or more years in combination with compliance and one or more years of utility operations, cyber security or auditing, which includes at least two years of FERC/NERC.
NERC certification preferred.
FERC/NERC, Generation, T&D, and OT Cybersecurity experience.
CISSP or other cybersecurity certification.
Knowledge of business processes and procedures in operational domain (Transmission & Distribution and/or Generation, combined with Information Technology and/or Cybersecurity).
Intermediate knowledge of relevant NERC CIP Cybersecurity regulations and reliability standards.
Competencies
Functional Competencies:
Advanced knowledge of business processes and procedures in operational domain.
Advanced knowledge of relevant
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s