Required Skills: NERC CIP, FERC, OT, SCADA, EMS, DERMS, substations, wind, solar, battery storage
Job Description
Must Haves:
• 3+ years of experience in Governance, Risk & Compliance (GRC), cybersecurity compliance, IT audit, information security, or related roles
• NERC or FERC experience required
• Strong understanding of cybersecurity and compliance frameworks such as:
o NIST Cybersecurity Framework
o NIST 800-53 / NIST 800-171
o ISO 27001
o SOC 2
o CIS Controls
• Experience supporting internal or external security audits, control testing, evidence collection, and remediation tracking
• Ability to develop, review, and maintain information security policies, standards, procedures, and control documentation
• Experience conducting or supporting risk assessments, gap assessments, control maturity reviews, and compliance readiness activities
• Familiarity with third-party/vendor risk management, including security questionnaires, vendor reviews, and risk documentation
• Ability to track and report on compliance status, remediation activities, audit findings, exceptions, and risk treatment plans
• Strong documentation skills with the ability to translate technical security requirements into clear business-facing language
• Experience working with cross-functional teams including IT, Security Operations, Legal, Procurement, Engineering, Operations, and Compliance
• Working knowledge of cloud, enterprise IT, identity/access management, vulnerability management, change management, and incident response controls
• Strong attention to detail, organizational skills, and ability to manage multiple compliance initiatives simultaneously
• Excellent written and verbal communication skills
Nice to Haves:
• Experience in the renewable energy, utilities, power generation, energy trading, or critical infrastructure industries
• Familiarity with NERC CIP, FERC, or other energy-sector regulatory requirements
• Experience supporting compliance for environments that include OT, SCADA, EMS, DERMS, substations, wind, solar, battery storage, or generation assets
• Certifications such as:
o CISA
o CISM
o CRISC
o CISSP
o Security+
o ISO 27001 Lead Implementer or Lead Auditor
• Experience with GRC platforms such as:
o ServiceNow GRC
o Archer
o OneTrust
o AuditBoard
o LogicGate
o Drata
o Vanta
• Experience supporting SOC 2, ISO 27001, SOX ITGC, PCI, or customer security reviews
• Familiarity with security awareness programs, phishing campaigns, and user training initiatives
• Experience with privacy, data protection, and records retention requirements
• Understanding of supply chain security risks related to energy infrastructure, equipment vendors, EPC firms, OEMs, and managed service providers
• Experience creating executive-level dashboards, compliance scorecards, risk registers, and audit committee materials
Day to Day:
• Support the Information Security team’s governance, risk, and compliance program across corporate IT, cloud services, and operational technology environments
• Maintain and update security policies, standards, procedures, control narratives, and compliance documentation
• Coordinate evidence collection for audits, assessments, customer reviews, and internal compliance testing
• Track audit findings, remediation plans, control deficiencies, policy exceptions, and risk acceptance items
• Conduct control testing to validate whether security controls are operating effectively
• Support internal risk assessments, compliance gap assessments, vendor reviews, and security questionnaires
• Partner with IT, Security Operations, Infrastructure, Engineering, Legal, Procurement, and Operations teams to gather documentation and validate compliance requirements
• Assist with mapping security controls to frameworks such as NIST, ISO 27001, SOC 2, CIS, and applicable energy-sector requirements
• Help maintain the company’s risk register, control inventory, compliance calendar, and audit evidence repository
• Review third-party/vendor security documentation and help assess risk associated with technology providers, OEMs, contractors, and managed service providers
• Assist in preparing reports, dashboards, and presentations for security leadership and business stakeholders
• Monitor remediation progress and follow up with control owners to ensure timely closure of audit or compliance items
• Support continuous improvement of the company’s information security governance program
• Help ensure new systems, applications, and business initiatives align with security policies and compliance requirements
• Stay current on cybersecurity regulatory trends, energy-sector security expectations, and industry best practices
Overview
The Governance & Compliance Specialist will serve as a key member of the Information Security team, helping strengthen the company’s security posture by ensuring policies, controls, audits, risks, and regulatory obligations are effectively managed. In a renewable energy environment, this role is especially important in protecting corporate systems, cloud platforms, and operational assets that support reliable and secure energy generation.