IT Security Analyst, Senior
Role details
Job location
Tech stack
Job description
Power UTS OSS is seeking a highly motivated and experienced Senior IT Security Analyst to support and advance our NERC Critical Infrastructure Protection (CIP) Compliance Program. This role plays a critical part in sustaining regulatory compliance for Bulk Electric System (BES) cyber assets while strengthening program governance, audit readiness, and program maturity across the organization.This position offers the opportunity to work at the intersection of operational technology, and regulatory compliance within a complex utility environment. The successful candidate will help ensure the reliability and security of critical electric infrastructure through strong analytical leadership, program execution, communication, and collaboration with cybersecurity, infrastructure, reliability and multi-disciplined operational teams.The Senior IT Security Analyst is responsible for the ongoing operational program execution, maintenance, and maturation of the NERC CIP Compliance Program. The role ensures continuous audit readiness, supports internal controls development, and coordinates compliance activities and communication across technical, operational, and leadership stakeholders.This position requires advanced interpretation of NERC CIP Reliability Standards, independent analytical judgment, technical expertise, and clear communication to manage compliance risk and support reliable grid operations.Essential Duties: Program Operations & Compliance ExecutionExecute and sustain operational activities supporting the NERC CIP compliance programMaintain program documentation, procedures, and supporting evidence repositoriesSupport implementation and maturation of compliance processes, tools, and controlsCoordinate compliance activities aligned with evolving regulatory requirementsAudit Readiness & Evidence ManagementPrepare and maintain audit-ready documentation and compliance evidenceSupport mandatory data requests, self-certifications, spot checks, and regulatory auditsCoordinate responses to internal and external audit inquiriesEnsure continuity and accuracy of compliance records and supporting artifactsInternal Controls & Risk ManagementDesign, validate, and evaluate internal controls supporting CIP complianceAssess technical and procedural controls against regulatory requirementsIdentify compliance gaps and recommend remediation strategiesSupport mitigation planning and tracking for identified risks or findingsProgram Improvement & CoordinationPartner with cybersecurity, infrastructure, reliability & compliance and operational SMEs to improve compliance executionSimplify and standardize processes to increase program efficiency and sustainabilitySupport compliance training, education, and awareness initiativesMonitor control performance and recommend enhancements where neededTechnical & Analytical SupportEvaluate system capabilities and operational practices against compliance obligationsAnalyze emerging regulatory requirements and assess program impactsProvide subject matter expertise for compliance-related initiatives and projectsSupport development and maintenance of compliance metrics and reporting
Requirements
Minimum EducationBachelor's degree in information technology, cybersecurity or directly related field such as Information Technology Management, Business Information Systems, Cybersecurity, Electrical or Power EngineeringEquivalency: 1 year of experience = 1 year of educationMinimum Experience4 years of progressively responsible information technology experience related to assignmentPreferred Qualifications: * Experience with NERC CIP Reliability Standards Experience working with structured compliance programs, frameworks, and regulated environments* Experience with compliance audits, evidence management, or regulatory reporting* Strong analytical and documentation skills* Ability to interpret compliance requirements and translate them into operational controlsLicensing, Certifications and Other RequirementsSecurity+ or related certification (GIAC GCIA, GIAC GCIH, CISSP)As Assigned: -Washington State Driver's License-Depending on assignment, some positions may require the ability to pass additional background checks and / or obtain additional certifications, with maintenance thereafter