Position Summary:
We are seeking an Expert IT Solutions Engineer to primarily focus on CIP 10 but will also serve as a back-up for other CIP standards. The role coordinates and manages the requirements and measures, ensuring that the work is completed within the regulatory compliance requirements/timeframe and within the quality levels required by the control documents. The successful candidate will also provide project consultation, solution deliverables, and documentation updates associated with the tools and processes.
Key Responsibilities:
- Working knowledge with enterprise change management and monitoring tools
- Management & Operations: Administer the Domain Change Advisory Board for all applicable changes to the CIP 10 applications/systems configuration baseline. Coordinate with Subject Matter Experts within IT and Electric to ensure cybersecurity controls testing, software validation, and the documentation of configuration baseline changes within regulatory compliance requirements/timeframe and quality. Assist with reporting that is needed to support the processes. Understand and follow-up on any failed changes.
- Backup for other CIP Standards: Become competent to perform all required functions for at least one other CIP Standard to allow for load balancing of work across the team.
- Documentation: Develops a variety of documentation such as strategies, plans, designs, usage or configuration standards, policies, guidelines, user requirements, roadmaps, reports, metrics, process manuals, configuration manuals, and other documentation.
Required Education & Experience:
- Experience with IT change management (clearance) process
- BA/BS degree in Computer Science, Engineering, Business or related degree or equivalent experience
- Leadership experience, IT-Information Technology, 5 years
- Good grasp of information security fundamentals, concepts, and strategy
- Must obtain and maintain the required NERC background clearance and training
- Experience with tools such as Remedy, Appian, Tripwire
- Strong collaboration skills
- Experience with performing root cause evaluation
- Experience in IT-Information Technology engineering design, 8 years
- Risk assessment and risk analysis experience
- Demonstrated ability to work both as an individual contributor and in a team environment
- Proven customer facing skills and the ability to effectively communicate at both a high-level and a technical level
- NERC CIP compliance implementation experience with CIP 10 Configuration Change Management and Vulnerability Assessments, or experience with cybersecurity risk management and controls implementation and maintenance/operations
- Understands how to handle evidence containing sensitive information
- Strong written and oral communication, ability to create procedures, diagrams, and business cases
- Excellent communication skills (written and verbal) with senior leadership and technical audiences