Position Summary:
The Senior IT Process Engineer will conduct, monitor and improve identity and access management (IAM) processes and controls to facilitate regulatory compliance working closely with managers, team leaders, specialists, security teams, compliance teams and subject matter experts. This position will provide support to deliver regular IAM compliance health status and metrics, and internal and external auditor interactions as necessary.
Key Responsibilities:
- Reviews and stays current on North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) regulations as they apply to the Identity and Access (IAM) Management domain
- Works with compliance teams to establish, test, and maintain CIP related IAM controls
- Supports the development and presentation of regular status reports and metrics providing visibility to NERC CIP compliance status in the IAM domain
- Investigates and addresses CIP related IAM corrective action program (CAP) issues
- Supports regular reviews and updates to CIP004 standards and reliability standard audit worksheets (RSAW)
- Identifies potential compliance gaps and as required follows compliance reporting processes, performs extent of condition reviews, and establishes mitigation plans
- Supports interactions with external regulatory enforcement organizations during audits or other required meetings, and internal audit teams
- Performs ongoing monitoring to ensure IAM processes and technology solutions continue supporting NERC CIP compliance
- Works with lines of business to execute IAM procedures in a timely manner to maintain NERC CIP compliance
- Works within IAM Operations and with other cross functional operations and compliance teams to ensure processes and technical solutions align to meet NERC CIP requirements, and provide requirements to update processes and technical solutions as needed
- Establishes and executes IAM domain procedures and processes in support of NERC CIP compliance
Required Education & Experience:
- 2 years of IT/Cybersecurity experience
- Detail oriented
- Strong oral and written communication skills
- Experience in enterprise architecture environments, job-related
- Bachelors Degree in Computer Science or job-related discipline or equivalent experience
- Strong analytical skills
- Certified Information Systems Security Professional (CISSP)
- Experience with documenting processes and procedures
- Utility industry experience
- 5 years experience in IT-Information Technology engineering design
- Experience with NERC CIP regulations preferably in the IAM domain
- Solid understanding of general computing controls (GCCs)
- Ability to work with minimal supervision in a fast-paced environment