Unknown Company

Senior OT Cybersecurity Specialist - NERC CIP

northern, ky • Posted 1 weeks ago
Remote Contract IT & Technology

Senior OT Cybersecurity Specialist - NERC CIP

At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems for thriving cities, resilient environments, mission-critical outcomes, operational advancement, scientific discovery and cutting-edge manufacturing, turning abstract ideas into realities that transform the world for good.

Your impact

As a Senior OT Cybersecurity Specialist with a strong focus on NERC Critical Infrastructure Protection (CIP) , you will help protect the operational technology and cyber assets that support reliable electric generation and critical power operations. You will translate regulatory obligations into practical, sustainable controls that work in live plant environments. Working across cybersecurity, operations, engineering, compliance, and vendor teams, you will strengthen cyber resilience while helping the organization remain audit-ready and operationally effective.


Responsibilities

Own and support day-to-day NERC CIP compliance activities across applicable standards, including BES Cyber System identification and categorization, security management controls, personnel and training, electronic and physical access, system security management, incident response, recovery, configuration management, vulnerability assessments, information protection, communications, and supply chain risk management.

Maintain accurate inventories and classifications of BES Cyber Systems, BES Cyber Assets, Electronic Access Control or Monitoring Systems, Physical Access Control Systems, Protected Cyber Assets, and related infrastructure.

Develop, implement, and maintain NERC CIP policies, procedures, technical standards, control narratives, and evidence packages that are clear, repeatable, and aligned with actual operating practices.

  • Coordinate recurring compliance activities such as access reviews, account management, patch evaluations, malicious code prevention, security event monitoring, ports and services reviews, backup and recovery testing, vulnerability assessments, and change‑control evidence.
  • Prepare for and support internal assessments, mock audits, spot checks, self‑certifications, data requests, and regulatory audits; organize evidence, validate completeness, identify gaps, and track corrective actions to closure.
  • Partner with plant operations, controls, electrical engineering, IT, legal, physical security, and compliance personnel to resolve findings without creating unnecessary operational risk.
  • Perform OT cybersecurity risk assessments and design reviews for control systems, generation assets, plant networks, remote access, vendor connections, and new projects or modifications.
  • Apply secure architecture and defense‑in‑depth practices to industrial environments, including network segmentation, firewalls, jump hosts, identity and access management, logging, time synchronization, endpoint controls, backup, recovery, and secure remote access.
  • Support cybersecurity incident response and recovery exercises involving operational technology and applicable NERC CIP reporting, escalation, evidence preservation, and lessons learned.
  • Evaluate vendors and service providers for cybersecurity and NERC CIP supply chain risk; document security requirements and support contract, procurement, and remote‑access reviews.
  • Monitor changes to NERC CIP standards, implementation plans, guidance, and enforcement trends; assess organizational impact and help plan timely implementation, including emerging internal network security monitoring requirements.
  • Mentor technical and compliance stakeholders, deliver role‑based training, and promote a culture of respectful collaboration, accountability, and continuous improvement.

Here's what you'll need

  • Minimum 7 years of experience in operational technology, industrial control systems, electric utility cybersecurity, regulatory compliance, or a closely related field.
  • Minimum 5 years of direct, hands‑on experience implementing, operating, assessing, or auditing NERC CIP compliance controls in an electric utility, generation, transmission, balancing authority, or similarly regulated environment.
  • Demonstrated working knowledge of the NERC CIP standards and the ability to interpret requirements, implementation guidance, evidence expectations, and applicability within real operating environments.
  • Experience building and maintaining audit‑quality evidence, compliance calendars, control ownership, gap assessments, remediation plans, and management reporting.
  • Practical knowledge of OT and I/C technologies such as DCS, SCADA, PLCs, HMIs, historians, engineering workstations, relays, plant networks, industrial protocols, and vendor remote‑access solutions.
  • Understanding of OT network architecture and security controls, including TCP/IP, routing, switching, VLANs, firewalls, Active Directory, authentication, logging, vulnerability management, backup, and recovery.
  • Ability to work safely and effectively around critical infrastructure and operating generation facilities, balancing cybersecurity and compliance objectives with availability, reliability, and safety requirements.
  • Strong written and verbal communication skills, sound judgment, attention to detail, and the ability to explain regulatory and technical issues to both technical and nontechnical stakeholders.
  • Ability to manage multiple priorities, work independently, collaborate across disciplines, and travel to project or plant locations as required.
  • Bachelor’s degree in cybersecurity, information systems, computer science, electrical engineering, controls engineering, or a related technical discipline is preferred, not required. Equivalent combinations of relevant OT, electric‑sector, NERC CIP, military, apprenticeship, and industry experience will be considered. Advanced technical training or an associate degree combined with substantial hands‑on experience is acceptable.

Preferred

  • Experience with NERC compliance monitoring and enforcement processes, Regional Entity engagements, Reliability Standard Audit Worksheets, self‑certifications, spot checks, or formal audits.
  • Experience supporting Generator Owner and Generator Operator functions, including gas turbine, steam turbine, reciprocating engine, renewable, battery storage, microgrid, or behind‑the‑meter generation environments.
  • Experience with OT security monitoring, asset discovery, security information and event management, privileged access, vulnerability assessment, and configuration monitoring technologies.
  • Familiarity with NIST Cybersecurity Framework, NIST SP 800-82, ISA/IEC 62443, CISA guidance, and risk‑based security program development.
  • Relevant certifications such as GICSP, GRID, CISSP, CISM, CRISC, CISA, ISA/IEC 62443, or comparable NERC compliance credentials.
  • Experience leading projects, mentoring team members, or coordinating multidisciplinary remediation efforts.

#LI-MB5

Our health and welfare benefits are designed to invest in you, and in the things you care about. Your health. Your well‑being. Your security. Your future. Employees have access to medical, dental, vision, and basic life insurance, a 401(k) plan, paid time off, and the ability to purchase company stock at a discount. Eligible employees may also enroll in a deferred compensation plan or the Executive Deferral Plan. And certain roles may be eligible for additional rewards, including merit increases, performance discretionary bonus, and stock.

The base salary range for this position is $150,000.00 to $175,000.00. Within the range, individual pay is determined by work location and additional factors, including job‑related skills, experience, and relevant education or training.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. This position will be open for at least 3 days.

Onsite employees are expected to attend a Jacobs Workplace on a full‑time basis, as required by the nature of their role.

Your application experience is important to us, and we’re keen to adapt to make every interaction even better. If you require further support or reasonable adjustments with regards to the recruitment process (for example, you require the application form in a different format), please contact the team via Careers Support .

#J-18808-Ljbffr

Senior OT Cybersecurity Specialist - NERC CIP in northern at Unknown Company

This position is listed as contract and able to be worked remotely.

Back to Job Search