North American Electric Reliability Corporation logo
North American Electric Reliability Corporation

The North American Electric Reliability Corporation (NERC) is a not-for-profit international regulatory authority whose mission is to assure the effective and efficient reduction of risks to the reliability and security of the grid. NERC develops and enforces Reliability Standards; annually assesses seasonal and long‐term reliability; monitors the bulk power system through system awareness; and educates, trains, and certifies industry personnel. NERC’s area of responsibility spans the continental United States, Canada, and the northern portion of Baja California, Mexico. NERC is the Electric Reliability Organization (ERO) for North America, subject to oversight by the Federal Energy Regulatory Commission (FERC) and Provincial authorities in Canada. NERC's jurisdiction includes users, owners, and operators of the bulk power system, which serves nearly 400 million people.

Senior CIP Assurance Advisor

Location

United States

Posted

42 days ago

Salary

$140K - $150K / year

Seniority

Senior

Job Description

Senior CIP Assurance Advisor

North American Electric Reliability Corporation

Role Description NERC seeks a mission-focused individual who wants to make a difference by supporting the reliability of the North American electric grid. The Senior CIP Assurance Advisor is primarily responsible for providing oversight, guidance, and coordination in managing programs and processes to monitor, review, and evaluate program effectiveness of the ERO Enterprise implementation of risk-based compliance monitoring and adherence to the NERC Rules of Procedure, Compliance Monitoring and Enforcement Program, Certification Program, and approved delegation agreements. The Senior CIP Assurance Advisor may also support development, implementation, and oversight of the Certification Program for Reliability Coordinators, Balancing Authorities, and Transmission Operators. In addition, the Senior CIP Assurance Advisor also develops and delivers outreach and training related to risk-based compliance monitoring, certification, as well as compliance guidance implementation. This position reports to the Manager, Compliance Assurance and Certification. - Provide cyber subject matter expertise related to virtualization, cloud-based technologies, risk management, and internal controls. - Evaluate cloud architectures to ensure alignment with security, performance, scalability, and regulatory requirements. - Identify and recommend remediation of cloud‑related risks through control assessments and continuous monitoring activities. - Support compliance monitoring engagements of virtualized environments against security and regulatory requirements (NERC CIP Standards). - Plan, develop, and manage audit‑based compliance assurance activities and audit plans to support a risk‑based compliance monitoring and certification program. - Execute regulatory audit oversight processes to evaluate Regional Entity compliance with NERC Rules of Procedure and delegation agreements. - Identify, develop, and effectively deliver cyber security training and outreach. - Provide leadership with recommendations to improve the regional compliance oversight program. - Identify opportunities and assist in the ongoing development and improvement of NERC compliance monitoring and enforcement program. - Drive successful project execution by proactively managing schedules, identifying and mitigating risks, and overseeing effective change management. - Conduct Compliance Assurance activities in adherence to NERC Rules of Procedure. - Collect and analyze data to detect deficient controls and noncompliance with NERC rules and agreements. - Other duties as assigned. Qualifications - A Bachelor’s Degree from an accredited four-year college or university, or equivalent experience. - At least five years of progressive and successful experience leading cyber security projects, teams, and/or initiatives in a technically and operationally complex business/organization. - At least three years’ experience in virtualization and cloud-based technologies. - Experience in auditing, internal controls, enterprise risk management, and related governance, risk and control (GRC) frameworks and standards. - Project management and analytical experience. - Ability to work independently in a fast-paced environment with minimal direct supervision. - Competence in interpersonal communications, with the ability to interact diplomatically with people from many levels of industry and government. - Excellent oral and written communication skills, including editing and proofreading skills. - Proficiency in using Microsoft Office tools including Word, Outlook, Excel, and PowerPoint. - Demonstrated group facilitation skills. - Ability and willingness to travel regularly. Requirements - Knowledge of the NERC Rules of Procedure, NERC Compliance Monitoring and Enforcement Program, and NERC Reliability Standards. - Prior experience in regulatory compliance oversight and enforcement within a recognized industry, government, or government-authorized agency, especially in conducting performance audits or analysis of program effectiveness of government agency operations (e.g., GAO or other federal or state-level equivalent experience). - One or more of the following, or related, professional certifications: Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified Cloud Security Professional (CCSP). - A master’s degree in a related field. - At least five years of technical cybersecurity experience, preferably around virtualization and cloud-based technologies, and in the electricity sector, utility industry, or industrial control system environment. - Working knowledge in the critical infrastructure protection of the Bulk Electric System and supporting technologies. - Advanced knowledge and application of professional auditing standards and principles, such as COSO, GAGAS, and IIA. - Program design or procedure writing skills. Other - A background check will be conducted prior to employment. - In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire. - This position has been classified as exempt. - The position may be based remotely but must be able to travel to NERC offices or meeting locations if needed. Reimbursement of travel expenses will be in accordance with the company’s travel and expense reimbursement policies. Our Culture Declarations - Everyone at NERC is a leader. - We are accountable personally and organizationally to deliver on commitments. - We develop ourselves and people in the organization to ensure that NERC realizes its strategic objectives. - We are resilient and adaptable to the challenges and needs of the business and our team. - We exude a growth mindset and empower teams to take risks. - We build collaborative relationships within NERC, the ERO, and the stakeholders of NERC. - We exemplify NERC cultural behaviors: - Reward high-quality, creative, and innovative work. - Attract, engage, and retain top talent. - Value and respect diverse perspectives. - Provide a safe, inclusive, and collaborative work environment. - Form strong relationships within the company, and with the ERO Enterprise. - We demonstrate curiosity in a wide variety of areas and are open to exploring new situations, knowledge, and opportunities for growth and development. - We demonstrate an anticipatory mindset, preventing problems and building contingencies where appropriate. - We are champions for diversity and inclusion, seeking out and valuing diverse perspectives. - We value well-being, prioritizing collaboration, engagement, and connection among our team.

Related Categories

Related Job Pages

More QA Engineer Jobs

TryHackMe logo

QA Content Engineer

TryHackMe

TryHackMe is an online, cloud-based, cyber security training platform used by individuals and academics alike.

QA Engineer42 days ago
Full TimeRemoteTeam 51-200Since 2018H1B No Sponsor

• Plan, test, and write reports for cyber security training labs • Review iterative content development plans • Analyse industry trends and standards regarding tooling and techniques and incorporate that as quality improvement • Interact with content developers to improve the quality of labs being released • Support and interact with the community on content releases

United Kingdom
Full TimeRemoteTeam 51-200H1B No Sponsor

• Perform manual testing on web and mobile applications to ensure a seamless user experience. • Perform API tests and automation using Postman. • Creating and maintaining Postman documentation. • Create and execute automated regression, functional, performance, and API tests. • Develop and execute detailed test plans, test cases, and test scripts. • Document and report bugs, working closely with developers to resolve issues. • Ensure feature compliance by validating product requirements against test results. • Identify edge cases, inconsistencies, and performance issues. • Work with cross-functional teams to improve software quality throughout the development lifecycle. • Provide clear and structured feedback to enhance product functionality and user experience. • Maintain test documentation and contribute to quality assurance best practices.

Portugal
€44K - €56K / year
Job Closed
Full TimeRemoteTeam 11-50Since 2018H1B No Sponsor

• Design and execute comprehensive test plans for new features, covering functional, regression, edge case, and end-to-end scenarios. • Perform exploratory testing to uncover issues that scripted tests miss. • Participate in release cycles, validating builds before they go live and coordinating sign-off with engineers and PMs. • Build and maintain automated end-to-end test suites using Playwright and TypeScript. • Integrate automated tests into CI/CD pipelines to enforce quality gates on every merge. • Validate backend APIs using Postman or equivalent tools. • Use SQL queries to verify data correctness and integrity at the database level. • Test payment flows, subscription state transitions, and billing logic end-to-end. • Document bugs with precise, clear reproduction steps, environment details, logs, and screenshots. • Prioritize issues by severity and impact, communicating urgently when critical paths are affected. • Contribute to defining and evolving QA processes, standards, and tooling across the team. • Maintain living test documentation that stays in sync with the product.

Ukraine
Job Closed
Persistent Technology, Inc. logo

Junior QA Tester – Clinical Data Services

Persistent Technology, Inc.

Join our team today! If you think this full-time job is a fit for what you are looking for, applying is a snap - just follow the instructions on this page. Good luck!

QA Engineer42 days ago
Full TimeRemoteTeam 11-50

Position Description: Junior QA Tester – Clinical Data Services Overview The Junior QA Tester will support quality assurance and validation activities for clinical applications and data services developed and hosted for the Department of Veterans Affairs (VA). This role is focused on hands-on manual testing, ensuring that software releases, data pipelines, and integration services meet functional and data quality requirements prior to deployment. The ideal candidate will have a solid foundation in manual testing, strong attention to detail, and preferably experience working in a government or regulated environment. Key Responsibilities Manual Testing and Validation - Execute manual test cases and test scenarios for web applications, APIs, and data services. - Perform functional, regression, integration, and system testing. - Validate data accuracy, completeness, and transformations within data pipelines and interfaces. - Conduct API testing using tools such as Postman or similar. - Identify, document, and track defects using tools such as Jira or Azure DevOps. - Re-test resolved defects and perform regression testing to ensure issue resolution. Data & Clinical Domain Testing - Assist in validating data exchange between systems and APIs. - Support testing efforts involving healthcare data standards such as FHIR or HL7 (preferred but not required). - Ensure adherence to data security and privacy requirements (e.g., HIPAA). - Follow established processes for testing within a regulated or government environment. Collaboration and Documentation - Work closely with developers and team members to understand requirements and expected outcomes. - Participate in Agile team activities (daily stand-ups, sprint planning, etc.). - Document test results, defects, and testing progress clearly and accurately. Exposure to Automation (Nice to Have) - Gain exposure to basic automation testing tools and frameworks. - Assist in executing automated tests as needed. Qualifications Required - 1–3 years of experience in software testing or quality assurance with a strong focus on manual testing. - Experience executing manual test cases, documenting results, and tracking defects. - Experience testing web-based applications and/or APIs (REST/JSON preferred). - Familiarity with defect tracking tools such as Jira, Azure DevOps, or similar. - Strong attention to detail and ability to follow structured testing processes. - Good written and verbal communication skills. Preferred / Desired - Experience supporting government or federal contracts (VA or other agencies preferred). - Exposure to healthcare or clinical systems. - Basic understanding of data formats (JSON, XML). - Familiarity with API testing tools (Postman). - Experience working in Agile environments. - ISTQB Foundation Level or similar certification. - Ability to obtain a Public Trust clearance. Work Environment - Remote work supporting VA clinical data services. - Collaborative team environment with developers, analysts, and stakeholders.

United States