OUC - The Reliable One, an industry leader and the second largest municipal utility in Florida committed to serving the community and the environment, is presently seeking a Senior Critical Infrastructure Protection Analystto join the Legislative, Reg & Compliance division.
We are looking for a knowledgeable and organized professional to be responsible for supporting the effort to ensure that OUC is in compliance with all current mandatory and enforceable NERC CIP standards and properly prepared to meet all future enforceable NERC CIP standards.
In this role, you will be responsible to demonstrate both due care—ensuring that all required documentation, processes, are in place and if executed as designed would result in a fully compliant position—and due diligence—ensuring that all programs are executed as designed and produce sufficient evidence that Compliance can be clearly demonstrated.
OUC’s mission is to provide exceptional value to our customers and community by delivering sustainable and reliable services and solutions. Click here to learn more about what we do.
The ideal candidate will have:
Bachelor’s Degree in Computer Science Technology, or Engineering, or related field from an accredited college or university
Minimum of five (5) years of experience in any of the following areas: Cyber Security, NERC CIP Compliance, IT (consultant experience preferred), or Network Engineering
Knowledgeable in NERC CIP Standards
Experience in either program or project management
OUC offers a very competitive compensation and benefits package. Our Total Rewards package includes, to cite a few:
Competitive compensation
Low-cost medical, dental, and vision benefits and paid life insurance premiums with no probationary period. Retirement benefits include a cash balance account with employer matching along with a health reimbursement account
Paid vacation, holidays, and sick time
Educational and Professional assistance programs; Paid Memberships in Professional Associations
Please see below a complete Job description for this position.
Job Purpose:
Responsible for supporting the effort to ensure that OUC is in compliance with all current mandatory and enforceable NERC CIP standards and properly prepared to meet all future enforceable NERC CIP standards. Performance in this role is expected to demonstrate both due care—ensuring that all required documentation, processes, are in place and if executed as designed would result in a fully compliant position—and due diligence—ensuring that all programs are executed as designed and produce sufficient evidence that Compliance can be clearly demonstrated.
Primary Functions:
Interpret the requirements of NERC CIP standards;
Assess NERC compliance application notices, interpretation requests, and ballots relating to Critical Infrastructure Protection (CIP);
Function as Program Manager for a variety of OUC cyber security related programs such as Access Control, Electronic Security Perimeters, etc.;
Partner with internal customers that implement the cyber security controls on detailed design, implementation schedule, and quality assessment and user acceptance testing;
Create and maintain reports as needed and perform log reviews of OUC Security Information and Event Management (SIEM) devices supporting OUC Bulk Electric System (BES) Cyber Systems;
Perform routine audits of CIP cyber security controls related to the network and access point infrastructure to ensure design functionality and effectiveness;
Perform routine audits of CIP Windows based asset classes devices to ensure design functionality and effectiveness;
Conduct reviews of compliance programs and documentation specifically related to NERC CIP standards to ensure that they are complete and accurate. If gaps are identified, conduct an evaluation and/or root cause analysis to identify recommended improvements and mitigating actions;
Perform duties as required as a member of the OUC Cyber Security Monitoring Center such as responding to Cyber Security automated system alerts;
Perform as cyber Subject Matter Expert (SME) on the OUC Cyber Incident Response Team (CIRT);
Perform a review and make specific recommendations on all Electricity Sector Information Sharing and Analysis Center security notifications;
Perform investigations, documentation and submittal of potential violations to regulatory organizations and ensure they are tracked for timely resolution and fully documented in auditable records.
Represent OUC on SERC Reliability Corporation (SERC) committees, working groups, and FRCC CIPS;
Perform other duties as assigned.
Technical Requirements:
Working knowledge of, but not limited to, the following:
Layer 2, layer 3 and hybrid Ethernet network drawings;
Microsoft Visio network drawings, rack layouts, Access List spreadsheets;
Software Applications (i.e. Microsoft Visio, VMware, Kaseya, Ovation, Wireshark);
Familiarity with all, but not limited to, the following:
Equipment (i.e. Wireshark [Ethernet network Sniffing], IP telephony);
Cisco firewalls and switches command line expertise;
Related industry, organizational and departmental policies, practices and procedures; legal guidelines, ordinances and laws;
Demonstrated effective business communication and consultation skills to communicate effectively across a diverse group both internally and externally.
Ability to work independently and initiate appropriate courses of action on assignments.
Ability to manage multiple tasks and multiple projects and adapt with shifting priorities.
Ability to examine and evaluate data and present alternative actions in relation to the evaluation.
Ability to make arithmetic computations using whole numbers, fractions and decimals, and compute rates, ratios, and percentages;
Ability to use Microsoft Office Suite (Word, Excel, Outlook, etc.) and standard office equipment (telephone, computer, copier, etc.).
Education/ Certification/ Years of Experience Requirements:
Bachelor’s Degree in Computer Science Technology, or Engineering, or related field from an accredited college or university
Minimum of five (5) years of experience in any of the following areas: Cyber Security, NERC CIP Compliance, IT (consultant experience preferred), or Network Engineering
Working Conditions:
This job is typically performed in an office work environment. May require occasional travel between OUC facilities.
Physical Requirements:
This job requires standing, walking, sitting, repetitive motions, climbing (ladders, stairs, hills, etc.), bending/stooping, reaching over head, kneeling and/or crawling, and lifting up to twenty (20) pounds. This job requires speaking and hearing, typing, reading, writing, and detailed inspection.
OUC–The Reliable One is an Equal Opportunity Employer who is committed through responsible management policies to recruit, hire, promote, train, transfer, compensate, and administer all other personnel actions without regard to race, color, ethnicity, national origin, age, religion, disability, marital status, gender, sexual orientation, gender identity or expression, genetic information and any other factor prohibited under applicable federal, state, and local civil rights laws, rules, and regulations.
EOE M/F/Vets/Disabled
Bachelor’s Degree in Computer Science Technology, or Engineering, or related field from an accredited college or university
Minimum of five (5) years of experience in any of the following areas: Cyber Security, NERC CIP Compliance, IT (consultant experience preferred), or Network Engineering
Preferred certification: Certified Informational Systems Security Professional (CISSP)
The Orlando Utilities Commission (OUC - The Reliable One) is a municipally-owned public utility providing electric and water services to the citizens of Orlando, Florida, St. Cloud, Florida, and unincorporated Orange and Osceola counties. Established in 1923 by a special act of the Florida Legislature, OUC is the second largest municipal utility in Florida and 14th largest municipal in the country. OUC provides electric, water, chilled water and/or lighting services to 400,000 accounts. The company is governed by a five-member commission (including the Mayor of Orlando), which is responsible for all operating policies.OUC has maintained the best electric reliability in the state of Florida for 21 years in a row, when compared to Florida’s investor-owned utilities. Our power is produced at the OUC-owned Stanton Energy Center via a diverse fuel portfolio, which includes nearly 20 megawatts of solar energy.And, our clean, safe, great-tasting water - which is pumped from the Lower Floridan Aquifer - undergoes more than 20,000 chemical and bacteriological water quality tests each year, including tests for more than 135 regulated and unregulated substances like lead and copper.Website: h...ttp://www.ouc.comIndustry: UtilitiesCompany size: 1,001-5,000 employeesIncludes members with current employer listed as Orlando Utilities Commission (OUC - The Reliable One), including part-time roles.Headquarters : Orlando, FloridaFounded: 1923