POSITION RESPONSIBILITIES
Note : All official drafts, documents, and recommendations, as listed below, must be reviewed, finalized, and approved / accepted by appropriate BPA manager or other federal personnel with the authority to do so.
Monitor, review, analyze and support Transmission Technology (TT) Security Governance & Oversight compliance management processes including regulatory audits, investigations of potential violations, and mitigation of violations.
o Provide quality assurance reviews of NERC CIP compliance evidence, violation mitigation documentation, and cybersecurity controls documentation.
Draft and present recommendations for improvement to documentation or artifacts. Alert BPA manager of any noted concerns or potential issues.
o All materials related to audit responses must also be reviewed by BPA management and / or federal staff.
o Facilitate and coordinate efforts to maintain and improve documentation of program processes and procedures.
Serve as a technical team member supporting Subject Matter Experts (SMEs) on cybersecurity compliance activities such as facilitate recurring cybersecurity processes and procedures;
compile and submit compliance evidence in a Governance, Risk, and Compliance (GRC) tool; and contribute to investigations into potential violations.
Note : all drafted materials must be reviewed and finalized by BPA management / BPA staff.)
o Serve as a reliability compliance process point of contact (POC) for the TTB organization, primarily supporting BES Cyber System Categorization and Physical Security of BES Cyber Systems.
o Draft documentation necessary for compliance reporting and audit requirements.
o Develop and recommend strategies and actions to improve incident response maturity.
o Review process and procedure documentation to identify gaps and potential improvement areas.
o Collaborate with internal stakeholders and facilitate information gathering and analysis using standard tools and approaches, or developing new methodologies when needed, to assess business operations and functions, documents, and map current and future states, perform gap analysis, identify, and evaluate solution alternatives, provide recommendations, and develop / draft associated processes and procedures for management approved direction.
o Recommend mitigation, countermeasures, or other options as needed.
Identify potential impacts to Transmission programs and processes from new or modified NERC CIP standards and policies or Federal Information Security Modernization Act (FISMA) / National Institute of Standards and Technology (NIST) requirements.
o Provide recommendations to management to mitigate or comment on NERC proposed regulations and policies.
o Assist to develop solutions, processes, and procedures required to achieve and sustain NERC CIP compliance and effective NIST controls.
o Assist BPA staff with the promotion and implementation of approved recommendations and / or adopted procedures.
REQUIREMENTS
Education & Corresponding Experience (required on matrix)
Required Technical Skills & Experience (required on matrix)
Preferred Skills & Experience (optional on matrix)
Appendices
Valid U.S. Driver's License is required.
Last updated : 2024-04-23
Clear All
0 Security Control Assessor jobs found in Vancouver, WA area