SonicJobs Logo
Left arrow iconBack to search

Senior RCR Analyst/ RCR Analyst

NORTHEAST POWER COORDINATING
Posted 19 hours ago, valid for 13 days
Location

New York, NY, US

Salary

$120,000 - $155,000 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Registration, Certification, and Risk (RCR) Analyst will assess entity data to evaluate risks to reliable operations and assist with compliance monitoring.
  • Candidates must possess a Bachelor's Degree in Engineering, Cyber Security, Information Systems, or Risk Management and have a minimum of three years of relevant experience.
  • Key responsibilities include developing Inherent Risk Assessments, advising on internal controls, and participating in certification activities.
  • Preferred qualifications include experience with risk assessments and knowledge of NERC Reliability Standards, with certifications such as CIA or CISA being advantageous.
  • The position offers a salary range of $70,000 to $90,000, depending on experience and qualifications.

Position Summary

The Registration, Certification, and Risk (RCR) Analyst participates on a team that assesses entity data to determine an entity’s risk to reliable operations, develops focus areas for compliance monitoring, assesses entity performance, and provides outreach on compliance and reliability topics. The position also assists with the review and evaluation of requests for new or revised entity registration and assists in entity certification activities.

Key Responsibilities

  • Assesses entity operational attributes and characteristics to understand the entity’s risks to reliability and security of the Bulk Power System.
  • Develops and updates entity Inherent Risk Assessments (IRA), Compliance Oversight Plans (COP).
  • Develops audit scoping recommendations in accordance with NPCC Compliance Instructions and ERO report format guidance.
  • Advises on internal controls assessment focus areas based on inherent and residual entity risk. 
  • Assesses the maturity of entity risk and controls programs. 
  • Assesses the design, implementation, and effectiveness of entity internal control activities.
  • Assesses monitoring engagement results and other compliance history to develop and update entity COPs.
  • Follows IRA and COP processes based on specific Canadian Provincial agreements. 
  • Assists with coordination of the registration process, ERO CORES tool use, registration surveys, questionnaires, or data requests.
  • Participates as a team member for Certification activities.
  • Assists with the development of training, education, communication, and other outreach materials to NPCC staff and industry stakeholders.
  • Provides support as needed to NPCC Compliance Monitoring and NPCC Enforcement departments. 
  • Represents NPCC on ERO entity risk, mitigation, controls, compliance monitoring, and registration related task forces, working groups, special projects, and/or sub-teams.

Required Qualifications

  • Bachelor’s Degree in Engineering, Cyber Security, Information Systems or Risk Management; or equivalent combination of education and related electric utility industry experience.
  • Minimum three (3) (Analyst), or Minimum of five (5) (Senior Analyst) years of experience in one or more of the following:
    • Electric maintenance, engineering, or system operations
    • Cybersecurity, information security, or operational technology (OT) security
    • Risk management, internal audit, or compliance
    • Development, implementation, or assessment of internal controls
    • Regulatory compliance within a utility, energy, or critical infrastructure environment
    • Enterprise risk management or operational risk assessment
    • Utility Operations Risk Assessment
    • Knowledge and familiarity with NERC O&P and CIP Reliability Standards and related internal controls that support compliance and sustainability. 
    • Knowledge and familiarity with NERC/NPCC Compliance Monitoring and Enforcement Programs
  • Ability to analyze information, identify risks and control gaps, and communicate findings effectively to stakeholders.

Preferred Qualifications

  • Experience conducting risk assessments, control evaluations, or compliance reviews.
  • Knowledge of COSO Internal Control and Enterprise Risk Management frameworks, ISO 31000, and/or NIST frameworks.
  • Knowledge of NERC Reliability Standards, including Operations and Planning (O&P) and Critical Infrastructure Protection (CIP) requirements.
  • Familiarity with NERC and NPCC Compliance Monitoring and Enforcement Programs.
  • Professional certification such as:
    • Certified Internal Auditor (CIA)
    • Certification in Risk Management Assurance (CRMA)
    • Certified Information Systems Auditor (CISA)
    • Global Industrial Cyber Security Professional (GICSP)
    • Certified Information Systems Security Professional (CISSP)

Skills and Abilities

  • Able to develop and deliver professional presentations.
  • Able to effectively engage and participate in discussions with stakeholders.
  • Able to work on many projects simultaneously with only periodic guidance.
  • Excellent verbal and written communication skills.
  • Excellent interpersonal and conflict resolution skills.
  • Excellent organizational skills and attention to detail.
  • Strong analytical and problem-solving skills.
  • Ability to work independently and contribute in a cross-functional team environment

Physical Demands

  • Ability to sit for long periods of time, ability to communicate verbally, and in writing, and ability to handle long periods of screen time.
  • Ability to work and travel within the U.S. and travel to Canada

EEOC and Disclaimer

NPCC is an Equal Opportunity Employer. Employment, including the decision to hire, promote, discipline or discharge, will be solely based on competence, performance, and business needs. We prohibit discrimination on the basis of the individual’s actual or perceived disability, protected veteran status, race, color, sex, age, national origin, religion, sexual orientation, gender, gender identity, gender expression, genetic information, marital status, citizenship, domestic violence victim status, or any other status protected under federal, state or local law.

This job description is not intended to be all–inclusive, and the employee will also perform other reasonably related business duties as assigned by immediate supervisor and other management as required.
 
 This job description does not constitute a written or implied contract of employment.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.