1

Cip Compliance Jobs (NOW HIRING)

NERC CIP Manager

Leesburg, VA

$112K - $151K/yr

Compliance Program Management * Own and maintain the site's NERC CIP compliance program for all applicable standards, including CIP-002 (BES Cyber System Categorization), CIP-003 (Security Management ...

NERC CIP Compliance, including maintaining NERC procedures and logs and other required documentation * Keep all site NERC procedures current with the NERC CIP Standards * Maintain all NERC CIP ...

Coordinates all aspects of the Plant Critical Infrastructure Protection (CIP) Standards NERC CIP Compliance which Includes maintaining NERC procedures and logs and other required documentation. Keep ...

Coordinates all aspects of the Plant Critical Infrastructure Protection (CIP) Standards NERC CIP Compliance which Includes maintaining NERC procedures and logs and other required documentation. Keep ...

The primary responsibility of the position is to provide analytical support and coordination for the NERC (North American Electric Reliability Corporation) CIP Reliability Compliance Program. In ...

Develops a working knowledge of EMS and P&C CIP compliance requirements, supports process improvement initiatives, and provides technical assistance to internal stakeholders under the guidance of ...

Develops a working knowledge of EMS and P&C CIP compliance requirements, supports process improvement initiatives, and provides technical assistance to internal stakeholders under the guidance of ...

Showing results 41-60

Cip Compliance information

See salary details

$50K

$157.5K

How much do cip compliance jobs pay per year?

As of Sep 7, 2026, the average yearly pay for cip compliance in the United States is $152,036.00, according to ZipRecruiter salary data. Most workers in this role earn between $157,000.00 and $157,000.00 per year, depending on experience, location, and employer.

What is CIP compliance?

CIP compliance refers to adhering to the Customer Identification Program (CIP) regulations, which are part of the USA PATRIOT Act. Financial institutions must verify the identity of customers opening accounts to prevent money laundering and terrorist financing. This involves collecting information such as name, date of birth, address, and identification number, and verifying this information through reliable means. Institutions must also maintain records and compare customer information with government lists of known or suspected terrorists. CIP compliance is essential for maintaining a secure financial system and avoiding regulatory penalties.

What are the key skills and qualifications needed to thrive as a CIP Compliance specialist?

To thrive as a CIP (Customer Identification Program) Compliance Specialist, you need a solid background in regulatory compliance, anti-money laundering (AML) principles, and familiarity with financial services regulations, often supported by a degree in finance, law, or a related field. Expertise with compliance management software, transaction monitoring systems, and relevant certifications like CAMS (Certified Anti-Money Laundering Specialist) are typically required. Attention to detail, analytical thinking, and strong communication skills set professionals apart in ensuring accurate due diligence and reporting. These skills are crucial for identifying risks, maintaining regulatory standards, and protecting the organization from financial crimes.

What are some common challenges faced in a CIP Compliance role, and how can they be effectively managed?

CIP Compliance professionals often encounter challenges such as keeping up with evolving regulatory requirements, ensuring consistency in Know Your Customer (KYC) processes across different departments, and managing large volumes of customer data. To effectively manage these, it's important to stay updated through ongoing training, establish clear procedures for information collection and verification, and leverage technology to automate and streamline compliance checks. Regular collaboration with legal, operations, and IT teams is also key to maintaining strong compliance standards and addressing any gaps promptly.

What is the difference between Cip Compliance vs Cip Auditor?

AspectCip ComplianceCip Auditor
CertificationsOften requires certifications like CIPP, CIPM, or similarTypically holds certifications such as CIPP, CIPM, or related privacy and compliance credentials
Work EnvironmentWorks within organizations to ensure policies meet compliance standardsPerforms audits and assessments to verify compliance with Cip standards
Employer & Industry UsageUsed by financial institutions, healthcare, and data-sensitive industriesEmployed by firms conducting compliance audits or consulting agencies

In summary, Cip Compliance professionals focus on implementing and maintaining compliance policies within organizations, while Cip Auditors evaluate and verify adherence through audits. Both roles require similar certifications and work in compliance-heavy industries, but their core functions differ: one manages compliance processes, the other assesses their effectiveness.

More about Cip Compliance jobs
Infographic showing various Cip Compliance job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 12% Part Time, and 4% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $152,036 per year, or $73.1 per hour.

Senior OT Cybersecurity Specialist - NERC CIP

Jacobs Engineering Group Inc.

Houston, TX • On-site

$150 - $200/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 7 days ago


Job description

Senior OT Cybersecurity Specialist - NERC CIP

At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems for thriving cities, resilient environments, mission-critical outcomes, operational advancement, scientific discovery and cutting-edge manufacturing, turning abstract ideas into realities that transform the world for good.

Your impact

As a Senior OT Cybersecurity Specialist with a strong focus on NERC Critical Infrastructure Protection (CIP), you will help protect the operational technology and cyber assets that support reliable electric generation and critical power operations. You will translate regulatory obligations into practical, sustainable controls that work in live plant environments. Working across cybersecurity, operations, engineering, compliance, and vendor teams, you will strengthen cyber resilience while helping the organization remain audit-ready and operationally effective.


Responsibilities

Own and support day-to-day NERC CIP compliance activities across applicable standards, including BES Cyber System identification and categorization, security management controls, personnel and training, electronic and physical access, system security management, incident response, recovery, configuration management, vulnerability assessments, information protection, communications, and supply chain risk management.

Maintain accurate inventories and classifications of BES Cyber Systems, BES Cyber Assets, Electronic Access Control or Monitoring Systems, Physical Access Control Systems, Protected Cyber Assets, and related infrastructure.

Develop, implement, and maintain NERC CIP policies, procedures, technical standards, control narratives, and evidence packages that are clear, repeatable, and aligned with actual operating practices.

  • Coordinate recurring compliance activities such as access reviews, account management, patch evaluations, malicious code prevention, security event monitoring, ports and services reviews, backup and recovery testing, vulnerability assessments, and change‑control evidence.
  • Prepare for and support internal assessments, mock audits, spot checks, self‑certifications, data requests, and regulatory audits; organize evidence, validate completeness, identify gaps, and track corrective actions to closure.
  • Partner with plant operations, controls, electrical engineering, IT, legal, physical security, and compliance personnel to resolve findings without creating unnecessary operational risk.
  • Perform OT cybersecurity risk assessments and design reviews for control systems, generation assets, plant networks, remote access, vendor connections, and new projects or modifications.
  • Apply secure architecture and defense‑in‑depth practices to industrial environments, including network segmentation, firewalls, jump hosts, identity and access management, logging, time synchronization, endpoint controls, backup, recovery, and secure remote access.
  • Support cybersecurity incident response and recovery exercises involving operational technology and applicable NERC CIP reporting, escalation, evidence preservation, and lessons learned.
  • Evaluate vendors and service providers for cybersecurity and NERC CIP supply chain risk; document security requirements and support contract, procurement, and remote‑access reviews.
  • Monitor changes to NERC CIP standards, implementation plans, guidance, and enforcement trends; assess organizational impact and help plan timely implementation, including emerging internal network security monitoring requirements.
  • Mentor technical and compliance stakeholders, deliver role‑based training, and promote a culture of respectful collaboration, accountability, and continuous improvement.

Here's what you'll need

  • Minimum 7 years of experience in operational technology, industrial control systems, electric utility cybersecurity, regulatory compliance, or a closely related field.
  • Minimum 5 years of direct, hands‑on experience implementing, operating, assessing, or auditing NERC CIP compliance controls in an electric utility, generation, transmission, balancing authority, or similarly regulated environment.
  • Demonstrated working knowledge of the NERC CIP standards and the ability to interpret requirements, implementation guidance, evidence expectations, and applicability within real operating environments.
  • Experience building and maintaining audit‑quality evidence, compliance calendars, control ownership, gap assessments, remediation plans, and management reporting.
  • Practical knowledge of OT and I/C technologies such as DCS, SCADA, PLCs, HMIs, historians, engineering workstations, relays, plant networks, industrial protocols, and vendor remote‑access solutions.
  • Understanding of OT network architecture and security controls, including TCP/IP, routing, switching, VLANs, firewalls, Active Directory, authentication, logging, vulnerability management, backup, and recovery.
  • Ability to work safely and effectively around critical infrastructure and operating generation facilities, balancing cybersecurity and compliance objectives with availability, reliability, and safety requirements.
  • Strong written and verbal communication skills, sound judgment, attention to detail, and the ability to explain regulatory and technical issues to both technical and nontechnical stakeholders.
  • Ability to manage multiple priorities, work independently, collaborate across disciplines, and travel to project or plant locations as required.
  • Bachelor’s degree in cybersecurity, information systems, computer science, electrical engineering, controls engineering, or a related technical discipline is preferred, not required. Equivalent combinations of relevant OT, electric‑sector, NERC CIP, military, apprenticeship, and industry experience will be considered. Advanced technical training or an associate degree combined with substantial hands‑on experience is acceptable.

Preferred

  • Experience with NERC compliance monitoring and enforcement processes, Regional Entity engagements, Reliability Standard Audit Worksheets, self‑certifications, spot checks, or formal audits.
  • Experience supporting Generator Owner and Generator Operator functions, including gas turbine, steam turbine, reciprocating engine, renewable, battery storage, microgrid, or behind‑the‑meter generation environments.
  • Experience with OT security monitoring, asset discovery, security information and event management, privileged access, vulnerability assessment, and configuration monitoring technologies.
  • Familiarity with NIST Cybersecurity Framework, NIST SP 800-82, ISA/IEC 62443, CISA guidance, and risk‑based security program development.
  • Relevant certifications such as GICSP, GRID, CISSP, CISM, CRISC, CISA, ISA/IEC 62443, or comparable NERC compliance credentials.
  • Experience leading projects, mentoring team members, or coordinating multidisciplinary remediation efforts.

#LI-MB5

Our health and welfare benefits are designed to invest in you, and in the things you care about. Your health. Your well‑being. Your security. Your future. Employees have access to medical, dental, vision, and basic life insurance, a 401(k) plan, paid time off, and the ability to purchase company stock at a discount. Eligible employees may also enroll in a deferred compensation plan or the Executive Deferral Plan. And certain roles may be eligible for additional rewards, including merit increases, performance discretionary bonus, and stock.

The base salary range for this position is $150,000.00 to $175,000.00. Within the range, individual pay is determined by work location and additional factors, including job‑related skills, experience, and relevant education or training.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. This position will be open for at least 3 days.

Onsite employees are expected to attend a Jacobs Workplace on a full‑time basis, as required by the nature of their role.

Your application experience is important to us, and we’re keen to adapt to make every interaction even better. If you require further support or reasonable adjustments with regards to the recruitment process (for example, you require the application form in a different format), please contact the team via Careers Support .

#J-18808-Ljbffr