Job DescriptionThe (NERC/CIP & GADs) Compliance Coordinator is responsible for leading all NERC / CIP and GADs compliance activities at the Tallgrass Cheyenne Energy Center-an off-grid, large-scale AI-dedicated critical power, multi-unit generation campus that is planned to produce approximately 2.5 GW of initial capacity with expansion capability up to 10 GW from a fleet of simple-cycle gas turbines and combined-cycle gas turbine (CCGT) technologies.
The coordinator ensures full compliance with all applicable North American Electric Reliability Corporation (NERC) Reliability Standards-including Critical Infrastructure Protection (CIP) requirements, as well as all GADs data collection, validation, and submittals in accordance with NERC/IEEE requirements. This role leads the site's NERC/CIP & GADs compliance programs, covering governance, procedures, evidence management, and audit readiness across Bulk Electric System (BES) assets and BES Cyber Systems (BCS). The Coordinator partners with Operations, Maintenance, Engineering, and Corporate Compliance to implement robust cyber and physical security controls for the Emerson Ovation DCS environment and associated OT networks, and drives continuous improvement in reliability, security, and regulatory performance.
ResponsibilitiesEssential duties and responsibilities:Design, Construction & Commissioning Phase- Integrate NERC CIP requirements into plant design, network architecture, and control system configurations.
- Lead BES Cyber System identification, impact rating strategy, and boundary definition prior to commissioning.
- Review EPC, OEM, and integrator designs for CIP compliance, including ESP/PSP architecture.
- Oversee CIP-013 supply chain risk management, including vendor cybersecurity controls and contract requirements.
- Support FAT/SAT activities to validate CIP controls before system acceptance.
- Establish initial compliance evidence, baselines, diagrams, access lists, and recovery plans.
NERC Compliance Program Management- Serve as the site subject-matter expert (SME) for applicable NERC Reliability Standards (CIP and O&P).
- Maintain and execute the site's NERC Compliance Implementation Plan, including policy/procedure governance and evidence lifecycle management.
- Monitor regulatory updates (NERC/FERC/RRO) and implement changes, interpretations, and new standards within required timelines.
- Own BCS identification, impact rating, asset inventory, and boundary documentation; coordinate updates with Engineering and OT.
- Develop, maintain, and submit Reliability Standard Audit Worksheets (RSAWs), self-certifications, and periodic data submittals.
CIP Cyber & Physical Security Oversight- Manage compliance for CIP-002 through CIP-014 as applicable, with emphasis on CIP-002 (BCS), CIP-003 (security management controls), CIP-004 (training & access), CIP-005 (ESP), CIP-006 (PSP), CIP-007 (system security & patching), CIP-008 (incident reporting), CIP-009 (recovery), CIP-010 (configuration change & vulnerability assessments), CIP-011 (information protection), and CIP-013 (supply chain risk).
- Oversee Electronic Security Perimeter (ESP) and Physical Security Perimeter (PSP) controls including access authorization, revocation, logging/monitoring, and periodic reviews.
- Coordinate CIP-compliant account management, MFA where applicable, jump host usage, firewall rules, and remote access controls for Emerson Ovation DCS and supporting BCS.
- Coordinate with IT/OT on patch management (CIP-007), baseline & change management (CIP-010), vulnerability assessments, backups & recovery (CIP-009), and log retention.
- Ensure secure handling and disposal of BES Cyber System Information (BCSI) per CIP-011 and manage vendor/supply chain controls per CIP-013.
Documentation, Evidence & Audit Readiness- Develop and maintain complete, accurate, and verifiable compliance documentation, procedures, and records.
- Lead internal readiness reviews and coordinate external audits/spot checks; manage mitigation plans and corrective actions.
- Maintain evidence repositories (e.g., RSAWs, logs, access reviews, change records) with version control and retention compliance.
- Prepare responses to data requests; ensure traceability between standards, procedures, and evidence artifacts.
Training & Compliance Culture- Administer and track NERC/CIP training and access authorizations for employees and contractors (CIP-004).
- Deliver site briefings, tabletop exercises, and awareness campaigns on CIP responsibilities and cyber hygiene.
- Promote a proactive, audit-ready culture across Operations, Maintenance, Engineering, and Corporate functions.
Operational & Technical Support- Evaluate plant modifications (network/DCS/BCS/access systems) for NERC/CIP impacts and ensure compliant implementation.
- Support incident response and reporting (CIP-008) and root cause analysis; coordinate lessons learned and mitigations.
- Partner with Maintenance on Maximo CMMS work processes to embed compliance controls into work planning, access, and change activities.
- Coordinate with corporate cybersecurity, IT, and engineering for risk assessments, penetration tests (if applicable), and remediation tracking.
Generating Availability Data System (GADS) Reporting- Manage all GADs data collection, validation, and submittals in accordance with NERC/IEEE requirements.
- Ensure accuracy of event, performance, and outage data for GT and CCGT units.
- Coordinate with Operations, Maintenance, and Engineering to verify reliability event classifications.
- Maintain documentation, evidence, and audit readiness for GADs reporting.
Tools & Systems- Distributed Control System (DCS): Emerson Ovation (operations, configuration management, backups, and security hardening).
- Enterprise Asset Management: Maximo CMMS (work management, change control tie-ins, and evidence capture).
- Identity & Access Management: badge systems, directory services, MFA solutions, privileged access workflows.
- Network & Security: firewalls, switches, SIEM/logging, jump hosts, secure remote access, vulnerability scanning tools.
- Document & Evidence Repositories: version-controlled storage for procedures, RSAWs, logs, and audit artifacts.
QualificationsJOB REQUIREMENTS:Minimum requirements:Education:- Bachelor's degree in Engineering, Cybersecurity, Information Systems, or related field; equivalent experience considered.
Experience/Specific Knowledge:- 5+ years of direct NERC/CIP compliance experience in power generation, utility, or similar critical infrastructure.
- Working knowledge of BES Cyber System classifications/impact ratings and applicable NERC CIP and O&P standards.
- Hands-on familiarity with control system/OT environments (Emerson Ovation preferred) and OT network concepts.
- Experience with patching, configuration/change management, access controls, backup/recovery, and log retention in regulated environments.
- Strong technical writing, documentation, and audit-preparation skills; ability to organize complete, accurate, and verifiable evidence.
- Intermediate proficiency level in MS Office applications that may include but are not limited to Outlook, Excel, Word, and PowerPoint.
- Certifications, Licenses & Registrations:
- Must possess and maintain a valid driver's license and a driving record satisfactory to the company and its insurers (for travel).
Competencies, Skills & Abilities:- Regulatory Compliance & Audit Readiness
- Cybersecurity & OT Risk Management
- Technical Writing & Documentation Control
- Stakeholder Communication & Training Delivery
- Project Management & Prioritization
- Analytical Thinking & Attention to Detail
- Cross-Functional Collaboration (IT/OT/Operations/Maintenance)
Physical Demands:All of the physical requirements listed below are those that may be necessary for an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Sitting; standing; walking or moving throughout the facility; driving; talking; seeing (specific vision abilities required by this job include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus); hearing; feeling; bending or stooping; squatting or crouching; reaching; kneeling; pushing; pulling; lifting to 25 lbs.
- Must be able to sit for prolonged periods of time.
- The employee is regularly required to use hands to type, touch, handle, or feel. The employee is required to talk and hear. The employee is frequently required to stand and reach with hands and arms. The employee is occasionally required to walk and climb or balance. The employee must regularly lift and /or move up to 10 pounds and occasionally lift and/or move up to 25 pounds.
Working Conditions:- Primarily office-based with routine access to plant operating areas and secure environments.
- May require after-hours response to compliance or cyber events and occasional travel for audits/training.
- Role involves handling of sensitive BCSI and adherence to strict security protocols.
- Travel 5-10% for training, vendor visits, and corporate meetings.
Supervisory Responsibility:Yes
PREFERRED EDUCATION, EXPERIENCE, CERTIFICATIONS, COMPETENCIES, SKILLS, & ABILITIES:Above the minimum requirements, not required but advantageous in this position:
- Experience in large CCGT or thermal power generation facilities.
- Prior participation in NERC audits, spot checks, mitigation plans, or self-reports.
- Certifications: NERC Compliance Specialist (NCS), CISSP, CISA, CISM, GIAC GICSP, or similar.
- Experience with Maximo CMMS, cyber asset inventories, and evidence management systems.
- Working knowledge of FERC orders/guidance and Regional Entity processes (e.g., SPP RE, WECC, MRO, etc.).
Other responsibilities:The above statements describe the general nature and level of work being performed. This position may perform other duties as assigned.