Live opening · Posted 3 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Cyber Security Analyst – NERC CIP / Patch Management
Job Type: 7+ month Contract with possible extension
Work Arrangement: 100% Remote
Level: I / II / III based on experience
Position Overview
We are seeking a Cyber Security Analyst to support cybersecurity and compliance activities within a critical infrastructure environment. The ideal candidate will have experience with NERC CIP requirements, vulnerability management, security patch management, and cybersecurity operations.
This role will primarily support CIP-007 R2 patch management processes, while also contributing to vulnerability assessments, security baselines, incident response, cybersecurity projects, and compliance activities.
Key Responsibilities
Monitor and support CIP-007 R2 security patch management processes and related tools.
Support compliance with NERC CIP requirements and cybersecurity controls protecting critical infrastructure.
Maintain and support the organization's cybersecurity program and protection of corporate cyber assets.
Monitor, track, and coordinate security patches and vulnerability remediation throughout the lifecycle.
Perform or support vulnerability assessments of systems, applications, and services.
Develop and maintain security baselines, procedures, standards, and cybersecurity documentation.
Work with IT and business teams to incorporate appropriate security controls into on-premises, cloud, and SaaS solutions.
Translate technical findings from security and assessment tools into clear reports, remediation plans, and action items.
Participate in the cybersecurity incident response process.
Support cybersecurity awareness and training activities.
Assist with cybersecurity projects, including technology implementation, vendor evaluations, vulnerability assessments, and security reviews.
Collaborate with technical and business stakeholders to identify security risks and implement appropriate controls.
Participate in an on-call rotation to support security alerts and incidents, including occasional after-hours onsite response.
Support other cybersecurity and compliance activities as required.
Required Qualifications
4–7 years of professional experience in cybersecurity, information security, IT security, or a related IT discipline for a Level II profile.
Hands-on experience with vulnerability management and/or security patch management.
Understanding of NERC CIP requirements; experience with CIP-007 / CIP-007 R2 is highly preferred.
Experience working with security tools, vulnerability assessment platforms, or patch management solutions.
Experience with one or more IT infrastructure areas such as Windows, Linux/Unix, networking, or systems administration.
Ability to analyze technical security findings and communicate them through clear reports and remediation plans.
Strong written and verbal communication skills.
Ability to work independently while collaborating effectively with technical and business teams.
Ability to participate in an on-call security response rotation.
Willingness to travel occasionally to company locations when required.
Preferred Qualifications
Experience in utilities, energy, power, critical infrastructure, OT, ICS, or industrial environments.
Direct experience with NERC CIP compliance and BES Cyber Systems.
Experience specifically supporting CIP-007 R2 patch management.
Experience with security baselines, system hardening, and configuration management.
Experience with cybersecurity incident response.
Bachelor's degree in Computer Science, Cybersecurity, Information Security, IT, or a related discipline.
Security certification such as CISSP, GIAC/GSEC, Security+, or similar.
Location & Travel
100% Remote
Candidate must reside in an eligible state.
Candidates residing in California, Colorado, Illinois, Kentucky, Massachusetts, Montana, Nebraska, New York, Oregon, or Washington are not eligible at this time.
Frequent travel to facilities in the Akron, OH area may be required.
Occasional overnight travel within OH, PA, NJ, MD, and WV may be required.
Experience Levels
Level I: 0–4 years of professional experience
Level II: 4–7 years of professional experience
Level III: 7–10 years of professional experience
Ideal Candidate Profile
The strongest candidates will typically have:
NERC CIP / CIP-007
Patch Management
Vulnerability Management
Security Assessment / Remediation
Windows/Linux or Networking
Cybersecurity Operations
Experience in the utility or energy sector is a strong plus.
Ankita Singh
Senior Recruitment Consultant
TPI Global Solutions
Email:Ankitas@tpiglobalsolutions.com
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.