Description
Dragonfli Group seeks a NERC CIP Remediation Analyst to deliver hands-on remediation execution in direct coordination with a seasoned audit readiness team supporting a large municipal utility enterprise preparing for a Western Electricity Coordinating Council (WECC) compliance audit.
This is a keyboard-level execution role. The analyst will work alongside advisory leads responsible for audit preparation, gap assessment, and mock audit facilitation. The remediation analysts own the execution layer: closing identified gaps, implementing controls, and building the evidence record across CIP-003 through CIP-013.
Responsibilities
- Execute hands-on remediation tasks across NERC CIP standards CIP-003 through CIP-013 as directed by the audit readiness lead
- Implement technical and procedural controls to close compliance gaps identified through gap assessments and mock audit findings
- Compile, organize, and QA/QC compliance evidence packages in support of WECC audit submission
- Document remediation activities, control test results, and closure evidence with precision
- Coordinate with internal IT, OT, and compliance staff to validate remediation completion across technical and regulatory domains
- Support cyber asset identification, BES Cyber System categorization, and control implementation activities
- Maintain detailed work logs in support of T&M billing and audit trail requirements
- Escalate blockers and risks to engagement lead without delay
Requirements
Required Qualifications
- 3+ years of direct NERC CIP compliance or remediation experience
- Hands-on familiarity with CIP-003 through CIP-013 standards
- Demonstrated execution experience: implementing controls, building evidence, closing findings. Advisory-only profiles will not be considered
- Experience working within OT/ICS environments
- Strong documentation discipline; evidence collection and control validation required
- WECC regional experience preferred
Preferred Qualifications
- Prior municipal or investor-owned utility client experience
- Familiarity with WECC audit process, Data Requests, and audit communication protocols
- NERC CIP certification or equivalent industry credential
