Overview In this role, you will lead high-impact cybersecurity initiatives to secure critical infrastructure and customer data within a large electric utility. You will partner across cyber, IT/OT, compliance, risk, and operations to embed security into architecture and delivery. You'll translate risk into actionable plans, shape secure-by-default designs, and drive governance through repeatable threat modeling and validation methods. The position offers impact on grid resilience, operational reliability, and regulatory readiness, with a focus on secure modernization and executive-level risk reporting. This is an opportunity to influence security at scale in a mission-driven organization.
Responsibilities- Lead cyber security project delivery, manage issues/risks, and align delivery with success criteria
- Design and maintain secure posture across on-premises and cloud environments
- Develop and maintain secure system profiles and overall compliance view
- Collaborate with IT and Quality teams to remediate IT risks
- Drive auditing, vulnerability assessments, and configuration management
- Ensure integration of security applications during implementations and patches
- Partner with external security providers to enhance threat detection and response
- Analyze threats with infrastructure teams and propose architectural changes
- Shape auditing procedures and risk/compliance addressing methods
- Cultivate relationships with senior leaders to map security to business priorities
Key requirements- Ten or more years of experience in information technology, information security and/or cybersecurity
- Proven ability to lead cybersecurity initiatives in complex enterprise environments
- Experience in architecture, cloud, identity, endpoint, network security, vulnerability management, governance, risk, and compliance
- Ability to translate findings into practical remediation plans with clear owners, timelines, and outcomes
- Strong understanding of security architecture, baselines, configuration management, and secure-by-design practices
- Proven collaboration with engineering, operations, compliance, audit, risk, vendor, and business teams
- Ability to communicate complex cybersecurity issues to technical and non-technical audiences
- strategic thinking
- stakeholder management
- clear communication
- security engineering
- risk management
- secure architecture