Director, Cybersecurity
Ai Security
Cloud Platforms
Cybersecurity Governance
Cybersecurity Leadership
Cybersecurity Program Director
Cybersecurity Program Management
Industrial Control Systems Cybersecurity
Information Security
Information Technology (IT)
InfoSec
Management
Ot Cybersecurity
Risk Governance
Risk Management
Scada Security
Security
Security Compliance
Security Operations
Security Standards
Job Description
Competitive Power Ventures is building resilient security across corporate IT and operational technology environments, and this role leads the enterprise program to help reduce cyber risk, support regulatory readiness, and strengthen security operations. Based onsite in Maryland (Silver Spring, MD), this leadership position combines strategic planning, governance, and day-to-day oversight of security capabilities.
What you’ll do
- Develop, maintain, and execute CPV’s enterprise cybersecurity strategy and multi-year cybersecurity roadmap.
- Advise the Vice President of Information Technology and senior management on cybersecurity risks, emerging threats, regulatory developments, and recommended investments.
- Establish cybersecurity priorities based on business risk, regulatory requirements, operational needs, and CPV’s risk tolerance.
- Create annual cybersecurity objectives, budgets, initiatives, and performance metrics.
- Provide cybersecurity leadership across corporate IT, cloud, SaaS, data, and OT environments.
- Coordinate cybersecurity activities across CPV’s corporate offices and generation assets, including vulnerability, testing, and remediation programs.
- Manage cybersecurity personnel and third-party resources, including consultants and managed security providers.
- Develop, maintain, and enforce cybersecurity policies, standards, procedures, and technical controls.
- Maintain governance across access management, privileged access, change management, vulnerability management, incident response, data protection, third-party security, remote access, and artificial intelligence.
- Lead enterprise cybersecurity risk assessments and maintain visibility into significant cyber risks.
- Oversee cybersecurity monitoring and security operations, including endpoint, identity, email, cloud, network security, threat detection, and security monitoring.
- Own the incident response program, including plans, escalation procedures, communications protocols, and response playbooks.
- Coordinate tabletop exercises and incident simulations with IT, OT, Legal, Communications, Human Resources, Asset Management, and senior leadership.
- Partner with Infrastructure & Operations and business stakeholders for disaster recovery and business continuity planning.
- Support OT cybersecurity protections for operational environments, including SCADA and new plant or renewable asset cybersecurity requirements.
- Support CPV’s compliance obligations, including NERC CIP requirements, and maintain alignment with NIST CSF.
- Coordinate cybersecurity audits, assessments, evidence collection, remediation activities, and management responses with internal and external stakeholders.
- Lead cybersecurity awareness and education, including training, phishing and social engineering exercises, and targeted security communications.
- Deliver regular executive reporting on cyber risks, incidents, vulnerabilities, remediation progress, compliance, and program maturity, including reporting to governance bodies as required.
What you bring
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline (or equivalent professional experience).
- Approximately 10+ years of progressive experience in cybersecurity, information technology, infrastructure, or related disciplines.
- At least 5 years of cybersecurity leadership or management experience.
- Demonstrated experience developing or managing an enterprise cybersecurity program.
- Strong understanding of cybersecurity risk management, security architecture, vulnerability management, incident response, identity and access management, and security operations.
- Experience with cloud and SaaS environments, particularly Microsoft technologies.
- Experience managing cybersecurity vendors, consultants, and managed security service providers.
- Strong written, verbal, executive presentation, and stakeholder-management skills.
- Ability to translate complex technical risks into understandable business risks and recommendations.
- Preferred: power generation, energy, utility, industrial, or critical infrastructure sector experience.
- Preferred: experience presenting to executive management, Audit Committees, or Boards.
- Preferred certifications: CISSP and/or relevant Microsoft or cloud security certifications.
- Must pass a pre-employment background and financial credit check.
Tools and frameworks you’ll work with
- NERC CIP, NIST Cybersecurity Framework (CSF), SCADA
- Microsoft technologies, cloud, SaaS
- Artificial intelligence and generative AI, including AI platforms and AI agents
Compensation and benefits
Base salary range: USD 165,000 - 195,000 per year (company’s good faith estimate).
- Annual discretionary bonus up to 30%
- PTO: 160 hours per year
- Up to 13 company-paid holidays
- Medical, dental, and vision: 100% company paid
- 401(k): 100% company match up to 6%
- Life insurance
- Short- and long-term disability
- Parental leave
- Flexible spending accounts