> Markdown version of [/jobs/ext/2427409-cyber-security-architect](https://www.wearedevelopers.com/jobs/ext/2427409-cyber-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Architect - **Company:** Eugene Water & Electric Board - **Location:** Eugene, OR, United States (Remote available) - **Experience:** Expert - **Salary:** $129,351.0 - $161,689.0 - **Contract:** Permanent contract - **Skills:** Business Systems, Cloud Computing, Cyber Security, Databases, Information Systems Security Architecture Professional, Network Segmentation, Performance Tuning, SAP (Applications), Software Vulnerability Management, Information Technology, Process Control Systems, Operational Systems - **Published:** August 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=264577279d2f2ecb ## About the Role EWEB will consider an equivalent combination of relevant education and experience when reviewing applications. Candidates who do not meet all the minimum qualifications, but whose application materials demonstrate the necessary knowledge, skills, and abilities to be successful in the position, are encouraged to apply. We understand that valuable experience can be gained through various avenues, and we value diverse experiences and unique perspectives. Education: Bachelor's degree in cybersecurity, computer science, or related field required. Licenses/Certifications: Certified Information Systems Security Professional (CISSP) certification required, or the ability to obtain one within six months. Experience: Seven (7) years of progressive experience in cybersecurity, information security, or related fields required, including responsibility for leading functions such as cybersecurity architecture, security operations, governance, assurance, risk management, and program development. Nice-to-Have: Experience as a cybersecurity practitioner in utility or other OT organizations, including experience securing OT or other critical infrastructure environments. Experience assessing security controls for SAP or similar ERP platforms. Experience with NERC CIP standards. Audit, risk, and security-related training or certifications. Post-offer background check required: Yes. ## Description Leads cybersecurity architecture and control strategy across enterprise IT, operational technology, ERP, and other critical business systems. Develops and executes cybersecurity audit and assurance programs that validate controls, address compliance requirements, and drive consistent, data-informed risk treatment decisions. Develops and supports cybersecurity programs and operations to align cybersecurity outcomes with EWEB's strategic objectives and operational needs. This position opens July 31, 2026, and will remain open until filled. The first review of applications will occur on August 17, 2026. The Eugene Water & Electric Board (EWEB) is seeking a Cyber Security Architect to join a cybersecurity team supporting both IT and operational technology environments within Oregon's largest public utility. This role functions as a hands-on cybersecurity practitioner and leader working across security architecture, assurance, compliance, engineering, operations, incident response, vulnerability management, program development, and governance activities. Responsibilities are not confined to a single specialty area, and priorities shift based on operational need, risk posture, and active security conditions. Success in this role requires the ability to operate across multiple business functions and security domains, maintain effective prioritization in a high-demand environment, communicate at all levels across the organization, and apply pragmatic, risk-based judgment., Cybersecurity Architecture * Provide cybersecurity architecture development and consultation, representing Cyber Security as a member of the EWEB architecture team. * Lead and coordinate security reviews of technology solutions, including architectural, application, and compliance considerations. * Evaluate the benefits and risks of technology solutions and identify implementation strategies to enhance security posture. Security Governance & Assurance * Develop, maintain, and execute cybersecurity assurance activities, including internal assessments, third-party and regulatory audit support, compliance monitoring, and control validation. * Develop and maintain cybersecurity standards and related documents to support security governance and operational risk management. * Provide risk treatment recommendations to address non-compliance, remediation needs, audit and assessment findings, and other assurance outcomes. Cybersecurity Program Development * Develop and mature cybersecurity programs and capabilities, including processes, metrics, roles and responsibilities, resources, inventories, reporting mechanisms, accountability, and performance optimization. * Lead the cybersecurity education and awareness program to mature organizational risk awareness and security culture. Operational Security Enablement * Lead and support incident response program development, readiness, and execution, including plans, runbooks, response activities, and post-incident improvement. * Elevate operational security capabilities by integrating monitoring and other telemetry into actionable analysis and risk-informed response. * Provide primary and/or backup support for designated cybersecurity programs, processes, and technical security controls. Note: This job posting is intended to represent key areas of responsibility. It is not meant to be all inclusive and does not prescribe or restrict the work that may be assigned., * Technology architecture, engineering, and technical control design across the enterprise technology stack, including cloud, identity, network, endpoint, database, and related security technologies. * Cybersecurity governance, risk, and compliance, including the ability to evaluate technical security risks and translate them into business impact and risk treatment considerations. * Planning and performing cybersecurity assessments and supporting audits, including evaluating control design, implementation, and effectiveness. * SAP or similar ERP security and control environments, including related experience with access controls, segregation of duties, role design, and evaluation of application-level security controls. * Operational technology (OT) security concepts, including industrial control systems, network segmentation, monitoring constraints, and security considerations specific to OT environments. Skills in: * Project management. * Architecture, deployment, and operation of complex technical systems to address business needs. Ability to: * Effectively communicate complex cybersecurity-related concepts to technical and non-technical audiences at all levels. * Provide cybersecurity leadership, mentorship, and guidance across teams, influencing outcomes and supporting effective collaboration without direct authority. * Develop and lead cybersecurity programs and initiatives with limited management guidance, owning outcomes, priorities, and stakeholder coordination. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)