Vice President, Chief Information Security Officer

Eversource Energy
Berlin, CT, United States
27 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cloud Computing Security Cyber Security Information Systems Disaster Recovery Executive Information Systems Identity and Access Management Information Systems Security Architecture Professional Secure Coding Software Engineering Cloud Platform System Software Security
+6 more
Model Validation AI Platforms Information Technology Process Control Systems Operational Systems Devsecops

Job description

The Vice President, Chief Information Security Officer (CISO) is the enterprise executive accountable for Eversource Energy’s cybersecurity strategy, cyber resilience, and secure enablement of business, operational, digital, data, and AI initiatives. The CISO leads the enterprise cybersecurity organization and partners with executive leadership, the Board, Legal, Compliance, Enterprise Risk Management, Information Technology, Operations, Engineering, and external stakeholders to protect operational reliability, customer trust, regulatory compliance, and enterprise value., * Transform and lead a high-performing cybersecurity organization through talent development, succession planning, organizational design, and strategic workforce planning.

  • Develop and execute a comprehensive enterprise cybersecurity strategy aligned with business objectives, risk appetite, regulatory requirements, and long-term corporate goals.
  • Develops and oversees implementation of strategic and tactical operating plans for the area, establishes operating and financial objectives, and aligns area plans, policies and programs with other areas of IT as well as the Company.
  • Serve as the principal advisor to executive leadership and the Board on cybersecurity strategy, cyber risk, emerging threats, resilience, regulatory developments, and investment priorities.
  • Lead enterprise cyber risk management activities, including risk identification, assessment, mitigation, monitoring, and risk acceptance governance.
  • Establishes and implements standards, procedures, and guidelines to prevent the unauthorized use, release, modification, or destruction of data in any form.
  • Responsible for closely monitoring emerging information security threats, assessing the company’s risk exposure, implementing mitigating measures and communicating information to key stakeholders on a timely basis.
  • Establish and maintain a comprehensive cybersecurity governance framework encompassing information security, operational technology (OT), industrial control systems (ICS), cloud environments, data protection, identity security, and third-party risk.
  • Direct the company’s cyber resilience program, including incident response, crisis management, cyber exercises, disaster recovery coordination, and business continuity integration.
  • Ensure effective protection of critical operational technology environments, including compliance with NERC CIP requirements and cybersecurity controls supporting grid reliability and operational resilience.
  • Ensures information security and compliance is addressed as a business issue across the company and provides overall coordination and management of all security and compliance activities within the company.
  • Develops and maintains high level relationships with business partner organizations to understand their business requirements and offer security solutions.
  • Lead cybersecurity governance for enterprise AI adoption, including AI security, data protection, model risk, third-party AI services, and responsible AI use.
  • Oversee identity and access management, privileged access management, cloud security, application security, DevSecOps, and data protection programs.
  • Manages the technical security team, including Security Managers and Supervisors, Security Engineers, Security Analysts, IT Compliance staff and Third Party Security resources and vendors.
  • Ensures Security team participation in the software development lifecycle to provide developers with the opportunity to develop secure code.
  • Monitors changes in industry-relevant legislation and accreditation.
  • Engages with Government and industry partners on cyber programs.
  • Manages all IT compliance programs (SOX, NERC/CIP, etc.).
  • Develop and maintain strong relationships with government agencies, industry organizations, regulators, law enforcement, intelligence-sharing organizations, and external security partners.
  • Lead cybersecurity awareness, education, and culture initiatives across the enterprise.
  • Establish and communicate meaningful cybersecurity metrics, key risk indicators, and executive dashboards to support decision-making and transparency., Responding to emergency situations to meet customers’ needs is part of every employee’s role. If employed, you will be given an Emergency Restoration assignment. This means you may be called to assist during an emergency outside of your normal responsibilities, work hours and location.

Requirements

  • Strong business/relevant industry acumen
  • Ability to quickly articulate creative & alternative methods for solving security-specific business problems
  • Hands-on leadership style
  • Excellent leadership skills and ability to lead organization through rapid change
  • Strong technical background
  • Background and style that elicits respect in the organization through management style, technical depth, customer service and results

  • Ability to influence others where there is no direct authority
  • Demonstrate proven ability to effectively lead and meet business objectives

Education:

  • Bachelor’s degree in Cyber Security, Computer Technology, Computer Science, Information Systems, or related degree. A Master’s Degree is preferred

Experience:

  • Minimum of 15 years of experience in Information Security.

Licenses & Certifications:

  • Certified Information Systems Security Professional (CISSP) and/or Certificate Information Security Manager (CISM). Individual should possess a US Security Clearance or the ability to obtain a clearance.

Working Conditions:

  • Must be available to work emergency restoration assignment as required.
  • Must be available to travel between MA/CT/NH as necessary.

corpajd

LI-ES3

Competencies:

Build trusting relationships

Manage and develop people

Foster teamwork and cross-functional collaboration

Lead change

Communicate strategic vision

Create an engaged workforce

Focus on the customer

Benefits & conditions

Eversource offers a competitive total rewards program. Check out our careers site for an overview of our benefits programs. Salary is commensurate with your experience. This position is eligible for a potential incentive. The annual salary range for this position is

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:36 min

Choosing between managed AI platforms and custom governance

Péter Farkas Péter Farkas · Europe 2026 Virtual

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:03 min

Career evolution in data engineering and AI platforms

Maria Apazoglou · Coffee With Developers

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

Videos

See all

Related articles

See all