Principal Cybersecurity Strategy Consultant - Electric Utility

The Cybersecurity
United States
7 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$100,000.0 - $165,000.0
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Cyber Security Information Systems Identity and Access Management Information Systems Security Architecture Professional Power BI Software Security Cyber Threat Analysis

Job description

A cybersecurity consulting organization is seeking an experienced Principal Cybersecurity Strategy Consultant to support the continued development and execution of a enterprise cybersecurity strategy for a electric utility.

This role will work with cybersecurity executives, senior leaders, program owners, and technical teams to translate organizational priorities, cybersecurity assessments, operational needs, and business dependencies into a clear and actionable enterprise strategy.

The consultant will help mature an existing cybersecurity strategy, develop multi-year roadmaps, establish measurable milestones, clarify ownership across cybersecurity functions, and prepare executive-level materials that communicate progress, decisions, risks, and investment priorities.

The ideal candidate combines substantial electric-utility cybersecurity experience with strong strategic planning, management consulting, stakeholder facilitation, and executive communication skills. This position requires someone who can bring structure to ambiguous environments, explain complex reasoning concisely, and convert extensive technical and organizational information into practical decisions and deliverables.

Key Responsibilities

  • Support the continued development and execution of an enterprise-wide, cybersecurity strategy.
  • Translate cybersecurity assessments, organizational priorities, risk information, and operational needs into strategic goals, initiatives, and sequenced roadmaps.
  • Align cybersecurity strategy and initiatives with the NIST Cybersecurity Framework, applicable regulatory expectations, and electric-utility business objectives.
  • Facilitate working sessions with cybersecurity executives, senior managers, technical leaders, and cross-functional stakeholders.
  • Develop team-level plans that define mission, responsibilities, strategic objectives, initiatives, dependencies, milestones, and success measures.
  • Establish traceability between identified risks, cybersecurity capabilities, strategic objectives, funded initiatives, and expected maturity improvements.
  • Identify overlapping responsibilities, capability gaps, organizational dependencies, and areas requiring leadership decisions.
  • Develop phased implementation roadmaps with clear priorities, owners, target dates, assumptions, and dependencies.
  • Define practical performance indicators and reporting methods for measuring strategy execution, capability maturity, and risk reduction.
  • Support the integration of cybersecurity strategy information into dashboards and executive reporting tools, including Power BI.
  • Prepare concise executive briefings, decision materials, milestone updates, and recommendations for senior leadership.
  • Maintain structured documentation supporting key decisions, changes in direction, stakeholder feedback, and strategy evolution.
  • Provide clear weekly reporting on progress, accomplishments, upcoming activities, risks, decisions, and support needed.
  • Collaborate with project management, technical, governance, risk, and executive stakeholders to maintain alignment.
  • Support knowledge transfer and ensure strategic materials remain understandable, maintainable, and usable after the engagement.

Strategic Areas of Focus

The consultant may support cybersecurity functions including:

  • Security Operations and Incident Response
  • Cyber Threat Intelligence
  • Cybersecurity Architecture and Engineering
  • IT and OT/Grid Security
  • Vulnerability and Exposure Management
  • Identity and Access Management
  • Governance, Risk, and Compliance
  • Third-Party and Supply-Chain Risk
  • Data Security and Privacy
  • Cloud and Application Security
  • Cybersecurity Awareness and Workforce Development
  • Business Resilience and Recovery
  • Continuous Authorization and Risk-Based Decision-Making, The successful candidate must be able to independently evaluate complex information while maintaining clear alignment with the consulting organization, prime contractor, and client. Success requires more than cybersecurity expertise: the consultant must communicate progress clearly, document decision logic, establish realistic milestones, identify dependencies early, and produce executive-ready work that can be understood and acted upon by others.

This is not primarily a hands-on engineering or architecture position. The focus is enterprise cybersecurity strategy, roadmap development, stakeholder alignment, governance, executive communication, and sustained strategy execution.

Pay: $100,000.00 - $165,000.00 per year

Requirements

  • 15+ years of professional experience across cybersecurity, technology strategy, risk management, critical infrastructure, or management consulting.
  • 10+ years supporting electric utilities, energy organizations, or similarly complex critical-infrastructure environments.
  • Demonstrated experience developing enterprise cybersecurity strategies and multi-year transformation roadmaps.
  • Experience working within or directly supporting a CISO organization at a large, complex enterprise.
  • Strong understanding of electric-utility IT and OT cybersecurity environments, business operations, regulatory considerations, and organizational dependencies.
  • Demonstrated ability to translate technical assessments and cybersecurity risks into executive-level priorities and investment decisions.
  • Experience developing strategic objectives, capability models, operating models, governance structures, milestones, and performance measures.
  • Strong knowledge of cybersecurity frameworks and standards, including:
  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • NIST SP 800-82
  • NIST SP 800-207
  • Applicable utility and critical-infrastructure cybersecurity practices
  • Experience facilitating interviews, workshops, and working sessions with executives, senior managers, and technical stakeholders.
  • Ability to distinguish among enterprise strategy, capability roadmaps, technology roadmaps, implementation plans, and project-level deliverables.
  • Exceptional written and verbal communication skills, including the ability to provide direct and concise answers, explain supporting logic, and adapt content for executive and technical audiences.
  • Demonstrated ability to receive feedback constructively, resolve ambiguity collaboratively, and maintain alignment across multiple stakeholders.
  • Strong organizational skills and the ability to manage parallel workstreams, dependencies, and evolving priorities.
  • Ability to travel periodically for onsite meetings and workshops.
  • Fluent professional English.

Preferred Qualifications

  • Prior cybersecurity leadership or consulting experience with a large investor-owned electric utility.
  • Experience supporting enterprise NIST CSF assessments and converting assessment results into funded transformation roadmaps.
  • Familiarity with utility cybersecurity regulatory and risk environments, including NERC CIP.
  • Experience aligning cybersecurity initiatives with budgets, work orders, investment planning, and operational priorities.
  • Experience developing cybersecurity operating models, governance structures, and executive reporting programs.
  • PMP, CISM, CRISC, GIAC, or comparable professional certifications.
  • Master’s degree in cybersecurity, information systems, business administration, engineering, or a related discipline.

Engagement Profile

This is a senior strategy and advisory engagement intended for an experienced cybersecurity leader who can operate effectively between executives, program managers, and technical teams.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:24 min

Moving the semantic layer upstream to avoid vendor lock-in

Piotr Menclewicz Piotr Menclewicz · Europe 2026 Virtual

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

2:51 min

Alibaba Cloud developer resources and cloud computing training

Cheng Zhang · LIVE

Videos

See all

Related articles

See all