Sr. Manager, Cybersecurity
Duration : 6+ Months
Location : Houston, TX
Position Summary
The Sr. Manager, Cybersecurity leads comprehensive cybersecurity operations and strategy to protect ProEnergy's critical infrastructure and business systems from evolving cyber threats. This role manages cybersecurity teams, implements security controls across IT and OT environments, and ensures regulatory compliance including NERC-CIP standards for critical infrastructure protection. The position combines strategic cybersecurity leadership with operational oversight to safeguard power generation facilities, manufacturing operations, and business systems across 40+ countries while enabling digital transformation initiatives.
Reports To : Vice President, IT Operations
Direct Reports : 2-4 Cybersecurity Analysts and Specialists
Location : Houston, TX with global cybersecurity responsibility
Travel : 20-25%
Position Responsibilities
- Develop and implement comprehensive cybersecurity strategy aligned with business objectives
- Manage enterprise cybersecurity program across IT and operational technology (OT) environments
- Establish cybersecurity governance framework including policies, standards, and procedures
- Lead threat landscape analysis and security risk assessment initiatives
- Coordinate cybersecurity integration with digital transformation and cloud adoption projects
- Oversee cybersecurity budget planning and resource allocation
- Manage Security Operations Center (SOC) providing 24 / 7 monitoring and threat detection
- Lead incident response program with coordinated response to cybersecurity events
- Oversee security technology stack including SIEM, EDR, firewalls, and threat intelligence platforms
- Coordinate threat hunting and advanced persistent threat (APT) detection capabilities
- Manage security metrics, reporting, and communication to executive leadership
- Establish relationships with law enforcement, government agencies, and industry partners
- Ensure compliance with NERC-CIP Critical Infrastructure Protection standards
- Manage SOX IT controls implementation and testing for financial systems
- Coordinate compliance with industry standards (ISO 27001, NIST Cybersecurity Framework)
- Oversee third-party risk assessment and vendor security management programs
- Lead regulatory audit preparation and coordinate with external auditors
- Maintain cybersecurity risk register and executive risk reporting
- Lead and develop the cybersecurity team including analysts, engineers, and specialists
- Recruit and hire cybersecurity professionals across multiple specializations
- Conduct performance evaluations and create individual development plans
- Implement professional development programs and certification pathways
- Coordinate security training and awareness programs for all employees
- Evaluate and implement advanced cybersecurity technologies and solutions
- Oversee deployment of zero-trust security architecture and micro-segmentation
- Manage identity and access management (IAM) and privileged access management programs
- Coordinate security architecture for cloud platforms and hybrid environments
- Implement security automation and orchestration (SOAR) capabilities
- Ensure integration of security controls with operational technology systems
Required Qualifications
Bachelor's degree in Cybersecurity, Computer Science, or related field (master's preferred)Minimum 5-8 years of progressive cybersecurity experienceMinimum 3 years of cybersecurity management and team leadership experienceExperience with critical infrastructure or regulated industry security requirementsExpert knowledge of cybersecurity frameworks, technologies, and best practicesAdvanced proficiency with SIEM platforms, security analytics, and threat detection toolsStrong experience with incident response, digital forensics, and threat huntingWorking knowledge of operational technology (OT) and industrial control systems securityUnderstanding of cloud security, identity management, and zero-trust architectureFamiliarity with security automation, threat intelligence, and advanced security toolsProven ability to lead and develop cybersecurity teamsStrong strategic thinking and program management capabilitiesExcellent communication skills for executive and board-level reportingExperience with budget management and vendor relationship managementAbility to translate technical risks into business languageDeep understanding of NERC-CIP Critical Infrastructure Protection standardsExperience with SOX IT controls, ISO 27001, and cybersecurity compliance frameworksKnowledge of privacy regulations (GDPR, state privacy laws) and data protectionFamiliarity with incident reporting requirements and regulatory coordinationUnderstanding of risk management methodologies and quantitative risk analysisDesired Qualifications
Experience with advanced persistent threat (APT) detection and responseKnowledge of artificial intelligence and machine learning for cybersecurityUnderstanding of deception technologies and active defense strategiesExperience with cloud security architecture and DevSecOps practicesFamiliarity with emerging threats including AI-powered attacks and quantum computing risksExperience in power generation, utilities, or energy sector cybersecurityKnowledge of manufacturing and operational technology securityUnderstanding of global cybersecurity operations and international regulationsExperience with merger and acquisition cybersecurity due diligenceBackground in public-private partnerships and government collaborationExperience with board-level cybersecurity reporting and communicationStrategic planning and business case development capabilitiesCrisis leadership during major cybersecurity incidentsIndustry thought leadership and public speaking experienceUnderstanding of cyber insurance and business continuity planningCertifications Required
CISSP (Certified Information Systems Security Professional)CISM (Certified Information Security Manager) or equivalent management certificationNERC-CIP certification or demonstrated compliance experiencePreferred
CISA (Certified Information Systems Auditor)Advanced technical certifications (GCIH, GPEN, cloud security certs)Project management (PMP) or business management (MBA) credentialsWorking Conditions
Office environment with occasional visits to secure facilities and operations centersStandard business hours with 24 / 7 availability for cybersecurity incidentsUltimate accountability for cybersecurity incident response and crisis management