Competitive Power Ventures, Inc. (“CPV”), with headquarters in Silver Spring, MD, and offices in Braintree, MA and Sugar Land, TX, is uniquely positioned to leverage global technology and financial partnerships to help modernize America’s power generation. We are driven to improve our energy infrastructure by developing and operating power generation facilities using cutting edge, domestically available natural gas, and renewable power technology. CPV is owned by OPC Energy, the first privately held electric company in Israel. OPC Energy became a public company in August 2017 and is traded on the Tel-Aviv Stock Exchange (TASE: OPCE).
CPV is seeking a Director of Cybersecurity to join our Information Technology Department in our Silver Spring, MD office.
The Director will work closely with Information Technology, Operational Technology, Asset Management, Energy Management, Application Services, Legal, Human Resources, Internal Audit, business leaders, and third-party service providers to identify, communicate, prioritize, and manage cybersecurity risks appropriately.
The position requires a leader who can operate effectively at both the strategic and technical levels, translating cybersecurity risks into business terms for senior management while providing direction and oversight for cybersecurity technologies, processes, and personnel.
Key Responsibilities:
- Develop, maintain, and execute CPV’s enterprise cybersecurity strategy and multi-year cybersecurity roadmap.
- Advise the Vice President of Information Technology and senior management on cybersecurity risks, emerging threats, regulatory developments, and recommended investments.
- Establish cybersecurity priorities based on business risk, regulatory requirements, operational requirements, and CPV’s risk tolerance.
- Develop annual cybersecurity objectives, budgets, initiatives, and performance metrics.
- Provide cybersecurity leadership across corporate IT, cloud, SaaS, data, and OT environments.
- Coordinate cybersecurity activities across CPV’s corporate offices and generation assets
- Manage cybersecurity personnel, consultants, managed security providers, and other third-party cybersecurity resources.
- Develop, maintain, and enforce CPV cybersecurity policies, standards, procedures, and technical controls.
- Maintain governance over areas including access management, privileged access, change management, vulnerability management, incident response, data protection, third-party security, remote access, and artificial intelligence.
- Establish cybersecurity metrics and Key Risk Indicators (KRIs) to measure the effectiveness and maturity of CPV’s cybersecurity program.
Cyber Risk Management
- Lead enterprise cybersecurity risk assessments and maintain visibility into significant cyber risks.
- Coordinate vulnerability assessments, penetration testing, security reviews, and remediation programs.
- Ensure vulnerabilities and cybersecurity findings are appropriately prioritized, assigned, tracked, and remediated.
Security Operations
- Provide leadership and oversight for CPV’s cybersecurity monitoring and security operations capabilities.
- Oversee endpoint security, identity security, email security, cloud security, network security, vulnerability management, threat detection, and security monitoring.
Incident Response & Business Continuity
- Own and maintain CPV’s cybersecurity incident response program.
- Maintain cybersecurity incident response plans, escalation procedures, communications protocols, and response playbooks.
- Coordinate cybersecurity tabletop exercises and incident simulations with IT, OT, Legal, Communications, Human Resources, Asset Management, and senior leadership.
- Partner with Infrastructure & Operations and business stakeholders to support disaster recovery and business continuity planning.
Operational Technology (OT) Cybersecurity
- Partner with CPV’s OT leadership, plant personnel, Asset Management, and third-party providers to establish and maintain cybersecurity protections for operational environments.
- Coordinate OT cybersecurity risk assessments, vulnerability assessments, and remediation efforts.
- Support cybersecurity requirements associated with new plants, renewable assets, SCADA implementations, and other operational technology projects.
Regulatory & Compliance
- Support CPV’s cybersecurity compliance obligations, including applicable NERC CIP requirements.
- Maintain alignment with recognized cybersecurity frameworks and practices, including the NIST Cybersecurity Framework (CSF).
- Coordinate cybersecurity audits, assessments, evidence collection, remediation activities, and management responses.
- Partner with Compliance, Legal, Internal Audit, and external auditors on cybersecurity-related reviews.
- Track regulatory and industry cybersecurity developments relevant to CPV and the energy industry.
AI & Emerging Technology Security
- Partner with IT and business leadership to establish security controls for CPV’s adoption of artificial intelligence and generative AI technologies.
- Evaluate cybersecurity risks associated with AI platforms, AI agents, enterprise integrations, and automated workflows.
- Ensure AI systems follow appropriate access controls, data protection requirements, approval processes, and least privilege principles.
- Participate in CPV’s AI governance process and review cybersecurity implications of proposed AI use cases.
- Monitor emerging technology risks and recommend appropriate security standards and controls.
Cybersecurity Awareness & Training
- Lead CPV’s cybersecurity awareness and education program.
- Coordinate employee cybersecurity training, phishing simulations, social engineering exercises, and targeted security communications.
- Develop specialized cybersecurity training for executives, IT personnel, privileged users, plant personnel, and other higher-risk groups.
- Promote a culture in which cybersecurity is viewed as a shared business responsibility.
Executive Reporting
- Develop regular cybersecurity reporting for the VP of Information Technology and senior management.
- Provide cybersecurity updates to CPV’s cybersecurity steering committee and other governance bodies.
- Develop executive-level reporting on cyber risks, incidents, vulnerabilities, remediation progress, compliance, and cybersecurity program maturity.
- Support cybersecurity reporting to the Audit Committee and/or Board of Directors as required.
Requirements:
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline, or equivalent professional experience.
- Approximately 10+ years of progressive experience in cybersecurity, information technology, infrastructure, or related disciplines.
- At least 5 years of cybersecurity leadership or management experience.
- Demonstrated experience developing or managing an enterprise cybersecurity program.
- Strong understanding of cybersecurity risk management, security architecture, vulnerability management, incident response, identity and access management, and security operations.
- Experience working with cloud and SaaS environments, particularly Microsoft technologies.
- Experience managing cybersecurity vendors, consultants, and managed security service providers.
- Strong written, verbal, executive presentation, and stakeholder-management skills.
- Ability to translate complex technical risks into understandable business risks and recommendations.
- Experience in power generation, energy, utility, industrial, or critical infrastructure sectors is preferred.
- Experience in presenting cybersecurity matters to executive management, Audit Committees, or Boards is preferred.
- One or more of the following certifications is preferred:
o CISSP – Certified Information Systems Security Professional
o Relevant Microsoft or cloud security certifications - Must pass a pre-employment background and financial credit check
Compensation: The base annual salary range for this position is $165,000 – $195,000 in the Company’s good faith estimate. The actual base salary for this position will be contingent upon individual experience, role responsibilities, and office location.
In addition to base salary, this position allows additional compensation and benefits, including:
- an annual discretionary bonus up to 30%, fully contingent based on individual and company performance,
- paid time off (PTO) of 160 hours per year, hours earned monthly, and up to 13 company paid holidays, and
- group benefits: 100% company paid medical, dental and vision coverage, a 401(k) plan with a 100% company match up to 6%, life insurance, short-and-long term disability, parental leave and flexible spending accounts.
The base annual salary range may be modified in the future.
Competitive Power Ventures, Inc. reserves the right to change or terminate any or all benefit plans and/or plan design at its discretion.
CPV holds all employees to the highest ethical standards and is committed to conducting business with integrity, transparency and honesty to ensure our success.
CPV is an Equal Opportunity Employer.
CPV holds all employees to the highest ethical standards and is committed to conducting business with integrity, transparency and honesty to ensure our success.
CPV is an Equal Opportunity Employer.
