Description
We are seeking a visionary Chief Information Security Officer (CISO) to lead the cybersecurity strategy for our innovative renewable energy technology company. In this executive role, you will define and execute our enterprise-wide security governance, risk, and compliance programs. You will be responsible for building and mentoring a world-class security team, establishing robust control frameworks, and architecting security for our cloud platforms, applications, and distributed infrastructure. This position requires a strategic leader who can translate complex technical risks into business-centric terms for executive leadership. Your expertise will be critical in maturing our security posture, managing incident response, and ensuring the resilience of the digital assets that power the future of energy. Join us to secure the critical technology at the forefront of the green energy transition.
Requirements
1. Minimum of 5 years of experience in a senior cybersecurity leadership role (e.g., Director, Head of Security, CISO).
2. Demonstrated expertise in designing and implementing enterprise-wide security governance, including threat modeling, maturity modeling, and control frameworks (NIST, MITRE ATT&CK).
3. Deep technical knowledge of cloud security architecture and services, specifically within AWS.
4. Strong background in application security (AppSec) and integrating security into the CI/CD pipeline (DevSecOps).
5. Proven experience leading compliance and audit programs for frameworks such as SOC 2, ISO 27001, and GDPR.
6. Hands-on experience leading incident response for major security events, from detection through remediation and post-mortem.
7. Expertise in securing digital assets, cryptographic systems, and distributed infrastructure environments.
8. Proven ability to build, mentor, and lead high-performing, multi-disciplinary security teams.
Desirable
1. Experience in the energy, manufacturing, or critical infrastructure sectors.
2. Professional certifications such as CISSP, CISM, or CCSP.
3. Direct experience with offensive security, penetration testing, or Capture The Flag (CTF) competitions.
4. Familiarity with securing Operational Technology (OT) and IoT systems.
5. Experience presenting security strategy and risk posture to a Board of Directors.