North Carolina's Electric Cooperatives · 4 hours ago
Director, Enterprise Security
North Carolina's Electric Cooperatives is a leading generation and transmission cooperative in the nation, seeking a Director of Enterprise Security. This role is responsible for developing and implementing an enterprise security program that encompasses both cybersecurity and physical security, ensuring the protection of information assets and critical infrastructure.
Electrical DistributionEnergyRenewable Energy
Responsibilities
Develop and execute an enterprise-wide security strategy covering both cyber and physical security domains
Establish and maintain policies, standards, procedures, and site security plans aligned with industry best practices (e.g., ASIS, DHS CISA, NFPA, NERC)
Coordinate enterprise risk management activities: risk assessments, criticality analyses, threat/vulnerability reviews, and remediation roadmaps
Define security architecture and control baselines across IT, OT, facilities, and corporate environments
Oversee the Manager of Cybersecurity, including policy development, regulatory compliance, security assessments (internal and third-party), and incident response planning and execution
Ensure security is integrated into SDLC, data platforms, and EMS/OT systems; collaborate with Software Development and Data Management teams to embed cybersecurity controls
Oversee audit readiness and compliance with applicable standards and regulations (e.g., NERC CIP where applicable)
Manage cybersecurity awareness and training for all staff and facilitate executive briefings and security committee meetings
Oversee the Manager of physical security systems to ensure NCEMC’s seven facilities across the state of NC are safe and secure
Lead and coordinate response to physical security incidents; manage investigations and reporting with law enforcement and regulatory agencies
Plan and execute security infrastructure projects balancing cost, risk reduction, regulatory compliance, and operational impact
Prepare and manage budgets for cybersecurity and physical security operations and capital initiatives
Develop and deliver training for employees, contractors, member organizations, and security personnel on site access, reporting, and emergency response protocols
Establish criteria for coordinate drills and exercises in collaboration with internal safety personnel and relevant external partners
Ensure compliance with regulatory requirements and maintain audit readiness, including NERC CIP-003-8 (where applicable)
Define and report security performance metrics, risks, and improvement plans for senior leadership
Maintain and continuously improve the incident response plan and business continuity interfaces
Manage and mentor the cybersecurity and physical security managers
Foster strong cross-functional relationships with IT, operations, facilities, and business units to integrate security into daily operations and strategic initiatives
Qualification
Required
Bachelor's degree in computer science, Information Security, Security Management, Emergency Management, or a related field. An equivalent combination of education, training, and relevant work experience may be substituted for the degree requirement
6–10 years of progressive experience across IT/cybersecurity and physical security, including at least 5+ years focused on cybersecurity/physical security
3–5+ years of leadership/management experience in security or IT
Working knowledge of IT hardware, operating systems, applications, and datacenter operations
Proven ability to lead and develop teams (cyber and physical security) and manage contractors/vendors
Strong oral and written communication; effective presentation skills for technical and executive audiences
Demonstrated customer and colleague relationship-building skills; cross-functional collaboration
Strength in risk assessment, incident/crisis management, analytical thinking, problem solving, conflict resolution, and adaptability
Preferred
A master's degree is preferred
Advanced security certifications such as CISSP, CISM, CISA, CRISC, or CCISO are strongly preferred
Electric utility operations experience preferred (including familiarity with substations, control centers, and generation facilities)
Familiarity with CIS (Center for Internet Security) security frameworks and maturity models
Company
North Carolina's Electric Cooperatives
North Carolina’s electric cooperatives are a network of not-for-profit electric utility organizations powering the days and empowering the lives of 2.8 million North Carolinians from the mountains to the coast.
Funding
Current Stage
Growth StageLeadership Team
Recent News
Company data provided by crunchbase