Senior Manager Cybersecurity
Charlotte, NC Hybrid
Salary not listedJobFig found this opening at its original source and checks that it remains available.
About the role
Leads Duke Energy’s Cybersecurity Supply Chain Risk Management (C-SCRM), Third-Party Risk Management (TPRM), and Cybersecurity Culture & Awareness programs. Responsible for establishing strategy, governance, operational processes, and performance metrics that identify, assess, mitigate, monitor, and report cybersecurity risk arising from suppliers, vendors, service providers, software providers, cloud providers, and other external dependencies. Oversees the enterprise cybersecurity culture and awareness program to strengthen employee security behaviors, reduce human risk, and improve organizational cyber resilience. Leads managers and cybersecurity professionals responsible for supplier and third-party cyber risk assessments, continuous monitoring, contractual cybersecurity requirements, secure software supply chain governance, awareness training, phishing resilience, culture measurement, and executive engagement programs. Ensures alignment with cybersecurity strategy, regulatory obligations, business objectives, and industry frameworks. No. This is not a Visa Sponsored Position. This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future.
What you'll bring
- Bachelors degree in Cybersecurity, Computer Science, Management Information Systems, or Other Related Degree
- Minimum 10 years related work experience
- In lieu of Bachelors degree(s) AND 10 year(s) related work experience listed above, High School/GED AND 14 year(s) related work experience
- Bachelor of Science or Bachelor of Arts degree
- 10+ years of experience in Cybersecurity fields, or roles focused on cybersecurity or IT functions, to include at least 1 year of managerial experience in addition to a degree OR 14+ years of Cybersecurity related experience, to include at least 1 year of managerial experience in lieu of a degree
- Ability to obtain one of the following within three years of hire: Certified Information Systems Security Professional (CISSP), Certified Cybersecurity Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials.
- 5-15%
- Experience designing, implementing, and leading Third Party Risk Management (TPRM) programs at scale.
- Knowledge of applicable NIST and ISO 27001/27036 Cybersecurity standards along with SOC1/SOC2 Type 1/Type 2 reports.
- Strong experience addressing senior-level leadership and the ability to collaborate and lead cross-functional teams and initiatives.
- Experience in inspiring change and leading a large-scale risk management framework in a large company.
- Excellent written and verbal communica t i on skills, interpersonal and collaborative skills, and the ability to communicate cybersecurity and risk-related concepts to technical and nontechnical audiences at various hierarchical levels, ranging from indiv i dual contributors to senior staff.