Duquesne Light Company, headquartered in downtown Pittsburgh, is a leader in providing electric energy and has been in the forefront of the electric energy market, with a history rooted in technological innovation and superior customer service. Today, the company continues its role as a leader in the transmission and distribution of electric energy, providing a secure supply of reliable power to more than half a million customers in southwestern Pennsylvania. Duquesne Light Company is committed to creating a culture of inclusion. We value and respect the unique differences and experiences of our employees. We believe that our differences lead to better collaboration, innovation and outcomes. We want you to join our team! Location Hybrid -Downtown, Pittsburgh The Director of Cybersecurity will lead our corporate cybersecurity initiatives. This role will be responsible for overseeing all aspects of cybersecurity, including identity and access management, end-point security, network security, application security, data security, and cloud security. The Director of Cybersecurity will work closely with the CISO to develop and implement comprehensive security strategies to protect our organization's information assets. Location: Hybrid, downtown Pittsburgh, Pennsylvania. Key Responsibilities:
- Develop and implement a robust cybersecurity strategy in alignment with the organization's goals and objectives.
- Oversee identity and access management (IAM) to ensure secure access to systems and data with a forward-looking view towards a Zero Trust based environment.
- Develop and implement zero trust strategies to ensure robust security across all surfaces such as data, applications, assets, and services.
- Lead the end-point security initiatives to protect devices and endpoints from cyber threats.
- Manage network security to safeguard the organization's network infrastructure.
- Ensure application security by implementing DevSecOps best practices and conducting regular security assessments.
- Oversee data security measures to protect sensitive information from unauthorized access and breaches.
- Develop and maintain cloud security protocols to secure cloud-based assets, workloads, identities, and services.
- Ensure compliance with NERC CIP (North American Electric Reliability Corporation Critical Infrastructure Protection) standards and requirements.
- Conduct regular incident response exercises to prepare for and mitigate potential security incidents.
- Align incident response processes with the MITRE ATT&CK framework to enhance threat detection and response capabilities.
- Monitor and respond to security incidents and breaches, conducting thorough investigations and implementing corrective actions.
- Manage relationships with Managed Security Service Providers (MSSPs) to ensure effective and efficient security operations.
- Collaborate with other IT teams to ensure seamless integration of cybersecurity measures across all technology initiatives.
- Integrate cybersecurity into enterprise architecture through collaboration and engagement with key stakeholders.
- Manage and lead a diverse team of technical cybersecurity analysts, engineers, and specialists to ensure the security and integrity of our organization's information systems.
- Create and implement training and development plans to enhance the skills and knowledge of the cybersecurity team.
- Develop cybersecurity workforce plans, assessments, strategies, and guidance, including staff training, education, and rotational processes.
- Adjust in response to or in anticipation of changes to cybersecurity-related policy, technology, and staffing needs and requirements.
- Collaborate with external partners such as industry peers, law enforcement, and state and federal agencies to strengthen cybersecurity defenses and share threat intelligence.
- Plan, estimate costs, budget, develop, implement, and manage product support strategies to field and maintain the readiness and operational capability of systems and components.
- Stay up to date with the latest cybersecurity trends, threats, and technologies to continuously improve the organization's security posture.
- Provide leadership and guidance to the cybersecurity team, fostering a culture of security awareness and continuous improvement.
- Prepare and present regular reports on the status of cybersecurity initiatives to the CISO and executive management.
Education and Experience
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. A master's degree is preferred.
- Fifteen (15+) or more years related experience, including ten (10+) years previous management experience required.
- Previous experience as a CISO preferred.
- Strong demonstrable experience in and knowledge of identity and access management, end-point security, network security, application security, data security, and cloud security.
- Relevant certifications such as CISSP, CISM, or SANS certifications are highly desirable.
- Prefer demonstrated experience and understanding of NERC CIP standards to ensure compliance and enhance critical infrastructure protection.
- Proven track record of developing and implementing successful cybersecurity strategies, programs and/or technologies.
- Excellent leadership, communication, and interpersonal skills.
- Ability to work effectively in a fast-paced, dynamic environment.
- Strong analytical and problem-solving skills.
Leadership Skills and Abilities:
- Excellent leadership, communication, and interpersonal skills.
- Ability to work effectively in a fast-paced, dynamic environment.
- Strong analytical and problem-solving skills.
EQUAL OPPORTUNITY EMPLOYER
Duquesne Light Holdings is committed to providing equal employment opportunity to all people in all aspects of the employment relationship, without discrimination because of race, age, sex, color, religion, national origin, disability, sexual orientation and gender identity or status as a Vietnam era or special disabled veteran or any other unlawful basis, as defined by applicable law, and fostering a workplace free of unlawful discrimination and retaliation. This policy affects decisions including, but not limited to, hiring, compensation, benefits, terms and conditions of employment, opportunities for promotion, transfer, layoffs, return from a layoff, training and development, and other privileges of employment. An integral part of Duquesne Light Holdings' commitment is to comply with all applicable federal, state and local laws concerning equal employment and affirmative action. Duquesne Light Holdings is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. Our goal is to foster an inclusive and accessible workplace where everyone has the opportunity to be successful. If you need a reasonable accommodation to search for a job opening, apply for a position, or participate in the interview process, connect with us at HR@duqlight.com and describe the specific accommodation requested for a disability-related limitation.
|