Vice President, Chief Information Security Officer
Eversource Energy
- Location
- Berlin, CT
- Work model
- On-Site
- Level
- Staff
- Posted
- 16h ago
Skills
About this role
Eversource will not offer immigration-related sponsorship for this position (e.g., H-1B, O-1, J-1, TN, E-3, etc.). Applicants requiring visa sponsorship to start employment with Eversource will not be considered. Vice President, Chief Information Security Officer Job Description The Vice President, Chief Information Security Officer (CISO) is the enterprise executive accountable for Eversource Energy’s cybersecurity strategy, cyber resilience, and secure enablement of business, operational, digital, data, and AI initiatives. The CISO leads the enterprise cybersecurity organization and partners with executive leadership, the Board, Legal, Compliance, Enterprise Risk Management, Information Technology, Operations, Engineering, and external stakeholders to protect operational reliability, customer trust, regulatory compliance, and enterprise value.
Key Responsibilities
Transform and lead a high-performing cybersecurity organization through talent development, succession planning, organizational design, and strategic workforce planning. Develop and execute a comprehensive enterprise cybersecurity strategy aligned with business objectives, risk appetite, regulatory requirements, and long-term corporate goals. Develops and oversees implementation of strategic and tactical operating plans for the area, establishes operating and financial objectives, and aligns area plans, policies and programs with other areas of IT as well as the Company. Serve as the principal advisor to executive leadership and the Board on cybersecurity strategy, cyber risk, emerging threats, resilience, regulatory developments, and investment priorities. Lead enterprise cyber risk management activities, including risk identification, assessment, mitigation, monitoring, and risk acceptance governance. Establishes and implements standards, procedures, and guidelines to prevent the unauthorized use, release, modification, or destruction of data in any form. Responsible for closely monitoring emerging information security threats, assessing the company’s risk exposure, implementing mitigating measures and communicating information to key stakeholders on a timely basis. Establish and maintain a comprehensive cybersecurity governance framework encompassing information security, operational technology (OT), industrial control systems (ICS), cloud environments, data protection, identity security, and third-party risk. Direct the company’s cyber resilience program, including incident response, crisis management, cyber exercises, disaster recovery coordination, and business continuity integration. Ensure effective protection of critical operational technology environments, including compliance with NERC CIP requirements and cybersecurity controls supporting grid reliability and operational resilience. Ensures information security and compliance is addressed as a business issue across the company and provides overall coordination and management of all security and compliance activities within the company. Develops and maintains high level relationships with business partner organizations to understand their business requirements and offer security solutions. Lead cybersecurity governance for enterprise AI adoption, including AI security, data protection, model risk, third-party AI services, and responsible AI use. Oversee identity and access management, privileged access management, cloud security, application security, DevSecOps, and data protection programs. Manages the technical security team, including Security Managers and Supervisors, Security Engineers, Security Analysts, IT Compliance staff and Third Party Security resources and vendors. Ensures Security team participation in the software development lifecycle to provide developers with the opportunity to develop secure code. Monitors changes in industry-relevant legislation and accreditation. Engages with Government and industry partners on cyber programs. Manages all IT compliance programs (SOX,