Bachelor’s degree in Information Systems, related technical field or equivalent experience (degree in Information Security or security certification preferred)
10+ years of experience in information security, with at least 2 years in a lead role within a security or security architecture team
Extensive understanding of IT Security standards and solutions, Application Security (Secure SDLC including agile), and underlying principles of networking, infrastructure, and system integration
Familiarity with current and proposed laws, regulations, industry standards, and ethical requirements related to information security and privacy
Experience with one or more of: security monitoring, database security, policy and procedure, Active Directory, cryptography/PKI, application security, secure SDLC, risk assessments, security awareness, or related information security subject area
Experience in cloud technologies including Azure
Knowledge of Operational Technology and NERC CIP desired
Strong working knowledge of information systems security standards and practices
Proven track record in security architecture and leadership
Ability to partner effectively across IT, business units, and executive leadership
Decisive, strategic, and collaborative; ability to set clear priorities and drive measurable improvements
Ability to multi-task, anticipate and respond to changing priorities, and operate effectively in a dynamic demand-based environment
Must be available to work emergency storm assignments as required and travel between MA/CT/NH as necessary
Competencies: Build trusting relationships, manage and develop people, foster teamwork and cross-functional collaboration, lead change, communicate strategic vision, create an engaged workforce, focus on the customer, take ownership & accountability
Responsibilities
Lead, mentor, and develop a team of 10+ security architects, fostering a culture of problem solving, partnership, and accountability
Partner with business, IT leaders, and project teams to design secure solutions from the start
Ensure architecture standards and security policies are enforced across projects and programs
Ensure security architecture aligns with industry best practices, regulatory requirements, and emerging threats
Develop Eversource Security Standards and ensure alignment with Eversource Enterprise Architecture and Solution Architecture teams
Serve as a trusted advisor to senior leadership on security architecture and risk-related decisions
Champion the adoption of innovative security solutions that improve efficiency and protection
Continuously assess and improve security architecture processes and practices
When Eversource security standards cannot be met, work with business to document policy exceptions in GRC (Governance Risk & Compliance) tool
Produce high quality oral and written work, presenting complex technical matters clearly and concisely to audiences ranging from peers to Senior Management
Recommend effective process changes to enhance defense and response procedures
Assist with annual SOX, CIP, and SOC assessments and related remediation efforts
Set the vision, strategy, and roadmap for security architecture across the organization, ensuring alignment with business objectives and compliance requirements