Vice President, Chief Information Security Officer
Eversource will not offer immigration-related sponsorship for this position. Applicants requiring visa sponsorship to start employment will not be considered.
About the role
The Vice President, Chief Information Security Officer (CISO) is the enterprise executive accountable for Eversource Energy’s cybersecurity strategy, cyber resilience, and secure enablement of business, operational, digital, data, and AI initiatives. The CISO leads the enterprise cybersecurity organization and partners with executive leadership, the Board, Legal, Compliance, Enterprise Risk Management, Information Technology, Operations, Engineering, and external stakeholders to protect operational reliability, customer trust, regulatory compliance, and enterprise value.
Responsibilities
- Transform and lead a high-performing cybersecurity organization through talent development, succession planning, organizational design, and strategic workforce planning.
- Develop and execute a comprehensive enterprise cybersecurity strategy aligned with business objectives, risk appetite, regulatory requirements, and long-term corporate goals.
- Develop and oversee implementation of strategic and tactical operating plans for the area, establish operating and financial objectives, and align area plans, policies, and programs with other areas of IT as well as the Company.
- Serve as the principal advisor to executive leadership and the Board on cybersecurity strategy, cyber risk, emerging threats, resilience, regulatory developments, and investment priorities.
- Lead enterprise cyber risk management activities, including risk identification, assessment, mitigation, monitoring, and risk acceptance governance.
- Establish and implement standards, procedures, and guidelines to prevent the unauthorized use, release, modification, or destruction of data in any form.
- Responsible for closely monitoring emerging information security threats, assessing the company’s risk exposure, implementing mitigating measures, and communicating information to key stakeholders on a timely basis.
- Establish and maintain a comprehensive cybersecurity governance framework encompassing information security, operational technology (OT), industrial control systems (ICS), cloud environments, data protection, identity security, and third-party risk.
- Direct the company’s cyber resilience program, including incident response, crisis management, cyber exercises, disaster recovery coordination, and business continuity integration.
- Ensure effective protection of critical operational technology environments, including compliance with NERC CIP requirements and cybersecurity controls supporting grid reliability and operational resilience.
- Ensure information security and compliance is addressed as a business issue across the company and provide overall coordination and management of all security and compliance activities within the company.
- Develop and maintain high-level relationships with business partner organizations to understand their business requirements and offer security solutions.
- Lead cybersecurity governance for enterprise AI adoption, including AI security, data protection, model risk, third-party AI services, and responsible AI use.
- Oversee identity and access management, privileged access management, cloud security, application security, DevSecOps, and data protection programs.
- Manage the technical security team, including Security Managers and Supervisors, Security Engineers, Security Analysts, IT Compliance staff, and Third Party Security resources and vendors.
- Ensure Security team participation in the software development lifecycle to provide developers with the opportunity to develop secure code.
- Monitor changes in industry-relevant legislation and accreditation.
- Engage with Government and industry partners on cyber programs.
- Manage all IT compliance programs (SOX, NERC/CIP, etc.).
- Develop and maintain strong relationships with government agencies, industry organizations, regulators, law enforcement, intelligence-sharing organizations, and external security partners.
- Lead cybersecurity awareness, education, and culture initiatives across the enterprise.
- Establish and communicate meaningful cybersecurity metrics, key risk indicators, and executive dashboards to support decision-making and transparency.
Requirements
- Bachelor’s degree in Cyber Security, Computer Technology, Computer Science, Information Systems, or related degree. A Master’s Degree is preferred.
- Minimum of 15 years of experience in Information Security.
- Certified Information Systems Security Professional (CISSP) and/or Certificate Information Security Manager (CISM).
- Individual should possess a US Security Clearance or the ability to obtain a clearance.
Skills
- Strong business/relevant industry acumen.
- Ability to quickly articulate creative & alternative methods for solving security-specific business problems.
- Hands-on leadership style.
- Excellent leadership skills and ability to lead organization through rapid change.
- Strong technical background.
- Background and style that elicits respect in the organization through management style, technical depth, customer service, and results.
- Ability to influence others where there is no direct authority.
- Demonstrated proven ability to effectively lead and meet business objectives.
Competencies
- Build trusting relationships.
- Manage and develop people.
- Foster teamwork and cross-functional collaboration.
- Lead change.
- Communicate strategic vision.
- Create an engaged workforce.
- Focus on the customer.
- Take ownership & accountability.
Working Conditions
- Must be available to work emergency restoration assignment as required.
- Must be available to travel between MA/CT/NH as necessary.
Benefits
Eversource offers a competitive total rewards program. Check out our careers site for an overview of our benefits programs.
This position is eligible for a potential incentive.