OverviewJOB PURPOSE
The AVP, Information and Cybersecurity is accountable for supporting SVP, Enterprise Technology in establishing, operating, and continuously improving the cybersecurity, technology risk, operational resilience, AI governance, and critical infrastructure protection capabilities that enable Pattern Energy to operate safely, reliably, and securely.
This role, with guidance from the SVP, Enterprise Technology, provides enterprise leadership across cybersecurity governance, cyber risk management, security operations, operational technology (OT) security, cyber resilience, identity and access governance, third-party risk management, AI security, and regulatory compliance activities. The role is responsible for protecting Pattern’s corporate, cloud, operational technology, generation, storage, and transmission environments while supporting business growth, operational reliability, and technology modernization.
The AVP, Information and Cybersecurity partners closely with Enterprise Technology, Power Operations, Engineering, EPC, Legal, Compliance, Internal Audit, Enterprise Excellence, and executive leadership teams to ensure cybersecurity, resilience, and technology risk management capabilities are embedded into enterprise operations and strategic decision-making.
Success in the role requires balancing operational reliability, safety, regulatory compliance, cybersecurity risk reduction, enterprise scalability, and disciplined execution while enabling innovation and reducing unnecessary complexity.
The AVP, Information and Cybersecurity is also accountable for ensuring the resilience, recoverability, and cybersecurity readiness of enterprise and operational technology environments supporting Pattern’s generation, storage, and transmission assets. This includes executive accountability for cybersecurity governance supporting NERC CIP obligations, cyber crisis management, operational resilience, and AI security governance.
This role helps drive enterprise prioritization, governance, and operational execution discipline in partnership with business leadership, Enterprise Excellence, and other enterprise stakeholders. The role is expected to build durable internal cybersecurity capability, improve cyber governance maturity, and reduce organizational dependency on fragmented processes and external implementation coordination.
The role serves as an advisor to the CEO, COO, Executive Leadership Team, and Board on cybersecurity, technology risk, operational resilience, AI governance, and critical infrastructure protection.
Key Accountabilities
Cybersecurity Strategy, Risk & Governance
- Develop and execute a multi-year cybersecurity, resilience, technology risk, and AI governance strategy aligned with enterprise objectives, operational priorities, and growth plans.
- Establish enterprise cybersecurity governance, risk management, and reporting processes that improve accountability, transparency, and decision quality.
- Ensure cybersecurity, resilience, AI, and technology risks are appropriately incorporated into enterprise planning, investment decisions, acquisitions, integrations, and strategic initiatives.
- Develop and manage cybersecurity operating and capital budgets, ensuring investments align with enterprise priorities, risk reduction objectives, resilience requirements, and regulatory obligations.
- Develop cybersecurity investment plans and assess initiatives based on risk reduction, operational resilience, business value, and long-term sustainability.
- With support from the SVP, Enterprise Technology, provide regular reporting to executive leadership and the Board regarding cyber risk posture, material incidents, resilience capabilities, emerging threats, regulatory developments, NERC CIP readiness, and strategic priorities.
- Conduct periodic cyber maturity assessments, benchmarking exercises, and independent reviews to support continuous improvement and strategic planning.
- Establish enterprise security awareness, education, executive cyber literacy, and AI awareness programs that promote a culture of security, resilience, and responsible technology use across the organization.
Cybersecurity Operations & Resilience
- Lead enterprise cybersecurity capabilities across threat detection, threat intelligence, vulnerability management, identity security, cloud security, incident response, cyber defense, and attack surface management.
- Ensure effective security governance and protection capabilities across enterprise infrastructure, cloud platforms, operational technology environments, and critical business systems.
- Ensure effective capabilities exist to identify, assess, respond to, and recover from cyber threats affecting enterprise and operational technology environments.
- Establish cyber crisis management, cyber recovery, business continuity, and disaster recovery capabilities appropriate for a critical infrastructure operating environment.
- Support incident response, disaster recovery, operational resilience, and technology risk management activities across the enterprise.
- Leverage automation and AI-enabled capabilities to improve cybersecurity effectiveness, operational efficiency, threat detection, investigation, response, and resilience outcomes.
- Ensure third-party cyber risk management capabilities appropriately address vendors, contractors, cloud providers, operational technology suppliers, EPC partners, and strategic service providers.
Operational Technology & Critical Infrastructure Security
- Lead cybersecurity strategy and governance supporting operational technology environments associated with generation, storage, transmission, SCADA, plant communications, industrial control systems, and operational support systems.
- Establish cybersecurity and resilience standards supporting operational technology architecture, remote access, network segmentation, monitoring, asset visibility, vendor connectivity, and secure operations.
- Support operational readiness, secure operations, recoverability, and resilience across critical infrastructure environments.
- Coordinate with operational stakeholders to ensure technology environments meet reliability, safety, resilience, and compliance expectations.
- Support secure integration of new facilities, operational technologies, acquisitions, and strategic growth initiatives.
- Ensure cybersecurity capabilities evolve in alignment with emerging threats affecting operational technology and critical infrastructure environments.
Regulatory Compliance & NERC CIP
- Ensure cybersecurity operations align with applicable regulatory, cybersecurity, operational risk management, and NERC CIP requirements.
- Serve as the executive sponsor for NERC CIP cybersecurity governance, audit readiness, compliance activities, and remediation programs.
- Oversee compliance reporting, evidence management, remediation tracking, control validation, and regulatory readiness activities.
- Partner with Legal, Compliance, Internal Audit, Enterprise Technology, and operational stakeholders to maintain effective governance and regulatory alignment.
- Monitor evolving regulatory requirements and industry standards and ensure timely adaptation of policies, controls, and operating procedures.
- Establish metrics and reporting that provide visibility into compliance posture, control effectiveness, audit readiness, and remediation progress.
AI Security & Governance
- Establish enterprise governance, risk management, and security practices supporting responsible adoption of AI technologies.
- Ensure AI systems, AI agents, autonomous workflows, and third-party AI services are appropriately inventoried, governed, monitored, and secured.
- Establish governance and security requirements for AI systems, AI agents, and autonomous workflows used across enterprise and operational environments, ensuring appropriate human oversight, accountability, and risk management.
- Protect AI-enabled business processes, models, training data, prompts, retrieval data, and outputs from unauthorized access, misuse, manipulation, or disclosure.
- Support adoption of AI technologies while maintaining appropriate cybersecurity, privacy, operational, and regulatory safeguards.
- Drive adoption of AI-enabled cybersecurity capabilities that improve operational efficiency, threat detection, vulnerability management, response, and resilience outcomes.
Enterprise Architecture & Technology Modernization
- Partner with Enterprise Technology leadership to ensure cybersecurity, resilience, AI governance, and regulatory requirements are embedded into enterprise architecture, cloud transformation, operational technology initiatives, and digital modernization programs.
- Support scalable technology architectures that improve resilience, security, maintainability, and operational effectiveness.
- Reduce fragmentation, unnecessary complexity, and inconsistency of cybersecurity controls across the enterprise technology landscape.
- Support enterprise technology modernization, integration activities, and strategic operational initiatives.
- Ensure cybersecurity requirements are integrated into technology acquisition, development, deployment, and operational support processes.
Third-Party Risk Management
- Establish and govern a risk-based third-party cybersecurity and supply chain risk management program.
- Ensure cybersecurity risks are appropriately assessed and managed across vendors, contractors, cloud providers, EPC partners, operational technology suppliers, and strategic service providers.
- Support cybersecurity due diligence activities associated with acquisitions, integrations, strategic partnerships, and major technology investments.
- Ensure cybersecurity requirements are embedded throughout procurement, contracting, onboarding, monitoring, and offboarding processes.
- Monitor concentration risk and dependencies associated with critical suppliers and service providers.
Enterprise Execution & Governance
- Partner with business leadership and Enterprise Excellence to support enterprise prioritization, portfolio governance, operational execution, and risk-based decision-making.
- Improve execution discipline, transparency, accountability, operational metrics, and value realization across cybersecurity and resilience initiatives.
- Contribute to enterprise governance processes that improve scalability, operational effectiveness, and decision quality.
- Support enterprise operating rhythms and governance forums that strengthen accountability and cross-functional collaboration.
Talent & Organizational Leadership
- Build and lead high-performing cybersecurity teams with strong governance, operational, resilience, architecture, OT security, AI security, and risk management capabilities.
- Develop internal cybersecurity capability and reduce over-reliance on external implementation and coordination models where practical.
- Foster a culture of accountability, systems thinking, operational excellence, continuous improvement, and enterprise partnership.
- Build durable organizational capability through succession planning, workforce development, leadership coaching, and talent development.
Strategic Leadership
- Serve as an advisor to executive leadership and the Board on cybersecurity, technology risk, operational resilience, AI governance, and critical infrastructure protection.
- Support enterprise scaling initiatives, acquisitions, integration activities, major operational changes, and strategic business priorities.
- Assess cybersecurity investments with focus on enterprise value, operational resilience, risk reduction, scalability, and long-term sustainability.
- Build trusted relationships with executive leadership, business stakeholders, regulators, strategic vendors, and operational partners.
- Represent Pattern Energy in relevant industry forums, NERC-related working groups, cybersecurity communities, and critical infrastructure engagements.
Qualifications
Experience/Qualifications/Education Required
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Engineering, Information Systems, Business Administration, or related discipline.
- 15+ years of progressive leadership experience across cybersecurity, technology risk, operational technology, critical infrastructure security, resilience, or related operational environments.
- Experience leading cybersecurity programs within complex, highly regulated, or critical inf