Director, Cybersecurity

Caturus Management Services, LLC

$150K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in IT, Computer Science, or a related field required.
  • Master's degree in Business Administration or related field preferred.
  • Professional certifications like CISSP, CISM, or GICSP preferred.
  • 10+ years in information security, with 3-5 years in leadership roles involving IT and OT security.
  • Experience in critical infrastructure sectors, particularly energy or LNG, is highly desired.

Responsibilities

  • Lead day-to-day security operations across corporate IT and Operational Technology environments.
  • Implement IT/OT network segmentation and defense-in-depth strategies aligned with NIST standards.
  • Develop security operations capabilities including incident response and monitoring tailored for OT environments.
  • Maintain a current asset inventory for IT and OT systems, including those managed by third parties.
  • Integrate security operations within field workflows in collaboration with operational leadership.
  • Oversee a continuous vulnerability management program with remediation SLAs based on asset criticality.
  • Conduct third-party security assessments and manage the engagement of testing vendors.

Benefits

  • Full-time position with opportunities for professional development.
  • Collaborative environment focusing on strategic security plans and operations.
  • Engagement with cutting-edge technologies and methodologies in cybersecurity.
  • Opportunity to lead a critical function within the energy sector's IT and OT realms.
Full Job Description
Director, Cybersecurity

Department: Information Technology

Employment Type: Full Time

Location: US TX Houston - Corporate Office

Job Description

Position Summary:
The Director, Cybersecurity is responsible for leading Caturus Energy's unified security function across both Information Technology (IT) and Operational Technology (OT) environments. This role owns the full lifecycle of enterprise information security: analysis, operations, governance, and risk management, spanning corporate IT systems, upstream field/SCADA systems, midstream gathering infrastructure, and the Commonwealth LNG terminal's industrial control systems (ICS).

The Director is accountable for a clear, high-bar outcome: no vulnerable systems left unmanaged. Every asset is inventoried, every known vulnerability is tracked to closure on a defined timeline, every critical system is independently tested by qualified third parties (including regular penetration testing) through to verified closure, and the company can demonstrate, on demand, to auditors, insurers, lenders, regulators, or the Board, exactly how its controls map to NIST and ISO frameworks and how IT General Controls (ITGCs) are operating.

Key Accountabilities:
  • Own day-to-day security operations across corporate IT (endpoints, identity, cloud, applications) and OT/ICS environments (drilling rig systems, gathering system SCADA, LNG terminal control systems).
  • Drive IT/OT network segmentation using zone-and-conduit architecture (ISA/IEC 62443) and defense-in-depth aligned to NIST SP 800-82 Rev. 3.
  • Build and mature a security operations capability: monitoring, detection, incident response, and threat intelligence, with OT-specific playbooks that respect process safety and well-control constraints; no security action shall compromise safe operation of physical assets.
  • Maintain a current, accurate asset inventory across IT and OT, including third-party/vendor-managed systems where Caturus has visibility or contractual security requirements.
  • Govern vendor and integrator remote access to wellsite and pipeline equipment: least-privilege access, MFA, session monitoring, and time-bound access for contractors and OEMs.
  • Coordinate with Drilling, Midstream, and Commonwealth LNG operations leadership so security operations are integrated into field workflows, aligned with API 1164 and, where relevant, integrated with process-safety (HAZOP) reviews.
  • Operate a continuous vulnerability management program across IT and OT: discovery, scoring and prioritization, assigned ownership, and time-bound remediation SLAs by severity and asset criticality.
  • Maintain a live vulnerability register with age, status, and owner for every open finding; report aging or overdue items to IT leadership on a defined cadence.
  • Ensure OT vulnerability management accounts for patch windows, vendor certification requirements, legacy equipment limitations, and safety systems, with documented risk acceptance where immediate patching is not feasible.
  • Deploy or manage OT-aware asset and network visibility tooling to support inventory and detection across the field environment.
  • Establish and manage a program of third-party security assessments, including annual (minimum) penetration testing of critical IT and OT environments, periodic vulnerability assessments and configuration reviews, and red team or adversary simulation exercises as risk and maturity warrant.
  • Track every finding from every third-party assessment through to verified closure, with re-testing or evidence-based validation required before any finding is marked closed.
  • Vet and manage the roster of qualified third-party testing vendors; set scope, rules of engagement, and safety constraints for OT testing so that no testing activity risks physical safety or process integrity.
  • Develop and maintain the enterprise information security risk register covering IT and OT risk, with likelihood/impact scoring, ownership, and treatment plans (mitigate, transfer, accept, avoid).
  • Present risk posture and trends to IT leadership, executive leadership, and the Board or Audit Committee as needed.
  • Own and mature the company's security governance framework: policies, standards, and procedures for both IT and OT.
  • Track overall program maturity against a recognized model and report maturity progression to leadership over time.
  • Establish security oversight for non-operated assets and joint ventures where Caturus holds an economic interest but not operational control, defining requirements through joint-operating and data-sharing agreements in partnership with Legal and Land/Business Development.
  • Support cyber due diligence for M&A activity, including pre-close diligence, post-close integration or separation, and security provisions in transition services agreements.
  • Partner with Legal, Internal Audit, and Corporate Affairs on regulatory and contractual security obligations, including CFIUS-related requirements. Maintain current, evidence-backed control mapping to NIST Cybersecurity Framework 2.0, NIST SP 800-53/800-82 Rev. 3, ISO/IEC 27001, and (where relevant to OT) ISO/IEC 27019 or IEC 62443.
  • Maintain and report on IT General Controls (ITGCs) supporting financial reporting integrity, in coordination with Internal Audit and external auditors.
  • Maintain awareness of, and readiness for, applicable energy-sector regulatory regimes in coordination with Legal, including TSA pipeline security directives, CIRCIA incident-reporting obligations, and conditional NERC CIP applicability.
  • Produce, on demand, audit-ready evidence of control operation and compliance status for internal leadership, external auditors, lenders, insurers, or regulators. Lead or support external audits, insurance underwriting security assessments, and customer/partner due diligence security questionnaires.
  • Own the Cybersecurity Incident Response Plan covering both IT and OT, and lead periodic executive tabletop exercises, including ransomware scenarios.
  • Own secure adoption governance for AI/LLM tooling (e.g., Microsoft Copilot): permission-hygiene remediation, data-leakage prevention, shadow-AI monitoring, and an AI acceptable-use policy.
  • Maintain controls against business email compromise and vendor-payment fraud, including out-of-band verification for banking and vendor-master-file changes.
  • Build out the cybersecurity function's staffing model, including internal hires, managed security service providers, and OT security specialists, as the program matures.
  • Manage relationships with security vendors, MSSPs, and the third-party testing ecosystem.
  • Own the cybersecurity budget and multi-year roadmap in partnership with the Head of IT.
  • Lead the security-awareness and phishing-simulation program, extending security culture into field operations.


Qualifications

Education, Certificates, and Licenses:
  • Bachelor's degree in Information Technology, Computer Science, Information Systems, Engineering, or a related discipline required.
  • Master's degree in Business Administration (MBA), Information Systems, or a related discipline preferred.
  • Professional certifications such as CISSP, CISM, GICSP, GRID, GIAC ICS (ICS410/ICS515), or similar credentials preferred.

Experience:
  • 10+ years of progressive information security experience, including at least 3-5 years in a leadership role spanning both IT and OT/ICS security.
  • Experience in energy, midstream, LNG, or another critical-infrastructure sector strongly preferred.
  • Demonstrated experience running vulnerability management and third-party penetration testing programs at scale, through to verified closure. Experience with OT/ICS security fundamentals (SCADA, DCS, safety instrumented systems) and the operational constraints of patching and testing production industrial environments.
  • Experience building and presenting risk reporting to executive leadership and/or a Board or Audit Committee.
  • Experience supporting regulatory compliance programs (TSA pipeline security directives, CIRCIA, NERC CIP as applicable) and IT General Controls audits preferred.
  • Experience with non-operated joint ventures, third-party-operated facility risk, or cyber due diligence for M&A/A&D activity preferred.

Knowledge, Skills, and Abilities:
  • Working command of NIST Cybersecurity Framework 2.0, NIST SP 800-53/800-82 Rev. 3, ISO/IEC 27001, IEC 62443 zone-and-conduit concepts, and IT General Controls; able to translate framework requirements into operational controls and audit evidence.
  • Deep understanding of vulnerability management, penetration testing methodology, and third-party assurance practices.
  • Working knowledge of industrial control systems (ICS), SCADA systems, operational technology, and associated cybersecurity considerations, including the operational and safety constraints distinct from corporate IT.
  • Understanding of applicable energy-sector regulatory frameworks (TSA pipeline directives, CIRCIA, NERC CIP where applicable) sufficient to build and maintain compliance readiness.
  • Ability to develop, quantify, and communicate enterprise risk in both technical and business terms to executive stakeholders.
  • Strong cross-functional collaboration skills, particularly with Drilling, Midstream, LNG Operations, Legal, Internal Audit, and Finance.
  • Exceptional leadership, organizational, communication, and relationship management skills.
  • Ability to develop and execute strategic security plans while managing day-to-day operations and incident response.
  • Demonstrated experience building, leading, and mentoring high-performing teams, including vendor and managed-service relationships.
  • Excellent analytical, problem-solving, and decision-making capabilities.
  • Commitment to safety, operational excellence, continuous improvement, and the secure operation of critical energy infrastructure; ability to ensure security controls never compromise well control, process safety, or personnel safety.

Similar Jobs

More Jobs at Caturus Management Services, LLC

  • Analyst, Finance
    $80K — $95K *
    Houston, TX 77084 (Harris County)
    Finance & Insurance
    In-Person
  • SCADA Technician
    $80K — $95K *
    Houston, TX 77084 (Harris County)
    Energy & Utilities
    In-Person
  • Manager, Maintenance
    $110K — $130K *
    Houston, TX 77084 (Harris County)
    Energy & Utilities
    In-Person
  • Senior Drilling Engineer
    $150K — $180K *
    Houston, TX 77084 (Harris County)
    Energy & Utilities
    In-Person
  • Revenue Accounting Manager
    $110K — $130K *
    Houston, TX 77084 (Harris County)
    Energy & Utilities
    In-Person

More Information Technology Jobs

Find similar Director, Cybersecurity jobs: