Posting Status:
Internal OnlyPosition Number:
402621Applications are being accepted through: 9/1/26
*If no date is displayed, applications are being accepted on an ongoing basis; however, this job posting may close at any time after a minimum of 5 days of being posted.
General Manager - Cyber and Physical SecurityGeneral Managers are executive-level, at-will positions reporting to an Officer
This General Manager provides strategic, enterprise-wide leadership for the organization's cybersecurity and physical security programs, ensuring the protection of information technology (IT), operational technology (OT), critical infrastructure, facilities, physical assets, and sensitive information. This role is accountable for safeguarding the systems and assets essential to reliable utility operations, public safety, regulatory compliance, and customer trust.
This role serves as a key executive partner to the business, working collaboratively across all functions to embed cybersecurity and physical security into core operations, capital investment decisions, infrastructure planning, and strategic initiatives. The General Manager ensures that security is not viewed as a standalone technical function, but as an integrated business enabler that supports operational reliability, asset protection, workforce safety, resilience, and enterprise risk management.
The General Manager delivers clear, actionable insight into security risks, translating an evolving threat landscape into business, operational, financial, safety, and reputational impacts. Through proactive risk management and enterprise-wide collaboration, the role enables informed decision-making and strengthens organizational resilience against both cyber and physical threats.
As a member of the Executive Leadership Team (ELT), General Manager Action Team (GMAT), and Enterprise Risk Management (ERM) Committee, this position is expected to think broadly across the enterprise, balancing security priorities with organizational objectives, financial considerations, and operational realities. The role contributes to enterprise-level strategy by ensuring security and risk considerations are embedded in long-term planning, infrastructure investments, critical asset protection, business continuity, and service delivery.
Essential Duties: This job description is not intended to be an exhaustive list of all duties, responsibilities or qualifications associated with the job. Specific job assignments may include some or all of the following:
LEADERSHIP & ENGAGEMENT- Serves as a strategic business partner to executive leadership, collaborating with officers, general managers, and business leaders to align cybersecurity, physical security, and enterprise risk management priorities with operational, customer, regulatory, and financial objectives.
- Acts as a standing member of the Executive Leadership Team (ELT), General Manager Action Team (GMAT), and Enterprise Risk Management (ERM) Committee, contributing to enterprise-wide decision-making, strategic planning, policy development, and risk governance.
- Provides enterprise leadership in identifying, assessing, prioritizing, and mitigating strategic, operational, cyber, and physical security risks, ensuring alignment with the organization's overall risk management framework and risk tolerance.
- Drives enterprise thinking beyond functional boundaries, ensuring security strategies reflect a holistic understanding of utility operations, including electric, gas, water, wastewater, and fiber functions.
- Leads enterprise security transformation and change management initiatives, ensuring successful adoption of security strategies, technologies, policies, and operational practices through effective communication, stakeholder engagement, and cross-functional collaboration.
- Ensures cybersecurity, physical security, and resilience considerations are embedded in business initiatives, capital programs, infrastructure investments, operational processes, and strategic planning activities through proactive engagement and executive leadership.
- Provides leadership and direction to security department leaders, fostering a high-performing, accountable, and resilient organization.
- Leads the security organization, including staffing strategy, workforce planning, succession planning, budget development, performance management, and professional development.
- Builds and sustains a culture of shared responsibility for security, emphasizing practical risk management, critical asset protection, workforce safety, operational resilience, and collaboration across IT, OT, facilities, and business teams.
ENTERPRISE STRATEGY, RISK MANAGEMENT & SECURITY OPERATIONS- Develops, maintains, and executes an enterprise security strategy that integrates cybersecurity, physical security, and critical infrastructure protection in support of organizational objectives, operational resilience, and risk management goals.
- Serves as the organization's senior security executive, advising executive leadership, business unit leaders, and the ERM Committee on enterprise security strategy, emerging threats, and risk management.
- Establishes enterprise security priorities based on risk, regulatory requirements, operational impact, business objectives, threat intelligence, and critical infrastructure dependencies.
- Oversees the effectiveness of enterprise security operations, including threat detection, security monitoring, incident response, vulnerability management, threat intelligence, cyber resilience, and physical security programs.
- Directs preparedness, response, recovery, and crisis management activities related to significant cyber, physical security, business disruption, and critical infrastructure events.
- Ensures the protection of critical infrastructure, facilities, physical assets, personnel, sensitive information, and operational technologies essential to reliable utility service delivery.
- Oversees physical security programs, including access control systems, surveillance technologies, facility security, asset protection, investigations, and coordination with law enforcement and emergency response agencies.
- Ensures compliance with applicable regulatory, legal, and industry requirements, including cybersecurity, physical security, critical infrastructure protection, and enterprise risk management obligations.
- Ensures security and resilience considerations are integrated into enterprise projects, strategic initiatives, business continuity planning, emergency preparedness, and disaster recovery programs.
- Develops security roadmaps, maturity strategies, performance metrics, and executive reporting that demonstrate program effectiveness and support informed business decision-making.
EXTERNAL ENGAGEMENT- Represents the organization in utility-sector security forums, critical infrastructure protection initiatives, information-sharing organizations, regulatory proceedings, public-private partnerships, and government security collaborations.
- Maintains strategic relationships with industry peers, law enforcement agencies, intelligence partners, regulators, emergency management organizations, and critical infrastructure stakeholders.
- Monitors threat intelligence, sector alerts, advisories, geopolitical developments, and emerging cyber and physical risks that may impact the organization's IT, OT, facilities, and critical assets.
- Serves as a trusted advisor and representative of the organization on matters related to cybersecurity, physical security, enterprise resilience, critical infrastructure protection, and risk management.
- Advances security partnerships and collaborative initiatives that strengthen the protection of essential services and critical infrastructure upon which customers, employees, and the community depend.
Education Requirement (Equivalent combination of training, education, and experience that provides the required skills, knowledge and abilities may be accepted in lieu of education requirement)
- Required: Bachelor's degree from an accredited college or university in Cybersecurity, Information Security, Information Technology, Computer Science, or a related field. An equivalent combination of education and progressively responsible leadership experience in cybersecurity, physical security, critical infrastructure protection, risk management, or utility operations may be considered.
- Preferred: Master's degree in Cybersecurity, Information Assurance, or a related discipline. Advanced executive education in enterprise leadership, strategic management, risk governance, or critical infrastructure protection.
Professional Certifications (Preferred)- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Protection Professional (CPP)
- Physical Security Professional (PSP)
- Relevant utility, critical infrastructure, or enterprise risk management certifications
Experience Requirement(Equivalent combination of training, education, and experience that provides the required skills, knowledge, and abilities may be accepted in lieu of experience requirement)
- Minimum of 12 years of progressively responsible experience in cybersecurity, physical security, critical infrastructure protection, risk management, or related disciplines.
- Minimum of 7 years of senior leadership experience directing enterprise security programs, security operations, risk management, or critical infrastructure protection initiatives.
- Experience advising executive leadership, boards, risk committees, and regulators on cybersecurity, physical security, resilience, and enterprise risk matters.
- Experience within a regulated industry is preferred, with utility, energy, water, or other critical infrastructure sector experience strongly preferred.
PHYSICAL REQUIREMENTS/WORKING CONDITIONS:SEDENTARY Work: Exerting up to 10 pounds of force occasionally (1/3 of the time), and/or a negligible amount of force frequently (1/3 to 2/3 of the time) to lift, carry, push, or pull objects. Sedentary work involves sitting most of the time but may involve walking or standing for brief periods of time. Jobs are sedentary only if walking and standing are required only occasionally and all other criteria are met. Positions in this class typically require talking, hearing, seeing and repetitive motions within an office working environment.
For information regarding benefits associated with this position, visit https://csutilities.sharepoint.com/sites/Benefits/SitePages/Benefits_Home.aspx
ATTENTION:- All positions will be posted for a minimum of 5 calendar days.
- Starting pay will be based on the successful candidate's experience, education, and training; however, those with limited direct experience could start below the posted pay range.
- If a single pay rate is posted, the job starts at that rate regardless of previous experience, education, and training.
- Colorado Springs Utilities does not sponsor work visas of any kind, including H-1B, TN, or F-1 student visas (with or without OPT or STEM work authorization), or any other employment-based visas. All eligible applicants must be authorized to work in the United States, and work authorization must not be based on employer sponsorship of a work visa.
Have a question? If you have a question about a position or need assistance from a recruiter, email us at [redacted] or call [redacted].