Duke Energy Corporation

Senior Manager Cybersecurity

Duke Energy Corporation$120K — $145K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Management Information Systems, or related field.
  • Minimum of 10 years of related work experience, or 14 years without a degree.
  • At least 1 year of managerial experience.
  • Desirable: Experience in designing and implementing TPRM programs at scale.
  • Desirable: Professional security management certification (e.g., CISSP, CISM, CISA).

Responsibilities

  • Develop and maintain the Cybersecurity Supply Chain Risk Management (C-SCRM) and TPRM governance framework.
  • Provide risk mitigation directives for projects, ensuring protection of company assets.
  • Maintain an up-to-date cybersecurity policies framework for TPRM and Cybersecurity Awareness programs.
  • Create internal networks among cybersecurity teams and business units for better alignment.
  • Manage the third-party cyber risk lifecycle including intake, assessment, and remediation tracking.
  • Oversee cyber assessments utilizing various standard handling reports and questionnaires.
  • Report regularly on the status of TPRM and Cybersecurity Awareness programs.

Benefits

  • Hybrid work environment with a balance of remote and onsite locations.
  • Opportunities for significant professional influence by shaping cybersecurity governance and culture.
  • Collaborative work with diverse teams across the organization.
  • Ability to lead major initiatives that enhance organizational cyber resilience.
Full Job Description
Important Application Submission Information
In order to ensure your application is successfully received before the job posting expires, please submit your application by 11:59 PM on Sunday, August 23, 2026

Job Summary

Leads Duke Energy's Cybersecurity Supply Chain Risk Management (C-SCRM), Third-Party Risk Management (TPRM), and Cybersecurity Culture & Awareness programs. Responsible for establishing strategy, governance, operational processes, and performance metrics that identify, assess, mitigate, monitor, and report cybersecurity risk arising from suppliers, vendors, service providers, software providers, cloud providers, and other external dependencies. Oversees the enterprise cybersecurity culture and awareness program to strengthen employee security behaviors, reduce human risk, and improve organizational cyber resilience.

Leads managers and cybersecurity professionals responsible for supplier and third-party cyber risk assessments, continuous monitoring, contractual cybersecurity requirements, secure software supply chain governance, awareness training, phishing resilience, culture measurement, and executive engagement programs. Ensures alignment with cybersecurity strategy, regulatory obligations, business objectives, and industry frameworks.

Responsibilities
  • Develop and maintain the enterprise Cybersecurity Supply Chain Risk Management (C-SCRM) and TPRM governance framework.
  • Provide clear risk mitigating directives for projects/initiatives/services including the application of controls to protect company assets.
  • Maintain and support a document framework of continuously up-to-date cybersecurity policies, standards and guidelines for the TPRM and Cybersecurity Awareness programs.
  • Help create the necessary internal networks among the cybersecurity team and line-of-business areas to ensure alignment as required.
  • Manage end-to-end third-party cyber risk lifecycle activities including:
    • Intake
    • Risk assessment
    • Remediation tracking
    • Exception management
    • Periodic reassessment
    • Offboarding
  • Oversee cyber assessments utilizing:
    • SIG questionnaires
    • SOC 1/SOC 2 reports
    • ISO certifications
    • Independent assessments
    • Continuous monitoring platforms
  • Provide regular reporting on the status of the Third-Party Risk Management (TPRM) and Cybersecurity Awareness programs as part of a strategic enterprise risk management program, thus supporting business positive outcomes.
  • Support a process for monitoring and periodically re-assessing third parties to ensure compliance with obligations.
  • Work with Legal and Supply Chain to ensure that cybersecurity requirements and the right to assess third parties be included in contracts/agreements.
  • Oversee the cybersecurity awareness and training program for all employees, contractors and approved system users, including formation, evaluation and action plans based on metrics regarding program effectiveness.


Required/Basic Qualifications
  • Bachelors degree in Cybersecurity, Computer Science, Management Information Systems, or Other Related Degree
  • Minimum 10 years related work experience
  • In lieu of Bachelors degree(s) AND 10 year(s) related work experience listed above, High School/GED AND 14 year(s) related work experience


Desired Qualifications
  • Experience designing, implementing, and leading Third Party Risk Management (TPRM) programs at scale.
  • Knowledge of applicable NIST and ISO 27001/27036 Cybersecurity standards along with SOC1/SOC2 Type 1/Type 2 reports.
  • Strong experience addressing senior-level leadership and the ability to collaborate and lead cross-functional teams and initiatives.
  • Experience in inspiring change and leading a large-scale risk management framework in a large company.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate cybersecurity and risk-related concepts to technical and nontechnical audiences at various hierarchical levels, ranging from individual contributors to senior staff.
  • Excellent analytical skills, the ability to manage multiple projects under strict timelines, as well as the ability to work well in a demanding, dynamic environment and meet overall objectives.
  • Ability to lead and motivate the cybersecurity team to achieve tactical and strategic goals.
  • Professional security management certification is desirable, such as Certified Information Systems Security Professional (CISSP), Certified Cybersecurity Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials.
  • Experience with contract and vendor negotiations
  • High degree of initiative, dependability and ability to work with little supervision while being resilient to change
  • Works effectively with a variety of personalities and can adapt his/her approach to effectively reach and develop his/her team. Uses this skill as well as his/her functional knowledge to both earn and maintain a high level of credibility with the team.


Working Conditions
  • Hybrid Mobility Classification - Work will be performed from both remote and onsite locations after the onboarding period. However, hybrid employees should live within a reasonable daily commute to a Duke Energy facility.
  • Office Environment


Specific Requirements
  • Bachelor of Science or Bachelor of Arts degree, preferably in Cybersecurity, Information Security, Computer Science, Management Information Systems or other closely related fields
  • 10+ years of experience in Cybersecurity fields, or roles focused on cybersecurity or IT functions, to include at least 1 year of managerial experience in addition to a degree OR 14+ years of Cybersecurity related experience, to include at least 1 year of managerial experience in lieu of a degree
  • Ability to obtain one of the following within three years of hire: Certified Information Systems Security Professional (CISSP), Certified Cybersecurity Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials.


Travel Requirements
5-15%

Relocation Assistance Provided (as applicable)
No

Represented/Union Position
No

Visa Sponsored Position
No. This is not a Visa Sponsored Position. This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future.

Please note that in order to be considered for this position, you must possess all of the basic/required qualifications.

About Duke Energy Corporation

Duke Energy is one of the largest energy holding companies in the United States. Its Electric Utilities and Infrastructure business unit serves approximately 7.5 million customers located in six states in the Southeast and Midwest.

Duke Energy Corporation Careers

Join the dynamic team at Duke Energy Corporation, a leader in sustainable energy, where innovation, leadership, and diversity drive success. As one of the largest electric power holding companies in the United States, there has never been a better time to explore job opportunities with us. Work You’ll Do At Duke Energy, your work will directly contribute to shaping the future of energy across the nation. Our commitment to sustainable, reliable power is matched by our dedication to our team's professional growth and development. Lead in an Environment Focused on Innovation and Sustainability Duke Energy is at the forefront of integrating renewable energy and cutting-edge technology to meet tomorrow's energy needs. Join a team where your innovative ideas can flourish and where you are part of leading the charge toward a cleaner energy future. Transform Your Career with Unmatched Opportunities With a wide range of career paths, from engineering to customer service, Duke Energy offers job opportunities that cater to diverse skills and ambitions. Whether you're seeking an entry-level position or a more senior role, you'll find a culture that supports your career aspirations. Internship Programs and Professional Development Start your career journey through Duke Energy’s internship programs designed to give you real-world experience and insights into the energy sector. Our programs help bridge the gap between academic learning and professional employment, enhancing your resume and preparing you for future hiring opportunities. Be Part of a Great Team Duke Energy’s commitment to diversity and inclusive culture makes it a great place to work. Our team is our strength, and we thrive on the creativity and different perspectives that each member brings. Enjoy benefits that support both your professional and personal life, as you collaborate with talented professionals dedicated to making a difference. Future-Proof Your Career Advance your career with Duke Energy’s extensive training and development programs. From leadership development to technical skills enhancement, we provide the tools you need to succeed. Our commitment to your growth ensures that your career is always moving forward. Explore Discover how Duke Energy is leading the way in renewable energy solutions and how our workforce is pivotal in driving this change. Stay Connected Join Our Team Search open positions that match your skills and interests. We look for passionate, curious, creative, and solution-driven team players. Ready to start your journey with Duke Energy? Prepare your resume, sharpen your interview skills, and join a company that values what you bring to the table. SEARCH DUKE ENERGY JOBS Keep Up to Date Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. READ CAREERS BLOG Job Alert Emails Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Explore the exciting and rewarding opportunities that await at Duke Energy Corporation. By joining Duke Energy, you’re not just getting a job—you’re gaining a career where you can truly make a difference.
Learn more about Duke Energy Corporation
Size
27,605 employees
Market Cap
$79 billion
Industry
Net Income
$1.3 billion
5 Year Trend
+2%
Revenue
$23.8 billion
NASDAQ

Similar Jobs

More Jobs at Duke Energy Corporation

More Information Technology Jobs

Find similar Senior Manager Cybersecurity jobs: