Hiring.Camp

Senior Manager Cybersecurity

Dukeenergy

·

Yesterday

Location
Duke Energy Plaza, United States of America
Workplace
Hybrid
Type
Full-time
Department
IT
Seniority
Senior
Experience
10+ years
Education
Bachelor
Closing date
Today
Source
Workday

Description

Important Application Submission Information

In order to ensure your application is successfully received before the job posting expires, please submit your application by 11:59 PM on Sunday, August 23, 2026

More than a career - a chance to make a difference in people's lives.

Build an exciting, rewarding career with us – help us make a difference for millions of people every day. Consider joining the Duke Energy team, where you'll find a friendly work environment, opportunities for growth and development, recognition for your work, and competitive pay and benefits.

Job Summary

Leads Duke Energy’s Cybersecurity Supply Chain Risk Management (C-SCRM), Third-Party Risk Management (TPRM), and Cybersecurity Culture & Awareness programs. Responsible for establishing strategy, governance, operational processes, and performance metrics that identify, assess, mitigate, monitor, and report cybersecurity risk arising from suppliers, vendors, service providers, software providers, cloud providers, and other external dependencies. Oversees the enterprise cybersecurity culture and awareness program to strengthen employee security behaviors, reduce human risk, and improve organizational cyber resilience.

Leads managers and cybersecurity professionals responsible for supplier and third-party cyber risk assessments, continuous monitoring, contractual cybersecurity requirements, secure software supply chain governance, awareness training, phishing resilience, culture measurement, and executive engagement programs. Ensures alignment with cybersecurity strategy, regulatory obligations, business objectives, and industry frameworks.

Responsibilities

  • Develop and maintain the enterprise Cybersecurity Supply Chain Risk Management (C-SCRM) and TPRM governance framework.

  • Provide clear risk mitigating directives for projects/initiatives/services including the application of controls to protect company assets.

  • Maintain and support a document framework of continuously up-to-date cybersecurity policies, standards and guidelines for the TPRM and Cybersecurity Awareness programs.

  • Help create the necessary internal networks among the cybersecurity team and line-of-business areas to ensure alignment as required.

  • Manage end-to-end third-party cyber risk lifecycle activities including:

    • Intake

    • Risk assessment

    • Remediation tracking

    • Exception management

    • Periodic reassessment

    • Offboarding

  • Oversee cyber assessments utilizing:

    • SIG questionnaires

    • SOC 1/SOC 2 reports

    • ISO certifications

    • Independent assessments

    • Continuous monitoring platforms

  • Provide regular reporting on the status of the Third-Party Risk Management (TPRM) and Cybersecurity Awareness programs as part of a strategic enterprise risk management program, thus supporting business positive outcomes.

  • Support a process for monitoring and periodically re-assessing third parties to ensure compliance with obligations.

  • Work with Legal and Supply Chain to ensure that cybersecurity requirements and the right to assess third parties be included in contracts/agreements.

  • Oversee the cybersecurity awareness and training program for all employees, contractors and approved system users, including formation, evaluation and action plans based on metrics regarding program effectiveness.

Required/Basic Qualifications

  • Bachelors degree in Cybersecurity, Computer Science, Management Information Systems, or Other Related Degree

  • Minimum 10 years related work experience

  • In lieu of Bachelors degree(s) AND 10 year(s) related work experience listed above, High School/GED AND 14 year(s) related work experience

Desired Qualifications

  • Experience designing, implementing, and leading Third Party Risk Management (TPRM) programs at scale.

  • Knowledge of applicable NIST and ISO 27001/27036 Cybersecurity standards along with SOC1/SOC2 Type 1/Type 2 reports.

  • Strong experience addressing senior-level leadership and the ability to collaborate and lead cross-functional teams and initiatives.

  • Experience in inspiring change and leading a large-scale risk management framework in a large company.

  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate cybersecurity and risk-related concepts to technical and nontechnical audiences at various hierarchical levels, ranging from individual contributors to senior staff.

  • Excellent analytical skills, the ability to manage multiple projects under strict timelines, as well as the ability to work well in a demanding, dynamic environment and meet overall objectives.

  • Ability to lead and motivate the cybersecurity team to achieve tactical and strategic goals.

  • Professional security management certification is desirable, such as Certified Information Systems Security Professional (CISSP), Certified Cybersecurity Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials.

  • Experience with contract and vendor negotiations

  • High degree of initiative, dependability and ability to work with little supervision while being resilient to change

  • Works effectively with a variety of personalities and can adapt his/her approach to effectively reach and develop his/her team. Uses this skill as well as his/her functional knowledge to both earn and maintain a high level of credibility with the team.

Working Conditions

  • Hybrid Mobility Classification – Work will be performed from both remote and onsite locations after the onboarding period. However, hybrid employees should live within a reasonable daily commute to a Duke Energy facility.

  • Office Environment

Specific Requirements

  • Bachelor of Science or Bachelor of Arts degree, preferably in  Cybersecurity, Information Security, Computer Science, Management Information Systems or other closely related fields

  • 10+ years of experience in Cybersecurity fields, or roles focused on cybersecurity or IT functions, to include at least 1 year of managerial experience in addition to a degree OR 14+ years of Cybersecurity related experience, to include at least 1 year of managerial experience in lieu of a degree

  • Ability to obtain one of the following within three years of hire: Certified Information Systems Security Professional (CISSP), Certified Cybersecurity Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials.

Travel Requirements

5-15%

Relocation Assistance Provided (as applicable)

No

Represented/Union Position

No

Visa Sponsored Position

No. This is not a Visa Sponsored Position. This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future.


Please note that in order to be considered for this position, you must possess all of the basic/required qualifications.

Privacy

Do Not Sell My Personal Information (CA)

Terms of Use

Accessibility

Skills

CybersecuritySOCRisk ManagementComplianceSOC 2ISO 27001CISSP

Similar Jobs

30

Senior Cybersecurity Manager

Concertgolfclubs · Lake Mary, Florida, US · Onsite

4 days ago

Sr. Cybersecurity Manager

ACCO Brands

3 weeks ago

Senior Manager Cybersecurity

SIA · Brussels, Belgium · Hybrid

1 month ago

Sr Cybersecurity Manager

Netgear · San Jose, CA · Hybrid

1 month ago

Cybersecurity Senior Project Manager

NYC Department of City Planning · New York City, NY, United States

Today

Senior Manager, Cybersecurity Awareness & Training

Jj · US160 NJ Raritan - 1003 US Highway 202 N, United States of America +3 · Hybrid

2 days ago

Senior Manager, Cybersecurity Awareness & Training

Jj · US160 NJ Raritan - 1003 US Highway 202 N, United States of America +3 · Hybrid

2 days ago

Sr. Manager - Cybersecurity - Pittsburgh

Wavestone · Pittsburgh, PA, United States · Hybrid

2 days ago

IT Audit, Cybersecurity & Risk Senior Manager

bakertilly · USA MA Tewksbury, United States of America

4 days ago

Senior Manager, Cybersecurity Manufacturing

Coke · US - GA - Atlanta, United States of America +1

1 week ago

Sr. Territory Manager- OT Cybersecurity

Honeywell · Markham, ON, Canada · Remote

1 week ago

Senior AI Product Manager, Cybersecurity

Scale AI · New York, NY; San Francisco, CA +2

1 week ago

Senior Manager MedTech Cybersecurity

Jj · IL001 Yokneam, Israel +1 · Hybrid

1 week ago

Senior Territory Manager - Cybersecurity / Network Security Sales background*

Sonicwall · Chennai, Tamil Nadu, India · Remote

2 weeks ago

Senior Manager, Cybersecurity Operations

Nflcareers · New York, New York, United States

2 weeks ago

Comcast Cybersecurity: Senior Program Manager, Cyber Security – Frontier AI Models

Comcast · PA - Philadelphia, 1701 John F Kennedy Blvd, United States of America · Remote, Onsite

2 weeks ago

Senior Cybersecurity Project Manager

CDO Technologies · Washington, DC

2 weeks ago

Sr Manager Cybersecurity Defense - CSIRT

Target · 7000 Target Pkwy N,NCD-0375 Brooklyn Park,MN 55445, United States of America

2 weeks ago

Sr. Account Manager - Cybersecurity | Omaha, NE

Optiv · Nebraska, United States of America

2 weeks ago

Sr. Account Manager - Cybersecurity | Arkansas

Optiv · Arkansas, United States of America +1

2 weeks ago

Senior Product Manager (Cybersecurity)

CIRA · Ottawa, Ontario, Canada

2 weeks ago

Cybersecurity Managed Services Senior Manager (Growth & Market Development)

Pwc · Warszawa - Polna 11, Poland +1

3 weeks ago

Cybersecurity Managed Services Senior Manager (Service Delivery Management)

Pwc · Warszawa - Polna 11, Poland +1

3 weeks ago

Senior Manager/ Director – Cybersecurity Transformation & AI Security

Tevora · Irvine, CA +1 · Hybrid

3 weeks ago

Senior Manager, Cybersecurity Stratey & Risk

Strava · Strava SF · Hybrid

3 weeks ago

NSIPS Cybersecurity Sr Manager | Secret Clearance

GDIT · USA LA New Orleans - 2251 Lakeshore Dr, Bldg 2, Fl 3 (LAC006), United States of America · Onsite

4 weeks ago

NSIPS Cybersecurity Sr Manager | Secret Clearance

Gdit · USA LA New Orleans - 2251 Lakeshore Dr, Bldg 2, Fl 3 (LAC006), United States of America · Onsite

1 month ago

Sr. Technical Program Manager, Cybersecurity Remediation

modernatx · 325 Binney St - Cambridge - USA - MA, United States of America +1

1 month ago

Sr Product Manager - Cybersecurity

Target · Bangalore,India

1 month ago

Commercial Cybersecurity Business Developer and Account, Senior Manager

Booz Allen Hamilton · USA, TX, Houston (18050 Saturn Lane), United States of America

1 month ago