Energy tech co. that designs, builds, services gas, nuclear, hydro, steam & wind power systems globally.
Lead cybersecurity due diligence, integration, and risk for M&A deals
4 days ago ago
$156,100 - $260,100
Experienced (8-12 years)
Full Time
New York, United States
Hybrid
Company Size
76,800 Employees
Service Specialisms
Energy Services
Digital Solutions
Sustainability
Smart Grid Technologies
Consulting
Sector Specialisms
Power
Gas Power
Steam Power
Nuclear
Hydro Power
Wind
Onshore Wind
Offshore Wind
Role
Description
third-party management
day 1 readiness
risk quantification
kpi reporting
playbook development
ot integration
Manage third-party providers for surge capacity/testing/regulatory advisory; integrate and QA outputs.
Operate in a matrix with DT M&A/PMO, Business Development, Legal, Privacy, Finance, Insurance, Sourcing, and BU security; lead cross-functional squads.
Own Day 1 control readiness; build and execute 30/60/100-day plans and drive TSA exit milestones.
Provide executive-ready risk narratives, options/trade-offs, and recommendations under tight timelines.
Quantify risk and remediation (capex/opex, timeline) and translate into valuation, PPAs, holdbacks, R&Ws/indemnities, and closing conditions.
Track and report KPIs (flow efficiency, diligence cycle time, Day 1 control coverage, TSA months saved, post-close findings); drive continuous improvement.
Lead pre-sign red-flag and full due diligence for GE Vernova's Deal Processes in DT and OT/ICS targets aligned to NIST CSF, SP 800-53/800-171, and 800-82.
Develop and run standard playbooks for IAM/PAM, network segmentation/zero trust, endpoint/EDR, cloud tenancy/landing zones, app security, data discovery/classification/transfer, logging/SIEM, vulnerability management, third-party risk, IR, and BCP/DR.
Establish clean-room protocols and data handling standards; ensure privacy and cross-border compliance (e.g., DPIAs).
Control gap assessment with target state; quantified remediation estimates; executive risk register and heatmap.
Design/govern safe OT/ICS integration and segmentation strategies; assess NERC CIP applicability and compliance contours.
Requirements
cissp
nist
iam
ot/ics
10+ years
risk quantification
Track record delivering Day 1 readiness and 30/60/100-day execution with TSA exits in global environments.
Hands-on depth in IAM/PAM, network/cloud security, endpoint/EDR, data protection, logging/monitoring, vuln mgmt, third-party risk, IR, and BCP/DR.
Day 1 control checklist and exceptions log; 30/60/100-day plan with critical path and TSA exit criteria.