This is a remote position.
They are committed to creating more renewable infrastructure solutions for the grid and are offeringcomprehensive compensation packagesto their employees leading the drive to meet company goals.Other perks included a competitive base salary, open PTO policy, flex work hours, benefits, the opportunity to work with a transparent Executive Leadership Team..and more.
- Drive the cybersecurity program: Partner daily with stakeholders to align activities to Plus Power’s security/compliance posture; champion secure-by-design and secure-by-default across the company.
- Own threat & vulnerability management: Baseline, monitor, and assess risk across OT/IT/data environments; triage and resolve security events, control gaps, policy questions, and technical risks.
- Build scalable security operations: Create repeatable frameworks to detect events, quantify feasibility, document risk, and model blast radius; project-manage implementation of security controls.
- Lead compliance & posture management: Administer CSPM platforms; run automated evidence collection; develop, communicate, and assess compliance vs. internal/external policies; advance certifications/attestations (SOX, ISO, NERC-CIP, NIST CSF 2.0).
- Secure the ecosystem: Stand up and run a Third-Party Cyber Risk Management (TPRM) program to mitigate vendor and software supply-chain risk.
- Elevate governance & reporting: Publish executive-ready cyber/risk metrics; partner with Legal & Compliance to operationalize controls and meet laws/regulations; collaborate with External Relations on proposed cyber legislation.
- Proven impact (8+ years): Identify vulnerabilities and deliver mitigation plans in fast-paced settings; juggle multiple priorities while operating independently or as part of a team.
- Security certs (e.g., CISSP, CISM, CRISC, CISA, GIAC, EC-Council) desired
- Deep technical breadth: Hands-on expertise in 2+ areas (e.g., network or embedded/hardware security, cryptography, web/network protocols, SBOM, threat modeling, pen testing, vulnerability assessment); OT familiarity preferred.
- Automation & measurement: Use Python/Rust to automate security workflows; establish and track KPIs/metrics that quantify security and risk performance.
- Audit & compliance leadership: Run audits and certification programs end-to-end—scope, control design, testing, risk mapping, and reporting—across SOC 2, ISO 27001, NIST frameworks; experienced in SOX environments.
- Stack fluency: Working knowledge of Email Security, DLP, CSPM, ZTNA, EDR/XDR and adjacent security technologies to strengthen enterprise posture.
- Credentials & communication: BS/MS in IS/CS/SE (or related); strong written/verbal communicator with cross-functional teams (technical & non-technical); proficient with Microsoft Word, Excel, PowerPoint, Outlook
- Solid exposure to cybersecurity best practices for software development and distributed architecture systems.
- HUGE PLUS - experience working in production ready coding environments in the energy trading or financial trading sector
- HUGE PLUS - solid understanding of national energy markets and renewable energy portfolios - PJM, ERCOT, SPP, MISO, NYISO, ISO-NE, and CAISO; capacity prices, regional energy pricing, congestion and curtailment analysis, transmission constraints, interconnection assessments, LMPs (locational marginal pricing), and/or regional supply and demand curves)
- Ideal candidates for this role will have experience working inSenior, Lead, Principal, Hands-on Manager, and Hands-on Director level rolesas Principal Cybersecurity Engineer, Cybersecurity Architect, Enterprise Security Engineer, Cyber Security Manager, Platform Security Engineer, Security Solutions Architect
