About the Role
The AVP, Information and Cybersecurity is accountable for supporting the SVP, Enterprise Technology in establishing, operating, and continuously improving cybersecurity, technology risk, operational resilience, AI governance, and critical infrastructure protection capabilities. This role provides enterprise leadership across various cybersecurity domains, protecting corporate, cloud, operational technology, generation, storage, and transmission environments while enabling business growth and modernization. The position serves as an advisor to executive leadership and the Board on these critical areas.
Responsibilities
- Develop and execute a multi-year cybersecurity, resilience, technology risk, and AI governance strategy.
- Establish enterprise cybersecurity governance, risk management, and reporting processes.
- Ensure cybersecurity, resilience, AI, and technology risks are incorporated into enterprise planning and investment decisions.
- Develop and manage cybersecurity operating and capital budgets.
- Develop cybersecurity investment plans and assess initiatives.
- Provide regular reporting to executive leadership and the Board regarding cyber risk posture, incidents, resilience, threats, and regulatory developments.
- Conduct periodic cyber maturity assessments and benchmarking.
- Establish enterprise security awareness, education, and AI awareness programs.
- Lead enterprise cybersecurity capabilities across threat detection, intelligence, vulnerability management, identity security, cloud security, incident response, cyber defense, and attack surface management.
- Ensure effective security governance and protection across enterprise infrastructure, cloud platforms, OT environments, and critical business systems.
- Ensure effective capabilities for identifying, assessing, responding to, and recovering from cyber threats.
- Establish cyber crisis management, cyber recovery, business continuity, and disaster recovery capabilities.
- Support incident response, disaster recovery, operational resilience, and technology risk management activities.
- Leverage automation and AI-enabled capabilities to improve cybersecurity effectiveness and outcomes.
- Ensure third-party cyber risk management capabilities appropriately address vendors, contractors, cloud providers, OT suppliers, EPC partners, and strategic service providers.
- Lead cybersecurity strategy and governance supporting operational technology environments.
- Establish cybersecurity and resilience standards supporting OT architecture, remote access, network segmentation, monitoring, asset visibility, vendor connectivity, and secure operations.
- Support operational readiness, secure operations, recoverability, and resilience across critical infrastructure environments.
- Coordinate with operational stakeholders to ensure technology environments meet reliability, safety, resilience, and compliance expectations.
- Support secure integration of new facilities, operational technologies, acquisitions, and strategic growth initiatives.
- Ensure cybersecurity capabilities evolve in alignment with emerging threats affecting OT and critical infrastructure environments.
- Ensure cybersecurity operations align with applicable regulatory, cybersecurity, operational risk management, and NERC CIP requirements.
- Serve as the executive sponsor for NERC CIP cybersecurity governance, audit readiness, compliance activities, and remediation programs.
- Oversee compliance reporting, evidence management, remediation tracking, control validation, and regulatory readiness activities.
- Partner with Legal, Compliance, Internal Audit, Enterprise Technology, and operational stakeholders to maintain effective governance and regulatory alignment.
- Monitor evolving regulatory requirements and industry standards and ensure timely adaptation of policies, controls, and operating procedures.
- Establish metrics and reporting that provide visibility into compliance posture, control effectiveness, audit readiness, and remediation progress.
- Establish enterprise governance, risk management, and security practices supporting responsible adoption of AI technologies.
- Ensure AI systems, AI agents, autonomous workflows, and third-party AI services are appropriately inventoried, governed, monitored, and secured.
- Establish governance and security requirements for AI systems, AI agents, and autonomous workflows.
- Protect AI-enabled business processes, models, training data, prompts, retrieval data, and outputs from unauthorized access, misuse, manipulation, or disclosure.
- Support adoption of AI technologies while maintaining appropriate cybersecurity, privacy, operational, and regulatory safeguards.
- Drive adoption of AI-enabled cybersecurity capabilities.
- Partner with Enterprise Technology leadership to ensure cybersecurity, resilience, AI governance, and regulatory requirements are embedded into enterprise architecture, cloud transformation, OT initiatives, and digital modernization programs.
- Support scalable technology architectures that improve resilience, security, maintainability, and operational effectiveness.
- Reduce fragmentation, unnecessary complexity, and inconsistency of cybersecurity controls.
- Support enterprise technology modernization, integration activities, and strategic operational initiatives.
- Ensure cybersecurity requirements are integrated into technology acquisition, development, deployment, and operational support processes.
- Establish and govern a risk-based third-party cybersecurity and supply chain risk management program.
- Ensure cybersecurity risks are appropriately assessed and managed across vendors, contractors, cloud providers, EPC partners, OT suppliers, and strategic service providers.
- Support cybersecurity due diligence activities associated with acquisitions, integrations, strategic partnerships, and major technology investments.
- Ensure cybersecurity requirements are embedded throughout procurement, contracting, onboarding, monitoring, and offboarding processes.
- Monitor concentration risk and dependencies associated with critical suppliers and service providers.
- Partner with business leadership and Enterprise Excellence to support enterprise prioritization, portfolio governance, operational execution, and risk-based decision-making.
- Improve execution discipline, transparency, accountability, operational metrics, and value realization across cybersecurity and resilience initiatives.
- Contribute to enterprise governance processes that improve scalability, operational effectiveness, and decision quality.
- Support enterprise operating rhythms and governance forums that strengthen accountability and cross-functional collaboration.
- Build and lead high-performing cybersecurity teams.
- Develop internal cybersecurity capability and reduce over-reliance on external implementation and coordination models.
- Foster a culture of accountability, systems thinking, operational excellence, continuous improvement, and enterprise partnership.
- Build durable organizational capability through succession planning, workforce development, leadership coaching, and talent development.
- Serve as an advisor to executive leadership and the Board on cybersecurity, technology risk, operational resilience, AI governance, and critical infrastructure protection.
- Support enterprise scaling initiatives, acquisitions, integration activities, major operational changes, and strategic business priorities.
- Assess cybersecurity investments with focus on enterprise value, operational resilience, risk reduction, scalability, and long-term sustainability.
- Build trusted relationships with executive leadership, business stakeholders, regulators, strategic vendors, and operational partners.
- Represent Pattern Energy in relevant industry forums, NERC-related working groups, cybersecurity communities, and critical infrastructure engagements.
Requirements
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Engineering, Information Systems, Business Administration, or related discipline.
- 15+ years of progressive leadership experience across cybersecurity, technology risk, operational technology, critical infrastructure security, resilience, or related operational environments.
- Experience leading cybersecurity programs within complex, highly regulated, or critical infrastructure industries preferred.
- Strong understanding of cybersecurity governance, technology risk management, operational resilience, cyber defense, regulatory compliance, and critical infrastructure protection.
- Demonstrated experience supporting operational technology environments, industrial control systems, and NERC CIP compliance programs.
- Experience leading cyber crisis management, incident response, business continuity, disaster recovery, and operational resilience initiatives.
- Strong understanding of NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-82, IEC/ISA 62443, CIS Controls, and comparable critical infrastructure security frameworks.
- Demonstrated experience improving cybersecurity maturity, governance, resilience, and enterprise scalability.
- Experience leading enterprise cybersecurity modernization and transformation efforts.
- Experience establishing AI governance, AI security, or responsible AI programs preferred.
- Strong executive communication and stakeholder management skills with ability to operate effectively across technical and business leadership teams.
- Experience supporting operational technology and cybersecurity environments in energy, utilities, industrial, or critical infrastructure sectors preferred.
- Professional certifications such as CISSP, CISM, CRISC, CISA, GICSP, GIAC, or equivalent are preferred.
- Regular travel to corporate offices, operating facilities, control centers, construction projects, and integration sites across North America is required.
Skills
- Cybersecurity
- Technology Risk Management
- Operational Resilience
- AI Governance
- Critical Infrastructure Protection
- Cybersecurity Strategy
- Cybersecurity Governance
- Risk Management
- Reporting
- Budget Management
- Threat Detection
- Threat Intelligence
- Vulnerability Management
- Identity Security
- Cloud Security
- Incident Response
- Cyber Defense
- Attack Surface Management
- Cyber Crisis Management
- Business Continuity
- Disaster Recovery
- Automation
- AI-enabled Capabilities
- Third-Party Risk Management
- Operational Technology (OT) Security
- Industrial Control Systems (ICS) Security
- SCADA Security
- NERC CIP Compliance
- Regulatory Compliance
- AI Security
- Responsible AI
- Enterprise Architecture
- Cloud Transformation
- Digital Modernization
- Supply Chain Risk Management
- Executive Communication
- Stakeholder Management
- Talent Development
- Succession Planning
- Team Leadership
Location
- North America
Work Type
- Hybrid
Experience Level
- 15+ years of progressive leadership experience
Education Level
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Engineering, Information Systems, Business Administration, or related discipline.
Salary/Compensations
- $203,000.00 - $254,000.00 USD
Benefits
- Bonus structure
- Medical insurance
- Dental insurance
- Vision insurance
- Short-term disability
- Long-term disability
- Life insurance
- Voluntary benefits
- Family care benefits
- Employee assistance program
- Paid time off and bonding leave
- Paid holidays
- 401(k)/RRSP retirement savings plan with employer contribution
- Employee referral bonuses
About the Company
- Pattern Energy is a leading renewable energy company that develops, constructs, owns, and operates high-quality wind and solar generation, transmission, and energy storage facilities.
- Our mission is to transition the world to renewable energy through the sustainable development and responsible operation of facilities with respect for the environment, communities, and cultures where we have a presence.
- Our company values of creative spirit, pride of ownership, follow-through, and a team-first attitude drive us to pursue our mission every day.
- Our culture supports our values by fostering innovative and critical thinking and a deep belief in living up to our promises.
- Headquartered in the United States, Pattern has a global portfolio of more than 30 power facilities and transmission assets, serving various customers that provide low-cost clean energy to millions of consumers.
Equal Opportunity
- Pattern Energy Group is an Equal Opportunity Employer.
