Director, Cybersecurity

Caturus

Houston (TX)

On-site

USD 150,000 - 230,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Caturus Energy, based in Houston, seeks a Director of Cybersecurity to lead the unified security function across IT and OT/ICS.

You will own the full lifecycle of enterprise information security, ensuring assets are inventoried, vulnerabilities tracked to closure, and critical systems tested with third parties. You will map controls to NIST/ISO frameworks and report to leadership.

Qualifications

  • 10+ years of information security experience, including leadership across IT and OT/ICS.
  • Experience in energy/critical-infrastructure sectors preferred.
  • Proven ability to run multidisciplinary vulnerability management and third-party testing programs.

Responsibilities

  • Own day-to-day security operations across IT and OT/ICS environments.
  • Drive IT/OT network segmentation per ISA/IEC 62443 and NIST guidelines.
  • Build and mature security operations with incident response and threat intel.
  • Maintain asset inventory across IT and OT, including third-party systems.
  • Govern vendor remote access with least-privilege, MFA, and time-bound access.
  • Coordinate security with field operations, API 1164, and safety reviews.
  • Lead vulnerability management with age, status, and owner tracking.

Skills

Security operations
Vulnerability management
IT/OT security
Risk governance
Third-party risk

Education

Bachelor's in IT/CS/Engineering
MBA preferred

Job description

Location: US TX Houston - Corporate Office

Department: Information Technology

Location: US TX Houston - Corporate Office

Description
About Us:

The Caturus platform founded by Kimmeridge - an alternative asset manager focused on the energy sector - supports Kimmeridge's overarching goal of providing low-cost energy on demand with the lowest carbon footprint.

Kimmeridge's vision in creating Caturus is to build the only independent, fully integrated natural gas and LNG export platform in the U.S. through a combination of its upstream operations and via Commonwealth LNG, a 9.5 million tonnes per annum liquefied natural gas export terminal in southwestern Louisiana on the U.S. Gulf Coast. The combined entities are committed to delivering responsibly sourced, low-emission fuel to domestic and international markets.

Caturus is a Houston-based, private exploration and production company seeking to materially grow production through development of deep, high pressure, dry gas windows of the Eagle Ford and Austin Chalk, as well as Haynesville formations located in Texas and Louisiana while maintaining a relentless focus on safety.

Commonwealth LNG was founded by industry veterans who decided to re-engineer the LNG construction model. Using proven best practices, Commonwealth is committed to building a world-class LNG export facility while focusing on safety, managing risk and achieving best-in-class environmental standards.

Job Description
Position Summary:

The Director, Cybersecurity is responsible for leading Caturus Energy's unified security function across both Information Technology (IT) and Operational Technology (OT) environments. This role owns the full lifecycle of enterprise information security: analysis, operations, governance, and risk management, spanning corporate IT systems, upstream field/SCADA systems, midstream gathering infrastructure, and the Commonwealth LNG terminal's industrial control systems (ICS). The Director is accountable for a clear, high-bar outcome: no vulnerable systems left unmanaged. Every asset is inventoried, every known vulnerability is tracked to closure on a defined timeline, every critical system is independently tested by qualified third parties (including regular penetration testing) through to verified closure, and the company can demonstrate, on demand, to auditors, insurers, lenders, regulators, or the Board, exactly how its controls map to NIST and ISO frameworks and how IT General Controls (ITGCs) are operating.

Key Accountabilities:
  • Own day-to-day security operations across corporate IT (endpoints, identity, cloud, applications) and OT/ICS environments (drilling rig systems, gathering system SCADA, LNG terminal control systems).
  • Drive IT/OT network segmentation using zone-and-conduit architecture (ISA/IEC 62443) and defense-in-depth aligned to NIST SP 800-82 Rev. 3.
  • Build and mature a security operations capability: monitoring, detection, incident response, and threat intelligence, with OT-specific playbooks that respect process safety and well-control constraints; no security action shall compromise safe operation of physical assets.
  • Maintain a current, accurate asset inventory across IT and OT, including third-party/vendor-managed systems where Caturus has visibility or contractual security requirements.
  • Govern vendor and integrator remote access to wellsite and pipeline equipment: least-privilege access, MFA, session monitoring, and time-bound access for contractors and OEMs.
  • Coordinate with Drilling, Midstream, and Commonwealth LNG operations leadership so security operations are integrated into field workflows, aligned with API 1164 and, where relevant, integrated with process-safety (HAZOP) reviews.
  • Operate a continuous vulnerability management program across IT and OT: discovery, scoring and prioritization, assigned ownership, and time-bound remediation SLAs by severity and asset criticality.
  • Maintain a live vulnerability register with age, status, and owner for every open finding; report aging or overdue items to IT leadership on a defined cadence.
  • Ensure OT vulnerability management accounts for patch windows, vendor certification requirements, legacy equipment limitations, and safety systems, with documented risk acceptance where immediate patching is not feasible.
  • Deploy or manage OT-aware asset and network visibility tooling to support inventory and detection across the field environment.
  • Establish and manage a program of third-party security assessments, including annual (minimum) penetration testing of critical IT and OT environments, periodic vulnerability assessments and configuration reviews, and red team or adversary simulation exercises as risk and maturity warrant.
  • Track every finding from every third-party assessment through to verified closure, with re-testing or evidence-based validation required before any finding is marked closed.
  • Vet and manage the roster of qualified third-party testing vendors; set scope, rules of engagement, and safety constraints for OT testing so that no testing activity risks physical safety or process integrity.
  • Develop and maintain the enterprise information security risk register covering IT and OT risk, with likelihood/impact scoring, ownership, and treatment plans (mitigate, transfer, accept, avoid).
  • Present risk posture and trends to IT leadership, executive leadership, and the Board or Audit Committee as needed.
  • Own and mature the company's security governance framework: policies, standards, and procedures for both IT and OT.
  • Track overall program maturity against a recognized model and report maturity progression to leadership over time.
  • Establish security oversight for non-operated assets and joint ventures where Caturus holds an economic interest but not operational control, defining requirements through joint-operating and data-sharing agreements in partnership with Legal and Land/Business Development.
  • Support cyber due diligence for M&A activity, including pre-close diligence, post-close integration or separation, and security provisions in transition services agreements.
  • Partner with Legal, Internal Audit, and Corporate Affairs on regulatory and contractual security obligations, including CFIUS-related requirements. Maintain current, evidence-backed control mapping to NIST Cybersecurity Framework 2.0, NIST SP 800-53/800-82 Rev. 3, ISO/IEC 27001, and (where relevant to OT) ISO/IEC 27019 or IEC 62443.
  • Maintain and report on IT General Controls (ITGCs) supporting financial reporting integrity, in coordination with Internal Audit and external auditors.
  • Maintain awareness of, and readiness for, applicable energy-sector regulatory regimes in coordination with Legal, including TSA pipeline security directives, CIRCIA incident-reporting obligations, and conditional NERC CIP applicability.
  • Produce, on demand, audit-ready evidence of control operation and compliance status for internal leadership, external auditors, lenders, insurers, or regulators. Lead or support external audits, insurance underwriting security assessments, and customer/partner due diligence security questionnaires.
  • Own the Cybersecurity Incident Response Plan covering both IT and OT, and lead periodic executive tabletop exercises, including ransomware scenarios.
  • Own secure adoption governance for AI/LLM tooling (e.g., Microsoft Copilot): permission-hygiene remediation, data-leakage prevention, shadow-AI monitoring, and an AI acceptable-use policy.
  • Maintain controls against business email compromise and vendor-payment fraud, including out-of-band verification for banking and vendor-master-file changes.
  • Build out the cybersecurity function's staffing model, including internal hires, managed security service providers, and OT security specialists, as the program matures.
  • Manage relationships with security vendors, MSSPs, and the third-party testing ecosystem.
  • Own the cybersecurity budget and multi-year roadmap in partnership with the Head of IT.
  • Lead the security-awareness and phishing-simulation program, extending security culture into field operations.
Qualifications
Education, Certificates, and Licenses:
  • Bachelor's degree in Information Technology, Computer Science, Information Systems, Engineering, or a related discipline required.
  • Master's degree in Business Administration (MBA), Information Systems, or a related discipline preferred.
  • Professional certifications such as CISSP, CISM, GICSP, GRID, GIAC I CS (ICS410/ICS515), or similar credentials preferred.
Experience:
  • 10+ years of progressive information security experience, including at least 3-5 years in a leadership role spanning both IT and OT/ICS security.
  • Experience in energy, midstream, LNG, or another critical-infrastructure sector strongly preferred.
  • Demonstrated experience running vulnerability management and third-party penetration testing programs at scale, through to verified closure. Experience with OT/ICS security fundamentals (SC
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Cybersecurity
Director, Cybersecurity

Caturus Management Services, LLC • Houston (TX)

On-site
USD 180,000 - 250,000
Manager, Strategic Delivery
Manager, Strategic Delivery

Caturus Management Services, LLC • Houston (TX)

On-site
USD 120,000 - 180,000
Manager, Strategic Delivery
Manager, Strategic Delivery

Caturus • Houston (TX)

On-site
USD 120,000 - 160,000
Director of Cybersecurity — IT & OT Security Leader
Director of Cybersecurity — IT & OT Security Leader

Caturus Management Services, LLC • Houston (TX)

On-site
USD 180,000 - 250,000
Sr. Manager Cybersecurity
Sr. Manager Cybersecurity

Oceaneering • Houston (TX)

On-site
USD 180,000 - 240,000
SCADA Technician
SCADA Technician

Caturus • Houston (TX)

On-site
USD 85,000 - 120,000
Director of Cybersecurity
Director of Cybersecurity

WSP • Houston (TX)

On-site
USD 180,000 - 260,000
Director, Cybersecurity
Director, Cybersecurity

Socket.dev • Dallas (TX)

On-site
USD 140,000 - 230,000
Senior Director, Information Security
Senior Director, Information Security

Landis+Gyr • Alpharetta (GA)

On-site
USD 180,000 - 240,000
Control Room Operator
Control Room Operator

Caturus • Houston (TX)

On-site
USD 70,000 - 110,000