Senior Manager, Security Governance
Pattern EnergyAbout the role
Overview
COMPANY OVERVIEW
Pattern Energy is a leading renewable energy company that develops, constructs, owns, and operates high-quality wind and solar generation, transmission, and energy storage facilities. Our mission is to transition the world to renewable energy through the sustainable development and responsible operation of facilities with respect for the environment, communities, and cultures where we have a presence.Our approach begins and ends with establishing trust, accountability, and transparency. Our company values of creative spirit, pride of ownership, follow-through, and a team-first attitude drive us to pursue our mission every day. Our culture supports our values by fostering innovative and critical thinking and a deep belief in living up to our promises. Headquartered in the United States, Pattern has a global portfolio of more than 35 power facilities and transmission assets, serving various customers that provide low-cost clean energy to millions of consumers.
Responsibilities
JOB PURPOSE
The Sr. Manager, Enterprise Technology Security & Governance is responsible for leading, governing, and maturing the organization’s enterprise security, cyber risk management, and critical infrastructure compliance capabilities. This role provides end to end ownership of security operations, identity governance, vulnerability and patch management, and NERC CIP compliance governance, ensuring alignment between regulatory obligations, cyber risk posture, and operational continuity across IT, OT, and cloud environments aligned to industry-standard frameworks such as NIST Cybersecurity Framework (CSF) and NIST 800-53/800-82 where applicable.
This is a hands-on senior leadership role requiring a blend of deep technical expertise, regulatory knowledge, and the ability to establish strong governance, policy, and accountability frameworks. The role operates at the intersection of cybersecurity, critical infrastructure operations, and compliance, serving as a key advisor to executive leadership on security risk and NERC CIP readiness. The ideal candidate has experience operating in regulated, mission critical environments—preferably energy, utilities, or renewables—and can balance security rigor with business and operational realities.
Key Accountabilities
- Security & compliance governance
- Establish and operate enterprise governance aligned to nist cybersecurity framework (csf) and nerc cip, including control mapping, maturity assessment, and consistent execution across it, ot, and cloud environments develop and maintain a nist-aligned security maturity roadmap, using nist csf or 800-53 to assess current state, define target state, and prioritize risk-based improvements
- Oversee and continuously improve incident response and cyber crisis management capabilities, including tabletop exercises and post-incident reviews
- partner with security operations to ensure detection and response capabilities align with enterprise risk tolerance
- Define, maintain, and enforce security, access control, patching, and vulnerability management policies, standards, and procedures
- Serve as a primary security and compliance authority during nerc cip audits, assessments, and regulatory engagements
- Ensure audit readiness through strong documentation, logging, evidence collection, and control validation
- Develop and execute a multi-year security and compliance roadmap aligned with business priorities, regulatory requirements, and risk posture
- Track compliance risks, remediation commitments, and control effectiveness, escalating issues as needed
- Establish and govern third-party cyber risk management, including vendor assessments, access controls, and ongoing monitoring
- Identity & access governance
- Own iam and identity governance programs, including rbac, least privilege enforcement, separation of duties, and periodic access certifications
- Ensure access control processes integrate with compliance, audit, and security monitoring requirements
- Partner with hr, infrastructure, ot, and cloud teams to ensure secure and compliant onboarding, offboarding, and role changes
- Cross functional leadership
- Collaborate closely with infrastructure, ot, cloud, security operations, legal, compliance, and internal audit teams to reduce cyber and compliance risk
- Act as a bridge between technical execution teams and executive leadership
- Translate technical vulnerabilities and compliance gaps into clear, business focused risk narratives
- People & capability development
- Coach, mentor, and develop a high performing team through clear goals, feedback, and career development
- Identify capability gaps and build sustainable processes rather than single point technical
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s