Director, Cyber Security Services - (26-IT-601015-082)
DC WaterAbout the role
The intent of this job description is to provide a representative summary of the major duties, locations, and responsibilities performed by incumbent(s) in this job. Incumbent(s) may not be required to perform all duties in this description, and incumbent(s) may be required to perform work-related tasks other than those specifically listed in this description. This job description is not a “contract” between the employee and the Authority. The job duties and essential functions may be changed at the discretion of the General Manager.
GeneralJob Title:Director, Cyber Security ServicesJob Code:OA0423 Supervises Directly:YesNew or Revised:RevisedRegular or At-Will:At-WillDate:5/5/2026Exempt or Non-Exempt:ExemptCompensation Approval Signature: Union / Non-Union:Non-UnionDivision
Department Name
Information Technology
IT-Information Security
Salary Schedule: Non-Union Salary RangeCost Center Code: 601015Grade:ESSBEssential Position:YesReports To:Vice-President, Information TechnologyEEO Code:Officials and AdministratorsWork FormatHybridWho We Are & What We Do:
At DC Water, we provide more than 700,000 District of Columbia residents and 24.6 million annual visitors with essential water, wastewater, and stormwater services. DC Water also provides wholesale wastewater treatment services for 1.8 million people in Montgomery and Prince George's counties in Maryland, and Fairfax and Loudoun counties in Virginia. We aspire to be known for superior service, ingenuity, and stewardship to advance the health and well-being of our diverse workforce and communities. To achieve this vision, we commit to our shared mission every day—exceeding expectations by providing high quality water services in a safe, environmentally friendly, and efficient manner.
Role Description:The Director, Cyber Security Services is responsible for identifying, assessing, and quantifying cybersecurity risks across the enterprise, encompassing both information technology (IT) and operational technology (OT) environments. This role evaluates, designs, develops, and oversees the implementation of cybersecurity and disaster recovery programs across all aspects of the Authority’s computing infrastructure to mitigate cyber risks and ensure the highest levels of cyber resilience. The Director, Cyber Security Services collaborates with a wide range of internal and external stakeholders, including IT and engineering leadership, security professionals, and regulatory partners such as WaterISAC, CISA, DHS, TSA, the FBI, and local law enforcement, as well as cybersecurity hardware and software vendors, to identify, plan, and implement physical and cybersecurity initiatives and programs that meet or exceed industry standards and Authority requirements.
Essential Duties & Responsibilities:- Maintains awareness of industry specific developments regarding cybersecurity and assesses the impact on Authority systems and develops plans and schedules as necessary to ensure compliance. Monitors implementation plans for successful execution.
- Directs the Authority’s patch management and release management processes to ensure all systems are patched in a timely manner. Coordinates patching and maintenance with third party providers to ensure cloud solutions remain compliant.
- Conducts vendor risk assessments and ensures all IT vendors comply with Authority IT standards and guidelines, especially those related to cybersecurity.
- Leads risk management activities to enhance assessment and mitigate cyber risks for both IT and OT systems.
- Directs a network of security professionals and vendors via a matrix structure to evaluate, assess, and develop strategies regarding potential threats to the Authority’s computer and information infrastructure.
- Designs and implements protection goals, objectives, and metrics consistent with the corporate strategic plan to ensure the highest level of cyber resiliency; creates work breakdown structures (WBS), project plans, project cost estimates, project recommendations, status reports, and executive presentations focused on mitigating cybersecurity risks.
- Ensures security audits, risk analyses, vulnerability assessments, and network testing are conducted successfully.
- Directs the development and implementation of global security policies, standards, guidelines, and procedures to ensure ongoing maintenance of security posture.
- Manages IT Ass
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s