Global Cybersecurity Risk Manager
UGI CorporationAbout the role
Requistion Number: 25817
When you work for AmeriGas, you become a part of something BIG! Founded in 1959, AmeriGas is the nation’s premiere propane company, serving over 1.5 million residential, commercial, industrial and motor fuel propane customers. Together, over 6,500 dedicated professionals will deliver over 1 billion gallons of propane from 1,800+ distribution points across the United States.
Job Summary
This position is a leadership position reporting to the CISO. The Global Cybersecurity Risk Manager is responsible for identifying, assessing, and managing information/cybersecurity related risks within the organization, by ensuring assessments of systems, processes, and technologies align with regulatory requirements, established standards and policies informed by the NIST Cybersecurity Framework, European Union regulations, and company/industry best practices that requires compliance. The Global Cybersecurity Risk Manager will work closely with cross-functional teams to assist with developing strategies to mitigate risks, enhance security controls to protect critical assets and data and advise the GRC team on security exceptions and vendor security risk management practices. The Global Cybersecurity Risk Manager will also provide oversight for all security related audits, assessments and action items from incidents under the scope of the CISO as well as promote risk awareness and enhancements to the control environment.
Duties and Responsibilities
- Advise the CISO on emerging risks and trends in the security industry and continuously assess the industry’s relevant risk events to assess how they may impact UGI.
- Assist in developing and driving the internal assessment plans that cover cyber security risks globally for information technology and operational technology and ensure all action plans and recommendations are tracked from internal and external assessments.
- Support projects through a security risk lens in support of evolving technology.
- Collaborate with ERM and other key stakeholders to establish the organization’s cybersecurity risk management strategy, expectations, and policies to align with regulatory requirements (i.e., NIS Directive, SEC, PCI, SOX, GDPR, CCPA, PUC, FERC, etc.)
- Ensure risks and exposures are clearly understood by key partners and gain consensus from management to understand, manage, and mitigate information/cyber security risks in line with an evolving business strategy.
- Establish a robust global process to conduct, track and report on the outcomes of internal and external control assessments progress on action items and recommendations to monitor process.
- Provide second line subject matter expert review and challenge (e.g., risk assessments, testing) where appropriate, including evaluation of risk prioritization to ensure a clear and collective view of risks.
- Establish strong external connections to stay ahead of emerging threats and what the industry is doing in the cybersecurity environment.
- Provide regular updates on risk management activities and significant risk exposures.
- Utilize data-driven insights to identify emerging risks and inform strategic planning.
- Ability to develop a mentoring culture with both experienced team members and junior staff.
Knowledge, Skills and Abilities
- This position requires keen external focus and avid learning given the rapid pace of change globally.
- Resourcefulness, good judgment, persistence, the ability to influence others and strong executive presence are some of the qualities of a successful candidate.
- Executive level communication skills, both oral and written, and the ability to partner effectively with multiple business groups, corporate functions and external providers.
- Represent the company’s position regarding risk matters and influence executives in a manner that is consistent with goals and objectives.
- Consistent track record of effectively working with data to manage risk and process re-engineering, simplification and streamlining.
- Comfortable in ambiguity and an advocate for change.
- Driven to achieve results and adept at reading the environment and managing change.
- Knowledge of risk management in cloud environments.
- Ability to prioritize work and possess good time management skills.
Education and Experience
- Bachelor’s degree in Computer Science, Information Systems, Cyber Security or Information Technology.
- Master’s Degree (Preferred): in Cybersecurity, Risk Management or Business Administration (MBA) with a Cyber or Risk focus can provide a deeper understanding of strategic management and leadership.
- One or more Industry-standard security certifications (such as CISSP, CISM, CISA, CRIS
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s