Senior Manager Cybersecurity
Duke Energy CorporationAbout the role
Important Application Submission Information
In order to ensure your application is successfully received before the job posting expires, please submit your application by 11:59 PM on Sunday, August 23, 2026More than a career - a chance to make a difference in people's lives.
Build an exciting, rewarding career with us – help us make a difference for millions of people every day. Consider joining the Duke Energy team, where you'll find a friendly work environment, opportunities for growth and development, recognition for your work, and competitive pay and benefits.
Job Summary
Leads Duke Energy’s Cybersecurity Supply Chain Risk Management (C-SCRM), Third-Party Risk Management (TPRM), and Cybersecurity Culture & Awareness programs. Responsible for establishing strategy, governance, operational processes, and performance metrics that identify, assess, mitigate, monitor, and report cybersecurity risk arising from suppliers, vendors, service providers, software providers, cloud providers, and other external dependencies. Oversees the enterprise cybersecurity culture and awareness program to strengthen employee security behaviors, reduce human risk, and improve organizational cyber resilience.
Leads managers and cybersecurity professionals responsible for supplier and third-party cyber risk assessments, continuous monitoring, contractual cybersecurity requirements, secure software supply chain governance, awareness training, phishing resilience, culture measurement, and executive engagement programs. Ensures alignment with cybersecurity strategy, regulatory obligations, business objectives, and industry frameworks.
Responsibilities
Develop and maintain the enterprise Cybersecurity Supply Chain Risk Management (C-SCRM) and TPRM governance framework.
Provide clear risk mitigating directives for projects/initiatives/services including the application of controls to protect company assets.
Maintain and support a document framework of continuously up-to-date cybersecurity policies, standards and guidelines for the TPRM and Cybersecurity Awareness programs.
Help create the necessary internal networks among the cybersecurity team and line-of-business areas to ensure alignment as required.
Manage end-to-end third-party cyber risk lifecycle activities including:
Intake
Risk assessment
Remediation tracking
Exception management
Periodic reassessment
Offboarding
Oversee cyber assessments utilizing:
SIG questionnaires
SOC 1/SOC 2 reports
ISO certifications
Independent assessments
Continuous monitoring platforms
Provide regular reporting on the status of the Third-Party Risk Management (TPRM) and Cybersecurity Awareness programs as part of a strategic enterprise risk management program, thus supporting business positive outcomes.
Support a process for monitoring and periodically re-assessing third parties to ensure compliance with obligations.
Work with Legal and Supply Chain to ensure that cybersecurity requirements and the right to assess third parties be included in contracts/agreements.
Oversee the cybersecurity awareness and training program for all employees, contractors and approved system users, including formation, evaluation and action plans based on metrics regarding program effectiveness.
Required/Basic Qualifications
Bachelors degree in Cybersecurity, Computer Science, Management Information Systems, or Other Related Degree
Minimum 10 years related work experience
In lieu of Bachelors degree(s) AND 10 year(s) related work experience listed above, High School/GED AND 14 year(s) related work experience
Desired Qualifications
Experience designing, implementing, and leading Third Party Risk Management (TPRM) programs at scale.
Knowledge of applicable NIST and ISO 27001/27036 Cybersecurity standards along with SOC1/SOC2 Type 1/Type 2 reports.
- <
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s