Cyber Security Architect

Eugene Water and Electric BoardEugene, OR
Hybrid

About The Position

The Eugene Water & Electric Board (EWEB) is seeking a Cyber Security Architect to join their cybersecurity team. This role supports both IT and operational technology environments within Oregon’s largest public utility. The position functions as a hands-on cybersecurity practitioner and leader, involved in security architecture, assurance, compliance, engineering, operations, incident response, vulnerability management, program development, and governance. Responsibilities span multiple specialty areas, with priorities shifting based on operational needs, risk posture, and security conditions. Success requires the ability to operate across business functions and security domains, prioritize effectively in a high-demand environment, communicate across the organization, and apply pragmatic, risk-based judgment.

Requirements

  • Knowledge of technology architecture, engineering, and technical control design across the enterprise technology stack, including cloud, identity, network, endpoint, database, and related security technologies.
  • Knowledge of cybersecurity governance, risk, and compliance, including the ability to evaluate technical security risks and translate them into business impact and risk treatment considerations.
  • Knowledge of planning and performing cybersecurity assessments and supporting audits, including evaluating control design, implementation, and effectiveness.
  • Knowledge of SAP or similar ERP security and control environments, including related experience with access controls, segregation of duties, role design, and evaluation of application-level security controls.
  • Knowledge of operational technology (OT) security concepts, including industrial control systems, network segmentation, monitoring constraints, and security considerations specific to OT environments.
  • Skills in project management.
  • Skills in architecture, deployment, and operation of complex technical systems to address business needs.
  • Ability to effectively communicate complex cybersecurity-related concepts to technical and non-technical audiences at all levels.
  • Ability to provide cybersecurity leadership, mentorship, and guidance across teams, influencing outcomes and supporting effective collaboration without direct authority.
  • Ability to develop and lead cybersecurity programs and initiatives with limited management guidance, owning outcomes, priorities, and stakeholder coordination.
  • Bachelor’s degree in cybersecurity, computer science, or related field required.
  • Certified Information Systems Security Professional (CISSP) certification required, or the ability to obtain one within six months.
  • Seven (7) years of progressive experience in cybersecurity, information security, or related fields required, including responsibility for leading functions such as cybersecurity architecture, security operations, governance, assurance, risk management, and program development.
  • Must be authorized to work for any employer in the United States.
  • Must live in the state of Oregon.

Nice To Haves

  • Experience as a cybersecurity practitioner in utility or other OT organizations, including experience securing OT or other critical infrastructure environments.
  • Experience assessing security controls for SAP or similar ERP platforms.
  • Experience with NERC CIP standards.
  • Audit, risk, and security-related training or certifications.

Responsibilities

  • Provide cybersecurity architecture development and consultation, representing Cyber Security as a member of the EWEB architecture team.
  • Lead and coordinate security reviews of technology solutions, including architectural, application, and compliance considerations.
  • Evaluate the benefits and risks of technology solutions and identify implementation strategies to enhance security posture.
  • Develop, maintain, and execute cybersecurity assurance activities, including internal assessments, third-party and regulatory audit support, compliance monitoring, and control validation.
  • Develop and maintain cybersecurity standards and related documents to support security governance and operational risk management.
  • Provide risk treatment recommendations to address non-compliance, remediation needs, audit and assessment findings, and other assurance outcomes.
  • Develop and mature cybersecurity programs and capabilities, including processes, metrics, roles and responsibilities, resources, inventories, reporting mechanisms, accountability, and performance optimization.
  • Lead the cybersecurity education and awareness program to mature organizational risk awareness and security culture.
  • Lead and support incident response program development, readiness, and execution, including plans, runbooks, response activities, and post-incident improvement.
  • Elevate operational security capabilities by integrating monitoring and other telemetry into actionable analysis and risk-informed response.
  • Provide primary and/or backup support for designated cybersecurity programs, processes, and technical security controls.

Benefits

  • Health care
  • Vacation and sick leave
  • Pension
  • Holidays
  • Employee credit union
  • Relocation reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service