Leads Duke Energy’s Cybersecurity Supply Chain Risk Management (C-SCRM), Third-Party Risk Management (TPRM), and Cybersecurity Culture & Awareness programs. Responsible for establishing strategy, governance, operational processes, and performance metrics that identify, assess, mitigate, monitor, and report cybersecurity risk arising from suppliers, vendors, service providers, software providers, cloud providers, and other external dependencies. Oversees the enterprise cybersecurity culture and awareness program to strengthen employee security behaviors, reduce human risk, and improve organizational cyber resilience. Leads managers and cybersecurity professionals responsible for supplier and third-party cyber risk assessments, continuous monitoring, contractual cybersecurity requirements, secure software supply chain governance, awareness training, phishing resilience, culture measurement, and executive engagement programs. Ensures alignment with cybersecurity strategy, regulatory obligations, business objectives, and industry frameworks.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior