About Stem
Stem (NYSE: STEM) is a global leader in AI-enabled software and services that enable its customers to plan, deploy, and operate clean energy assets. The company offers a complete set of solutions that transform how solar and energy storage projects are developed, built, and operated, including an integrated suite of software and edge products, and full lifecycle services from a team of leading experts. More than 16,000 global customers rely on Stem to maximize the value of their clean energy projects and portfolios. Learn more at
http://www.stem.com
.
Stem’s culture embodies diversity & inclusion beyond the traditional facets of gender, ethnicity, age, disabilities, and sexual orientation to include experience, personality, communication, workstyles, and more. At our core, Stem is at the momentous intersection of clean energy and software technology where diverse ideas, experiences, and professional skills converge to make the inclusive culture we have today. Together, we are turning old school thoughts about software and energy into progressive, collaborative, and innovative solutions. By joining our team, you will be collaborating with data scientists, energy experts, skilled salespeople, thought-leading executives and more from a range of backgrounds. This intersection of ideas, beliefs, and skills is what makes us unique enough to lead the world’s largest network of digitally connected energy storage systems.
What we are looking for:
As a Chief Information Security Officer, you will be responsible for establishing and maintaining Stem's enterprise-wide cybersecurity vision, strategy, and program to ensure all information assets and technologies are adequately protected. You will lead the development and implementation of comprehensive security policies, procedures, and controls while ensuring regulatory compliance across multiple frameworks. This role requires both strategic leadership and hands-on expertise in cybersecurity, with a focus on building a security-first culture that aligns with our business objectives and supports our growth in the clean energy sector.
Responsibilities:
•Strategic Security Leadership - Develop and implement a comprehensive cybersecurity strategy that aligns with Stem's business objectives and risk tolerance, ensuring protection of our clean energy technology platform and customer data.
•Develop and implement cybersecurity and data privacy policies that enable business objectives and satisfy external requirements.
•Risk Management & Governance - Establish and oversee enterprise-wide cybersecurity risk management program, conducting regular risk assessments and implementing appropriate controls to mitigate identified vulnerabilities.
•Compliance & Audit Management - Lead SOC 2 Type II audits, ISO 27001 certification processes, and other regulatory compliance requirements. Ensure adherence to industry standards including NIST, Zero Trust, PCI DSS, and relevant data privacy regulations (GDPR, CCPA).
•Incident Response & Crisis Management - Develop and maintain comprehensive incident response plans, lead crisis communications during security events, and oversee post-incident analysis and remediation efforts.
•Security Architecture & Technology - Guide the selection, implementation, and management of security technologies including SIEM, endpoint detection and response (EDR), identity and access management (IAM), and cloud security solutions.
•Team Leadership & Development - Build and lead a high-performing cybersecurity team. Manage relationships with external security providers and consultants.
•Business Enablement - Collaborate with executive leadership to ensure security initiatives support business growth while maintaining appropriate risk levels. Translate complex security concepts into business-friendly language for stakeholders.
•Security Awareness & Training - Develop and implement comprehensive cybersecurity awareness programs for all employees, ensuring a security-first culture throughout the organization.
•Regulatory & Legal Coordination - Work closely with legal, compliance, and privacy teams to ensure cybersecurity practices meet all regulatory requirements and contractual obligations.
•Budget Management - Develop and manage cybersecurity budget, ensuring efficient allocation of resources while maintaining effective security posture.
•Third-Party Risk Management - Establish and oversee vendor security assessment programs, ensuring all third-party relationships maintain appropriate security standards.
•Business Continuity & Disaster Recovery - Develop and maintain comprehensive business continuity and disaster recovery plans, ensuring rapid recovery from security incidents.
Requirements:
Education:
•Bachelor's degree in Computer Science, Information Security, or related technical field required. Master's degree in Cybersecurity, Information Systems, or relevant discipline preferred.
Experience:
•12+ years of progressive experience in information security roles with at least 5 years in senior leadership positions
•10+ years of hands-on experience with cybersecurity technologies and frameworks
•Proven track record of leading SOC 2, ISO 27001, and other compliance audit processes
•Experience in technology companies, preferably in clean energy, SaaS, or IoT environments
Technical Expertise:
•Deep knowledge of cybersecurity frameworks (NIST, ISO 27001, COBIT, SANS)
•Extensive experience with security technologies (SIEM, EDR, IAM, firewalls, intrusion detection/prevention)
•Strong understanding of cloud security (AWS, Azure, GCP) and DevSecOps practices
•Experience with vulnerability management, penetration testing, and security assessments
•Knowledge of data privacy regulations (GDPR, CCPA, HIPAA) and their implementation
Certifications (Required):
•CISSP (Certified Information Systems Security Professional)
•CISM (Certified Information Security Manager) or CISA (Certified Information Systems Auditor)
•Additional preferred certifications: CCISO, CISSP, CGEIT, CRISC
Leadership & Business Skills:
•Proven ability to build and lead high-performing security teams
•Strong business acumen with ability to align security strategy with business objectives
•Excellent communication skills with ability to present to executive audiences and board members
•Experience working with customers on security and compliance requirements
•Track record of successfully managing security budgets and vendor relationships
Industry Knowledge:
•Understanding of critical infrastructure security requirements
•Knowledge of energy sector regulations and compliance requirements
•Experience with IoT security and industrial control systems preferred
•Familiarity with financial services and energy trading security requirements
Salary Range
$220,400.00 - $330,600.00
What We Offer:
At Stem, you will work in a growing, innovative, mission-driven company with talented colleagues that have a passion for building renewable energy systems. Stem offers competitive compensation as well as a comprehensive set of benefits to support the health and wellness of our employee including:
•A competitive compensation package, including eligibility for a bonus or commission based on the role, and equity
•Full health benefits on the first day of employment (several medical plan options-HDHP and PPO, dental plans, FSA/HSA-with employer contribution, employer paid vision/LTD/STD/Life, variety of voluntary coverage)
•401k (pre- or post-tax) on first day of employment
•12 paid calendar holidays per year
Learn More
To learn more about Stem, visit our stem.com where you’ll find information about our solutions, technology, partners, case studies, resources, latest news and more. Here are some relevant links:
Stem, Inc. is an equal opportunity employer committed to diversity in the workplace and does not discriminate against any employee or applicant for employment because of race, color, sex, pregnancy, religion, national origin, ethnicity, citizenship, sexual orientation, gender identity, age, marital status, disability, genetic information, military status, protected veteran status or any other factor protected by applicable federal, state or local laws.