Crescent Energy

Head of Cybersecurity & GRC

LocationHouston, TX
Job Typefull_time

About This Job

Company Overview

At Crescent, we are investors and operators delivering value to shareholders through a disciplined, returns-driven growth through acquisition strategy and consistent return of capital. Our long-life, balanced portfolio combines stable cash flows from low-decline production with deep, high-quality development inventory. Our activities are focused in Texas and the Rocky Mountain region.

Job Summary

The

Head of Cybersecurity & GRC

is a senior leadership position responsible for safeguarding the organization’s digital assets, operational infrastructure, and sensitive data across IT and OT environments. This role leads the strategy, execution, and oversight of the cybersecurity program and enterprise risk management framework grounded in NIST CSF and aligned with upstream oil and gas business needs.

This leader will ensure that cybersecurity and compliance practices are embedded across the organization while enabling innovation and operational continuity. The ideal candidate brings a balance of technical expertise, strategic leadership, and deep upstream oil & gas experience, particularly with production, drilling, field operations, and industrial control systems (ICS/SCADA). This position will require continuous learning and on-going stewardship and prioritization of resources to effectively align safeguards over technology components relative to the anticipated threat landscape. This individual will play a critical role in accelerating our journey toward becoming a data-driven, technology-enabled enterprise, especially in the context of the energy sector's transformation.

Key Responsibilities

Cybersecurity Strategy & Operations:

+ Develop and lead the enterprise cybersecurity strategy, with a strong foundation in the NIST Cybersecurity Framework (CSF). + Oversee security operations, incident response, vulnerability management, and threat intelligence for IT and OT environments. + Implement layered defense strategies, including network segmentation, endpoint protection, identity and access management (IAM), and security monitoring (SIEM/SOAR).

Governance, Risk & Compliance (GRC)

+ Design and operate an enterprise GRC program to manage cyber, regulatory, operational, and third-party risk. + Lead compliance with relevant standards and regulations (e.g., NIST, SOX, TSA Pipeline Security Directives, SEC cyber disclosure, FERC, PHMSA). + Oversee internal/external audits, risk assessments, insurance questionnaires, and policy development ensuring alignment with corporate and industry standards

OT Security & Upstream Operations

+ Collaborate with operations, engineering, and field teams to secure industrial control systems (ICS), SCADA, and edge devices across upstream assets. + Establish risk-based security controls for field operations without compromising uptime or performance. + Build and foster OT cybersecurity awareness and partnerships across HSE, Production, Drilling, and Asset teams.

Leadership & Stakeholder Engagement

+ Serve as a trusted advisor to executive leadership on cyber risk, digital trust, and security investments. + Develop and lead a high-performing cybersecurity and GRC team spanning security engineering, compliance, risk, and awareness functions. + Build relationships across IT, Legal, Operations, and External Affairs to embed cybersecurity into core business processes and programs. + Facilitate regular cybersecurity and risk reporting to the Board Audit Committee, translating technical risks into business impact and ensuring executive alignment on risk posture and mitigation strategies + Develop and foster external relationships with organizations and key contributors that support and may enhance the on-going cybersecurity posture and overall operational resilience (e.g. ONE-ISAC, DHS CISA, FBI, etc.)

Security Architecture & Technology Oversight

+ Oversee security architecture for cloud, on-prem, and hybrid environments ensuring secure adoption of platforms like Snowflake, Azure, and SaaS tools. + Evaluate and implement cybersecurity tools, technologies, and services to strengthen the enterprise security posture. + Lead security reviews of new projects, platforms, and partnerships (M&A, joint ventures, field digitization efforts). + Coordinate and review the risk profiles associated with technology vendors and service providers (third & fourth party).


Qualifications & Experience

Education:
Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field is required. Master’s degree is a strong plus.
CISSP certification required. Additional certifications such as CISM, CRISC, CISA, or relevant GIAC; NIST CSF Implementation credentials are a strong plus.
Experience:
7+ years of cybersecurity and/or GRC leadership experience, with a minimum of 5 years in a senior role overseeing enterprise programs.
Deep understanding of upstream oil and gas operations, including field systems, SCADA, and industrial environments.
Demonstrated success building and running security programs based on the NIST Cybersecurity Framework.
Hands-on experience managing regulatory compliance and incident response in high-stakes operational settings
Skills & Competencies:
Strong knowledge of cyber risk management, threat modeling, incident handling, and security architecture.
Deep understanding of the intersection of IT and OT cybersecurity in energy and industrial sectors.
Proven ability to communicate risk to executive stakeholders, board members, and cross-functional leaders.
Strategic thinker with a pragmatic, business-aligned approach to cybersecurity and compliance.


Work Environment & Physical Requirements

Primarily office-based with occasional travel to field offices and operational sites as needed.
Potential exposure to remote and high-risk environments, requiring adherence to safety protocols.
May involve walking, climbing, bending, or handling equipment during site visits.
Possible exposure to varying weather conditions (heat, cold, rain) while on-site at the field offices.
Availability for emergency response and incident management, including after-hours support when required.

Crescent Energy is an equal opportunity employer. All qualified applicants will be considered for employment without regard to race, color, religion, gender/pregnancy, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status or any other legally protected status. Crescent Energy is also committed to compliance with all fair employment practices regarding citizenship and immigration status. If you require accommodation to complete the application process, please let us know by contacting Kimberly Kalsey at Kimberly.Kalsey@crescentenergyco.com.

Similar Jobs

company-logo

Head of Cybersecurity & GRC

Crescent Energy
Job Typefull_time
 
Houston, TX
12 days ago
company-logo

Cybersecurity Operations Center, Senior Specialist

Southern California Edison
Salary
$140400 - $210500
Rosemead, CA
2 days ago
company-logo

GRC Security Analyst II

World Fuel Services
Job Typefull_time
 
Miami, FL
15 days ago
company-logo

Senior Cybersecurity Analyst

NextEra Energy
Job TypeFull-time
 
Hialeah, FL
13 days ago
company-logo

Cybersecurity Analyst

Golden State Water Company
Job Typefull_time
 
San Dimas, CA
5 days ago
company-logo

CyberSecurity Consultant

NiSource
Job Typefull_time
Salary
$93800 - $140700
Columbus, OH
12 days ago
company-logo

Cybersecurity Operations Center Analyst I

Alliant Energy
Job TypeFull-time
Salary
$58000 - $76000
Cedar Rapids, IA
13 days ago
company-logo

Principal Cybersecurity Engineer

The Nuclear Company
Job Typefull_time
Salary
$198000 - $228000
Seattle, WA
28 days ago
company-logo

Cybersecurity Analyst

Targa Resources
 
Tulsa, OK
30 days ago
company-logo

Cybersecurity Engineer

Solar Turbines
Job TypeFull-time
Salary
$120299 - $180449
San Diego, CA
23 days ago
company-logo

SENIOR CYBER SECURITY PROGRAM SPECIALIST

Manitoba Hydro
Job TypeTemporary, Fixed term contract
 
Winnipeg, MB
12 days ago
company-logo

Sr. OT Cyber Security Specialist

Seattle City Light
Job Typefull_time
 
Seattle, WA
14 days ago
company-logo

Cybersecurity Analyst I

Arizona Public Service (APS)
 
Phoenix, AZ
5 days ago
company-logo

Cybersecurity Manager

NextEra Energy Resources
Job Typefull_time
 
Juno Beach, FL
6 days ago
company-logo

Cybersecurity Manager

NextEra Energy
Job TypeFull-time
 
Juno Beach, FL
6 days ago
company-logo

Cybersecurity Project Advisor

Oceaneering
Job Typefull_time
 
Hanover, MD
25 days ago
company-logo

Senior Cyber Security Analyst

DC Water
Job Typefull_time
Salary
$125000 - $136000
Washington, DC
29 days ago
company-logo

Sr. Cybersecurity Engineer

NiSource
Job TypeFull-time
Salary
$110200 - $165300
Merrillville, IN
29 days ago
company-logo

Sr. Cybersecurity Engineer

NiSource
Job TypeFull-time
Salary
$110200 - $165300
Columbus, OH
29 days ago
company-logo

Senior Cybersecurity Engineer, Detection Engineer

Marathon Petroleum
Job TypeFull-time
 
San Antonio, TX
21 days ago

Trending Jobs

company-logo

Electrical Engineer

Dudley Staffing
Job TypeFull-time
Salary
$55 - $75
Canonsburg, PA
5 months ago
company-logo

Division Order Analyst

Coronado Resources
Job TypeFull-time
 
Dallas, TX
about 2 months ago
company-logo

Accounts Payable Clerk

LPR Energy
Job TypeFull-time
Salary
$65000 - $65000
Dallas, TX
about 2 months ago
company-logo

Division Order Landman

R. Lacy Services, Ltd.
Job TypeFull-time
 
Longview, TX
27 days ago
company-logo

Professional Landman

Penterra Services, LLC
Job TypeContract
 
Lovington, NM
19 days ago
company-logo

contract landman

HPS Oil & Gas Properties
Job TypeFull-time
 
Lafayette, LA
4 months ago
company-logo

Oil and Gas Land and Title Analyst - SAM Associate II

Bank of America
Job TypeFull-time
 
Dallas, TX
3 months ago
company-logo

Contracts Administrator

Third Coast
Job TypeFull-time
Salary
$70000 - $85000
Houston, TX
2 months ago
company-logo

Attorney

Toeppich & Associates
Job TypeFull-time
 
Houston, TX
about 1 year ago
company-logo

Title Landman

Sustain Land Services
Job TypeFull-time
 
Norman, OK
3 months ago
company-logo

Senior Landman

Greenlake Energy
Job TypeFull-time
 
Austin, TX
3 months ago
company-logo

Title Reviewer

Innovation Land Services
Job TypeFull-time
 
Pittsburgh, PA
5 months ago
company-logo

Electrical Designer

Dudley Staffing
Job TypeFull-time
Salary
$45 - $60
Canonsburg, PA
5 months ago
company-logo

Civil/Structural Designer

Dudley Staffing
Job TypeFull-time
Salary
$30 - $60
Canonsburg, PA
5 months ago
company-logo

Landman

Stockyards Energy Land Services
Job TypeContract
 
Akiachak, TX
6 months ago
company-logo

Oil and Gas Title Attorney

Oliva Gibbs PLLC
Job TypeFull-time
 
Houston, TX
about 2 months ago
company-logo

contract Landman

HPS Oil & Gas Properties
Job TypeFull-time
 
Midland, TX
4 months ago
company-logo

contract Landman

HPS Oil & Gas Properties
Job TypeFull-time
 
Cheyenne, WY
4 months ago
company-logo

Mechanical/Piping Engineer

Dudley Staffing
Job TypeFull-time
Salary
$55 - $75
Canonsburg, PA
5 months ago
company-logo

Senior Division Order Analyst

Formentera
Job TypeFull-time
Salary
$110000 - $130000
Austin, TX
about 1 year ago

Notice: The inclusion of job postings or company information on our platform does not imply endorsement, partnership, or affiliation. Listings may include publicly available roles from various sources, and companies shown may not have a direct relationship with Energy Hire.