Crescent Energy

Head of Cybersecurity & GRC

LocationHouston, TX
Job TypeFull-time

About This Job


Company Overview:

At Crescent, we are investors and operators delivering value to shareholders through a disciplined, returns-driven growth through acquisition strategy and consistent return of capital. Our long-life, balanced portfolio combines stable cash flows from low-decline production with deep, high-quality development inventory. Our activities are focused in Texas and the Rocky Mountain region.


Job Summary:

The Head of Cybersecurity & GRC is a senior leadership position responsible for safeguarding the organization’s digital assets, operational infrastructure, and sensitive data across IT and OT environments. This role leads the strategy, execution, and oversight of the cybersecurity program and enterprise risk management framework grounded in NIST CSF and aligned with upstream oil and gas business needs.

This leader will ensure that cybersecurity and compliance practices are embedded across the organization while enabling innovation and operational continuity. The ideal candidate brings a balance of technical expertise, strategic leadership, and deep upstream oil & gas experience, particularly with production, drilling, field operations, and industrial control systems (ICS/SCADA). This position will require continuous learning and on-going stewardship and prioritization of resources to effectively align safeguards over technology components relative to the anticipated threat landscape. This individual will play a critical role in accelerating our journey toward becoming a data-driven, technology-enabled enterprise, especially in the context of the energy sector's transformation.


Key Responsibilities:


Cybersecurity Strategy & Operations:

Develop and lead the enterprise cybersecurity strategy, with a strong foundation in the NIST Cybersecurity Framework (CSF).
Oversee security operations, incident response, vulnerability management, and threat intelligence for IT and OT environments.
Implement layered defense strategies, including network segmentation, endpoint protection, identity and access management (IAM), and security monitoring (SIEM/SOAR).
Governance, Risk & Compliance (GRC)
Design and operate an enterprise GRC program to manage cyber, regulatory, operational, and third-party risk.
Lead compliance with relevant standards and regulations (e.g., NIST, SOX, TSA Pipeline Security Directives, SEC cyber disclosure, FERC, PHMSA).
Oversee internal/external audits, risk assessments, insurance questionnaires, and policy development ensuring alignment with corporate and industry standards
OT Security & Upstream Operations
Collaborate with operations, engineering, and field teams to secure industrial control systems (ICS), SCADA, and edge devices across upstream assets.
Establish risk-based security controls for field operations without compromising uptime or performance.
Build and foster OT cybersecurity awareness and partnerships across HSE, Production, Drilling, and Asset teams.

Leadership & Stakeholder Engagement

Serve as a trusted advisor to executive leadership on cyber risk, digital trust, and security investments.

Develop and lead a high-performing cybersecurity and GRC team spanning security engineering, compliance, risk, and awareness functions.
Build relationships across IT, Legal, Operations, and External Affairs to embed cybersecurity into core business processes and programs.
Facilitate regular cybersecurity and risk reporting to the Board Audit Committee, translating technical risks into business impact and ensuring executive alignment on risk posture and mitigation strategies
Develop and foster external relationships with organizations and key contributors that support and may enhance the on-going cybersecurity posture and overall operational resilience (e.g. ONE-ISAC, DHS CISA, FBI, etc.)

Security Architecture & Technology Oversight

Oversee security architecture for cloud, on-prem, and hybrid environments ensuring secure adoption of platforms like Snowflake, Azure, and SaaS tools.

Evaluate and implement cybersecurity tools, technologies, and services to strengthen the enterprise security posture.
Lead security reviews of new projects, platforms, and partnerships (M&A, joint ventures, field digitization efforts).
Coordinate and review the risk profiles associated with technology vendors and service providers (third & fourth party).


Qualifications & Experience:


Education:

Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field is required. Master’s degree is a strong plus.
CISSP certification required. Additional certifications such as CISM, CRISC, CISA, or relevant GIAC; NIST CSF Implementation credentials are a strong plus.
Experience:

7+ years of cybersecurity and/or GRC leadership experience, with a minimum of 5 years in a senior role overseeing enterprise programs.
Deep understanding of upstream oil and gas operations, including field systems, SCADA, and industrial environments.
Demonstrated success building and running security programs based on the NIST Cybersecurity Framework.
Hands-on experience managing regulatory compliance and incident response in high-stakes operational settings

Skills & Competencies:

Strong knowledge of cyber risk management, threat modeling, incident handling, and security architecture.

Deep understanding of the intersection of IT and OT cybersecurity in energy and industrial sectors.
Proven ability to communicate risk to executive stakeholders, board members, and cross-functional leaders.
Strategic thinker with a pragmatic, business-aligned approach to cybersecurity and compliance.


Work Environment & Physical Requirements:

Primarily office-based with occasional travel to field offices and operational sites as needed.
Potential exposure to remote and high-risk environments, requiring adherence to safety protocols.
May involve walking, climbing, bending, or handling equipment during site visits.
Possible exposure to varying weather conditions (heat, cold, rain) while on-site at the field offices.
Availability for emergency response and incident management, including after-hours support when required.

Crescent Energy is an equal opportunity employer. All qualified applicants will be considered for employment without regard to race, color, religion, gender/pregnancy, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status or any other legally protected status. Crescent Energy is also committed to compliance with all fair employment practices regarding citizenship and immigration status. If you require accommodation to complete the application process, please let us know by contacting Kimberly Kalsey at Kimberly.Kalsey@crescentenergyco.com.

Similar Jobs

company-logo

Head of Cybersecurity & GRC

Crescent Energy
Job TypeFull-time
 
Houston, TX
5 days ago
company-logo

Senior Advisor, Cybersecurity

ATCO Electric
Job TypeFull-time
 
Calgary, AB
5 days ago
company-logo

Senior Advisor, Cybersecurity

ATCO
Job TypeFull-time
 
Calgary, AB
6 days ago
company-logo

Senior Manager, Cybersecurity

Pacific Gas and Electric Company
Job TypeFull-time
 
Oakland, CA
15 days ago
company-logo

Cybersecurity Analyst

Irvine Ranch Water District (IRWD)
Job TypeFull-time
 
Irvine, CA
14 days ago
company-logo

Cybersecurity Analyst

Irvine Ranch Water District (IRWD)
Job TypeFull-time
 
Irvine, CA
27 days ago
company-logo

Cybersecurity Analyst

Clearway Energy
Salary
$86000 - $95000
San Francisco, CA
about 1 month ago
company-logo

Principal Cybersecurity Analyst

NextEra Energy
Job TypeFull-time
 
Juno Beach, FL
9 days ago
company-logo

Principal Cybersecurity Analyst

Florida Power & Light
Job TypeFull-time
 
Juno Beach, FL
9 days ago
company-logo

Cyber & Information Security Specialist

Bruce Power
Job TypeFull-time
 
Tiverton, ON
12 days ago
company-logo

IT/OT Cybersecurity Advisor

ENGIE
Job TypeFull-time
 
Houston, TX
13 days ago
company-logo

Cyber Security Advisor

Harvest Midstream Company
Job TypeFull-time
 
Houston, TX
27 days ago
company-logo

Cybersecurity Manager

Standard Solar
Job TypeFull-time
 
Rockville, MD
about 1 month ago
company-logo

Security Specialist

South Bow
Job TypeFull-time
 
Houston, TX
6 days ago
company-logo

Cyber Security Administrator

Qcells
 
Cartersville, GA
6 days ago
company-logo

Manager of Cyber Security

Osmose Utilities Services, Inc.
Job TypeFull-time
 
Peachtree City, GA
23 days ago
company-logo

Cyber Security Senior Analyst

Pembina Pipeline Corporation
 
Calgary, AB
25 days ago
company-logo

OT Cybersecurity Manager

Florida Power & Light
Job TypeFull-time
 
Juno Beach, FL
26 days ago
company-logo

Cybersecurity Analyst (37.25)

Golden State Water Company
Job TypeFull-time
 
San Dimas, CA
27 days ago
company-logo

Cyber Security Administrator

Suffolk County Water Authority
Job TypeFull-time
Salary
$110000 - $120000
Oakdale, NY
about 1 month ago

Trending Jobs

company-logo

Nuclear Technical Intern - Mid Atlantic

Constellation
Job TypeInternship
 
Lusby, MD
26 days ago
company-logo

Apprentice Lineman

Brink Constructors, Inc.
Job TypeFull-time
 
Rapid City, SD
25 days ago
company-logo

Deckhand (Houston)

John W. Stone Oil Distributor, LLC
 
Houston, TX
26 days ago
company-logo

Electrical Engineer

Dudley Staffing
Job TypeFull-time
Salary
$55 - $75
Canonsburg, Pennsylvania
3 months ago
company-logo

Director, Financial Planning & Analysis - Energy (Enterprise)

Pilot Thomas Logistics
Job TypeFull-time
 
Grapevine, TX
26 days ago
company-logo

Apprentice Lineman I

San Patricio Electric Cooperative, Inc.
Job TypeFull-time
 
Sinton, TX
10 days ago
company-logo

Quality Engineer

Jedco Inc.
Job TypeFull-time
 
Grand Rapids, MI
20 days ago
company-logo

Solar Electrician

MN8 Energy
Job TypeFull-time
 
California, United States
24 days ago
company-logo

Sr. Polymer Scientist

ExxonMobil
Job TypeFull-time
 
Baytown, TX
24 days ago
company-logo

Gas Foreman

Peak Utility Services Group
Job TypeFull-time
 
Lawton, OK
25 days ago
company-logo

contract landman

HPS Oil & Gas Properties
Job TypeFull-time
 
Lafayette, Louisiana
about 2 months ago
company-logo

Apprentice Power Lineman

Proline Power Corp.
Job TypeFull-time, Apprenticeship
 
Red Deer, AB
30 days ago
SD

Service Manager

Supertech Diesel Truck Specialists
Job TypeFull-time
 
Langley, BC
23 days ago
company-logo

Finishing Helper Entry Level- Dayshift

Bonnell Aluminum
Salary
$41600 - $41600
Carthage, TN
20 days ago
company-logo

Oil and Gas Land and Title Analyst - SAM Associate II

Bank of America
Job TypeFull-time
 
Dallas, Texas
19 days ago
company-logo

Meter Technician

ONEOK
Job TypeFull-time
 
Odessa, TX
26 days ago
company-logo

Senior Landman

Greenlake Energy
Job TypeFull-time
 
Austin, Texas
17 days ago
SD

Service Manager

Supertech Diesel Truck Specialists
Job TypeFull-time
 
Nanaimo, BC
23 days ago
company-logo

Assembler/Production

Uptalent
Job TypeContract
Salary
$37440 - $49920
Oklahoma City, OK
19 days ago
company-logo

Senior Investigator

Dominion Energy
Job TypeFull-time
 
Norfolk, VA
26 days ago