Director of Cybersecurity
WSP · Las Vegas, Nevada, United States · $220K–$275K/yr
Professional Services · 10,001+ employees
About the role
The Director of Cybersecurity will lead the planning, design, and implementation of cybersecurity programs across major infrastructure and public sector projects. This role involves serving as a technical advisor to project teams and clients while ensuring security requirements are met throughout the project lifecycle.
What they look for
Requirements
Candidates must have at least 12 years of cybersecurity experience, including 5 years in a leadership or consulting capacity. A bachelor's degree in a related field is required, and professional certifications such as CISSP or CISM are highly desirable.
Benefits
Full description
This Opportunity
We are seeking an experienced Director of Cybersecurity to lead the planning, design, implementation, and assurance of cybersecurity programs across major infrastructure, transportation, energy, utilities, aviation, and public sector projects. This is a hand on/seller-doer role. Unlike traditional corporate IT security roles, this position is embedded directly within project delivery teams, partnering with clients, engineers, program managers, technology specialists, and executive stakeholders to ensure cybersecurity requirements are designed, implemented, validated, and maintained throughout the project lifecycle.
The successful candidate will serve as a technical leader, trusted advisor, and project delivery professional, providing cybersecurity expertise for digital transformation initiatives, operational technology (OT) environments, cloud implementations, Project Management Information Systems (PMIS), critical infrastructure programs, and enterprise technology deployments.
This role combines technical cybersecurity expertise, client engagement, project management, regulatory compliance, risk management, and strategic advisory services.
Your Impact
Project Cybersecurity Leadership
- Lead cybersecurity planning and execution for major infrastructure, transportation, utility, energy, aviation, water, and public sector programs.
- Develop project-specific cybersecurity strategies, architectures, roadmaps, and implementation plans.
- Integrate cybersecurity requirements into project delivery processes, procurement packages, technical specifications, and solution designs.
- Collaborate with multidisciplinary engineering, program management, and technology delivery teams.
- Serve as the primary cybersecurity advisor for project executives, program managers, and client stakeholders.
- Support project pursuits, proposals, presentations, and client interviews.
Security Governance, Risk, and Compliance
- Conduct cybersecurity risk assessments and maturity evaluations.
- Develop and maintain security policies, standards, procedures, and governance frameworks.
- Lead compliance initiatives supporting federal, state, and industry requirements.
- Perform gap assessments and remediation planning against established cybersecurity frameworks.
- Support audits and independent security assessments.
- Develop Plans of Action and Milestones (POA&M) and track remediation activities.
Security Architecture and Technical Assurance
- Review and approve cybersecurity architecture for cloud, enterprise, operational technology, and PMIS environments.
- Evaluate technology platforms, integrations, and vendor solutions from a cybersecurity perspective.
- Define identity management, access control, network segmentation, encryption, monitoring, and incident response requirements.
- Support secure system design reviews and cybersecurity validation activities.
- Guide implementation of security controls across project technology ecosystems.
Critical Infrastructure and Operational Technology Security
- Support cybersecurity initiatives involving:
- Industrial Control Systems (ICS)
- SCADA environments
- Operational Technology (OT)
- Intelligent Transportation Systems (ITS)
- Connected and Autonomous Vehicle infrastructure
- Utility control systems
- Airport and transit technologies
- Lead cybersecurity assessments of critical infrastructure environments.
- Develop security strategies that balance operational reliability and cyber resilience.
Incident Response and Security Resilience
- Develop and maintain incident response plans and recovery procedures.
- Support cybersecurity incident investigations and response activities.
- Conduct tabletop exercises, simulations, and security preparedness reviews.
- Develop business continuity and disaster recovery recommendations.
Business Development and Client Engagement
- Identify cybersecurity opportunities across infrastructure markets.
- Support strategic pursuits and proposal development activities.
- Participate in conference presentations, thought leadership initiatives, and client workshops.
- Build trusted relationships with executive leadership and client stakeholders.
Team Leadership
- Mentor cybersecurity professionals, project managers, and technical staff.
- Support recruiting, workforce development, and technical training initiatives.
- Foster a culture of cybersecurity awareness and continuous improvement.
- Provide technical quality reviews and subject matter expertise across project portfolios.
Who You Are
Minimum Requirements:
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, Information Systems, or related discipline, or equivalent. Master's degree preferred.
- 12+ years of cybersecurity experience.
- 5+ years leading cybersecurity programs, projects, or consulting engagements.
- Demonstrated experience supporting infrastructure, transportation, aviation, utility, energy, water, or government projects.
- Experience serving in client-facing consulting or advisory roles.
- Proven ability to lead multidisciplinary project teams.
Technical Expertise:
- Experience with several of the following:
- FISMA
- NIST Cybersecurity Framework (CSF)
- NIST 800-53
- NIST 800-171
- FedRAMP
- ISO 27001
- CIS Critical Security Controls
- NERC-CIP
- PCI-DSS
- HIPAA/HITRUST
- Zero Trust Architecture
- Cloud Security (Azure, AWS, Google Cloud)
- OT/ICS Security
- Vulnerability Management
- Security Operations and Monitoring
- Identity and Access Management
- Security Architecture Reviews
- Risk Management and Compliance Programs
Preferred Experience:
Candidates with experience supporting one or more of the following will be strongly preferred:
- Utility transmission and distribution programs
- Energy generation facilities
- Airport technology systems
- Rail and transit programs
- Intelligent transportation systems
- Major capital project delivery organizations
- PMIS and construction technology platforms
- Smart infrastructure and connected mobility initiatives
- Cloud-hosted enterprise applications supporting public agencies
Certifications:
One or more of the following certifications is highly desirable:
- CISSP
- CISM
- CGRC (formerly CAP)
- CCSP
- CRISC
- GIAC Certifications
- Security+
- ISO 27001 Lead Auditor
- Certified Ethical Hacker (CEH)
Why Join Us?
You will help secure some of the nation's most important infrastructure programs while working directly with project delivery teams, owners, engineers, and technology professionals. This role offers the opportunity to influence large-scale digital transformation initiatives, critical infrastructure modernization efforts, and emerging smart infrastructure programs while shaping cybersecurity strategy from project conception through operation.
WSP Benefits:
WSP provides a comprehensive suite of benefits focused on a providing health and financial stability throughout the employee’s career. These benefits include coverage related to medical, dental, vision, disability, and life; retirement savings; paid sick leave; paid vacation (or other personal time); paid parental leave; and paid time off for purposes of bereavement, voting, and/or attendance at naturalization proceedings.
Compensation:
Expected Salary (all locations): $220,000-275,000/year
WSP USA is providing the compensation range that the company in good faith believes it might pay and offer for this position, based on the successful applicant’s education, experience, knowledge, skills, abilities in addition to internal equity and specific geographic location. WSP USA reserves the right to ultimately pay more or less than the posted range and offer additional benefits and other compensation, depending on circumstances not related to an applicant’s sex or other status protected by local, state, and/or federal law.
Expected Salary (Colorado only): $220,000-275,000/year
WSP USA is providing the compensation range that the company in good faith believes it might pay and/or offer for this position within the state of Colorado, based on the successful applicant’s education, experience, knowledge, skills, and abilities in addition to internal equity and specific geographic location. WSP USA reserves the right to ultimately pay more or less than the posted range and offer additional benefits and other compensation, depending on circumstances not related to an applicant’s sex or other status protected by local, state, and/or federal law.
#LI-MP1
About WSP WSP USA is the U.S. operating company of WSP, one of the world's leading engineering and professional services firms. Dedicated to serving local communities, we are engineers, planners, technical experts, strategic advisors and construction management professionals. WSP USA designs lasting solutions in the buildings, transportation, energy, water and environment markets. With more than 15,000 employees in over 300 offices across the U.S., we partner with our clients to help communities prosper.
www.wsp.com
WSP provides a flexible and agile workplace model while meeting client needs. Employees are also afforded a comprehensive suite of benefits including medical, dental, vision, disability, life, and retirement savings focused on providing health and financial stability throughout the employee’s career.
At WSP, we want to give our employees the challenges they seek to grow their careers and knowledge base. Your daily contributions to your team will be essential in meeting client objectives, goals and challenges. Are you ready to get started?
WSP USA (and all of its U.S. companies) is an Equal Opportunity Employer Race/Age/Color/Religion/Sex/Sexual Orientation/Gender Identity/National Origin/Disability or Protected Veteran Status.
The selected candidate must be authorized to work in the United States.
NOTICE TO THIRD PARTY AGENCIES:
WSP does not accept unsolicited resumes from recruiters, employment agencies, or other staffing services. Unsolicited resumes include any resume or hiring document sent to WSP in the absence of a signed Service Agreement where WSP has expressly requested recruitment/staffing services specific to the position at hand. Any unsolicited resumes, including those submitted to hiring managers or other business leaders, will become the property of WSP and WSP will have the right to hire that candidate without reservation – no fee or other compensation will be owed or paid to the recruiter, employment agency, or other staffing service.