This Opportunity
We are seeking an experienced Director of Cybersecurity to lead the planning, design, implementation, and assurance of cybersecurity programs across major infrastructure, transportation, energy, utilities, aviation, and public sector projects. This is a hand on/seller-doer role. Unlike traditional corporate IT security roles, this position is embedded directly within project delivery teams, partnering with clients, engineers, program managers, technology specialists, and executive stakeholders to ensure cybersecurity requirements are designed, implemented, validated, and maintained throughout the project lifecycle.
The successful candidate will serve as a technical leader, trusted advisor, and project delivery professional, providing cybersecurity expertise for digital transformation initiatives, operational technology (OT) environments, cloud implementations, Project Management Information Systems (PMIS), critical infrastructure programs, and enterprise technology deployments.
This role combines technical cybersecurity expertise, client engagement, project management, regulatory compliance, risk management, and strategic advisory services.
Your Impact
Project Cybersecurity Leadership
Lead cybersecurity planning and execution for major infrastructure, transportation, utility, energy, aviation, water, and public sector programs.
Develop project-specific cybersecurity strategies, architectures, roadmaps, and implementation plans.
Integrate cybersecurity requirements into project delivery processes, procurement packages, technical specifications, and solution designs.
Collaborate with multidisciplinary engineering, program management, and technology delivery teams.
Serve as the primary cybersecurity advisor for project executives, program managers, and client stakeholders.
Support project pursuits, proposals, presentations, and client interviews.
Security Governance, Risk, and Compliance
Conduct cybersecurity risk assessments and maturity evaluations.
Develop and maintain security policies, standards, procedures, and governance frameworks.
Lead compliance initiatives supporting federal, state, and industry requirements.
Perform gap assessments and remediation planning against established cybersecurity frameworks.
Support audits and independent security assessments.
Develop Plans of Action and Milestones (POA&M) and track remediation activities.
Security Architecture and Technical Assurance
Review and approve cybersecurity architecture for cloud, enterprise, operational technology, and PMIS environments.
Evaluate technology platforms, integrations, and vendor solutions from a cybersecurity perspective.
Define identity management, access control, network segmentation, encryption, monitoring, and incident response requirements.
Support secure system design reviews and cybersecurity validation activities.
Guide implementation of security controls across project technology ecosystems.
Critical Infrastructure and Operational Technology Security
Support cybersecurity initiatives involving:
Industrial Control Systems (ICS)
SCADA environments
Operational Technology (OT)
Intelligent Transportation Systems (ITS)
Connected and Autonomous Vehicle infrastructure
Utility control systems
Airport and transit technologies
Lead cybersecurity assessments of critical infrastructure environments.
Develop security strategies that balance operational reliability and cyber resilience.
Incident Response and Security Resilience
Develop and maintain incident response plans and recovery procedures.
Support cybersecurity incident investigations and response activities.
Conduct tabletop exercises, simulations, and security preparedness reviews.
Develop business continuity and disaster recovery recommendations.
Business Development and Client Engagement
Identify cybersecurity opportunities across infrastructure markets.
Support strategic pursuits and proposal development activities.
Participate in conference presentations, thought leadership initiatives, and client workshops.
Build trusted relationships with executive leadership and client stakeholders.
Team Leadership
Mentor cybersecurity professionals, project managers, and technical staff.
Support recruiting, workforce development, and technical training initiatives.
Foster a culture of cybersecurity awareness and continuous improvement.
Provide technical quality reviews and subject matter expertise across project portfolios.
Who You Are
Minimum Requirements:
Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, Information Systems, or related discipline, or equivalent. Master's degree preferred.
12+ years of cybersecurity experience.
5+ years leading cybersecurity programs, projects, or consulting engagements.
Demonstrated experience supporting infrastructure, transportation, aviation, utility, energy, water, or government projects.
Experience serving in client-facing consulting or advisory roles.
Proven ability to lead multidisciplinary project teams.
Technical Expertise:
Experience with several of the following:
FISMA
NIST Cybersecurity Framework (CSF)
NIST 800-53
NIST 800-171
FedRAMP
ISO 27001
CIS Critical Security Controls
NERC-CIP
PCI-DSS
HIPAA/HITRUST
Zero Trust Architecture
Cloud Security (Azure, AWS, Google Cloud)
OT/ICS Security
Vulnerability Management
Security Operations and Monitoring
Identity and Access Management
Security Architecture Reviews
Risk Management and Compliance Programs
Preferred Experience:
Candidates with experience supporting one or more of the following will be strongly preferred:
Utility transmission and distribution programs
Energy generation facilities
Airport technology systems
Rail and transit programs
Intelligent transportation systems
Major capital project delivery organizations
PMIS and construction technology platforms
Smart infrastructure and connected mobility initiatives
Cloud-hosted enterprise applications supporting public agencies
Certifications:
One or more of the following certifications is highly desirable:
CISSP
CISM
CGRC (formerly CAP)
CCSP
CRISC
GIAC Certifications
Security+
ISO 27001 Lead Auditor
Certified Ethical Hacker (CEH)
Why Join Us?
You will help secure some of the nation's most important infrastructure programs while working directly with project delivery teams, owners, engineers, and technology professionals. This role offers the opportunity to influence large-scale digital transformation initiatives, critical infrastructure modernization efforts, and emerging smart infrastructure programs while shaping cybersecurity strategy from project conception through operation.
WSP Benefits:
WSP provides a comprehensive suite of benefits focused on a providing health and financial stability throughout the employee’s career. These benefits include coverage related to medical, dental, vision, disability, and life; retirement savings; paid sick leave; paid vacation (or other personal time); paid parental leave; and paid time off for purposes of bereavement, voting, and/or attendance at naturalization proceedings.
Compensation:
Expected Salary (all locations): $220,000-275,000/year
WSP USA is providing the compensation range that the company in good faith believes it might pay and offer for this position, based on the successful applicant’s education, experience, knowledge, skills, abilities in addition to internal equity and specific geographic location. WSP USA reserves the right to ultimately pay more or less than the posted range and offer additional benefits and other compensation, depending on circumstances not related to an applicant’s sex or other status protected by local, state, and/or federal law.
Expected Salary (Colorado only): $220,000-275,000/year
WSP USA is providing the compensation range that the company in good faith believes it might pay and/or offer for this position within the state of Colorado, based on the successful applicant’s education, experience, knowledge, skills, and abilities in addition to internal equity and specific geographic location. WSP USA reserves the right to ultimately pay more or less than the posted range and offer additional benefits and other compensation, depending on circumstances not related to an applicant’s sex or other status protected by local, state, and/or federal law.
#LI-MP1
