Global Head of Cyber Security

Date: 19 Aug 2026

Location: US

Company: newcleo

The Global Head of Cyber Security is responsible for ensuring the protection and resilience of newcleo’s global technology estate, including IT, OT and critical digital assets (CDAs), across its operations in the US and Europe. The role owns the cyber security governance framework, maturity roadmap and enterprise cyber risk management required to safeguard operations, meet regulatory expectations and support business growth.

Reporting to the Head of IT RUN, the role leads the global Cyber Security function, including capability, budget and strategic suppliers, and coordinates cyber security activities across IT, Engineering and business functions. The role provides transparent reporting on cyber risk to the Head of IT RUN, with visibility to the Audit & Risk Committee, ensuring cyber risks are understood, prioritised and effectively managed across newcleo.

 

Main Activities

Cyber Security Governance & Framework:

  • Define and maintain newcleo’s cyber security governance framework, policies, standards and maturity roadmap.
  • Establish the enterprise security architecture and control framework aligned with nuclear-sector and international standards (e.g. ISO 27001, NIST CSF).
  • Define and oversee core security architecture domains, including identity and access management (IAM), zero trust principles and cloud security, ensuring consistent controls across on-premise, cloud and OT environments.
  • Ensure new technology, systems and digital capabilities are delivered secure by design, with security requirements embedded from project inception.
  • Define cyber security priorities and investment requirements to support risk reduction, regulatory compliance and business growth.

 Leadership & Team Management:

  • Lead and develop the global Cyber Security function, including local security leads across key locations.
  • Build capability through coaching, mentoring and succession planning.
  • Manage cyber security resources, budget and strategic supplier relationships.

 Security Operations & Incident Response:

  • Oversee global cyber defence capabilities, including threat monitoring, vulnerability management, penetration testing and incident response.
  • Lead cyber incident management, crisis response and remediation activities, coordinating with newcleo's wider business continuity and disaster recovery framework.
  • Ensure appropriate security controls and monitoring across IT, OT and critical digital assets.
  • Embed cyber security into operational processes and technology services.

 

Nuclear & Regulatory Compliance:

  • Maintain alignment with relevant regulations and standards, including the US Nuclear Regulatory Commission (NRC) cyber security requirements (10 CFR 73.54), French ANSSI requirements, NIS2, GDPR and IAEA nuclear security guidance.
  • Support regulatory engagement and represent newcleo in cyber security audits, inspections and certifications.
  • Ensure cyber security practices support nuclear safety, security and operational requirements across critical digital assets and OT environments.

 Risk Management & Assurance:

  • Maintain the enterprise cyber risk profile, escalating material risks, incidents and trends through appropriate governance channels.
  • Provide objective challenge and assurance over the effectiveness of cyber security controls across IT, Engineering and business functions.
  • Support third-party and supply chain cyber risk management, particularly for critical nuclear suppliers and partners.

 Culture, Awareness & Training:

  • Build a strong cyber security culture through awareness, training and targeted communications.
  • Establish role-based cyber training for higher-risk functions, including Engineering, OT and Finance.

Experience

 

  • Proven experience as a CISO / Head of Cyber Security in a global, multi-site organisation — ideally within nuclear, energy, or another critical infrastructure or highly regulated sector.
  • Deep expertise across IT, OT/industrial control system (ICS/SCADA) security and critical digital assets (CDAs), ideally within a nuclear or similarly regulated environment.
  • Strong track record engaging Boards, Audit & Risk Committees and regulators on cyber risk.
  • Working knowledge of nuclear-sector regulatory frameworks and international standards (ISO 27001, NIST CSF).
  • Experience leading incident response and crisis management at enterprise scale.
  • Relevant professional certification (e.g. CISSP, CISM, CRISC) desirable.

 

Language Proficiency: 

 

  • Strong written and verbal communication skills in English (CEFR C1+)
  • French or Italian is a plus.