Global Head of Cyber Security

Date: 17 Sept 2026

Location: US

Company: newcleo

The Global Head of Cyber Security is responsible for ensuring the protection and resilience of newcleo’s global technology estate, including IT, OT and critical digital assets (CDAs), across its operations in the US and Europe. The role owns the cyber security governance framework, maturity roadmap and enterprise cyber risk management required to safeguard operations, meet regulatory expectations and support business growth.

Reporting to the Head of IT RUN, the role leads the global Cyber Security function, including capability, budget and strategic suppliers, and coordinates cyber security activities across IT, Engineering and business functions. The role provides transparent reporting on cyber risk to the Head of IT RUN, with visibility to the Audit & Risk Committee, ensuring cyber risks are understood, prioritised and effectively managed across newcleo.

 

Main Activities

Cyber Security Governance & Framework:

  • Define and maintain newcleo’s cyber security governance framework, policies, standards and maturity roadmap.
  • Establish the enterprise security architecture and control framework aligned with nuclear-sector and international standards (e.g. ISO 27001, NIST CSF).
  • Define and oversee core security architecture domains, including identity and access management (IAM), zero trust principles and cloud security, ensuring consistent controls across on-premise, cloud and OT environments.
  • Ensure new technology, systems and digital capabilities are delivered secure by design, with security requirements embedded from project inception.
  • Define cyber security priorities and investment requirements to support risk reduction, regulatory compliance and business growth.

 Leadership & Team Management:

  • Lead and develop the global Cyber Security function, including local security leads across key locations.
  • Build capability through coaching, mentoring and succession planning.
  • Manage cyber security resources, budget and strategic supplier relationships.

 Security Operations & Incident Response:

  • Oversee global cyber defence capabilities, including threat monitoring, vulnerability management, penetration testing and incident response.
  • Lead cyber incident management, crisis response and remediation activities, coordinating with newcleo's wider business continuity and disaster recovery framework.
  • Ensure appropriate security controls and monitoring across IT, OT and critical digital assets.
  • Embed cyber security into operational processes and technology services.

 

Nuclear & Regulatory Compliance:

  • Maintain alignment with relevant regulations and standards, including the US Nuclear Regulatory Commission (NRC) cyber security requirements (10 CFR 73.54), French ANSSI requirements, NIS2, GDPR and IAEA nuclear security guidance.
  • Support regulatory engagement and represent newcleo in cyber security audits, inspections and certifications.
  • Ensure cyber security practices support nuclear safety, security and operational requirements across critical digital assets and OT environments.

 Risk Management & Assurance:

  • Maintain the enterprise cyber risk profile, escalating material risks, incidents and trends through appropriate governance channels.
  • Provide objective challenge and assurance over the effectiveness of cyber security controls across IT, Engineering and business functions.
  • Support third-party and supply chain cyber risk management, particularly for critical nuclear suppliers and partners.

 Culture, Awareness & Training:

  • Build a strong cyber security culture through awareness, training and targeted communications.
  • Establish role-based cyber training for higher-risk functions, including Engineering, OT and Finance.

Experience

 

  • Proven experience as a CISO / Head of Cyber Security in a global, multi-site organisation — ideally within nuclear, energy, or another critical infrastructure or highly regulated sector.
  • Deep expertise across IT, OT/industrial control system (ICS/SCADA) security and critical digital assets (CDAs), ideally within a nuclear or similarly regulated environment.
  • Strong track record engaging Boards, Audit & Risk Committees and regulators on cyber risk.
  • Working knowledge of nuclear-sector regulatory frameworks and international standards (ISO 27001, NIST CSF).
  • Experience leading incident response and crisis management at enterprise scale.
  • Relevant professional certification (e.g. CISSP, CISM, CRISC) desirable.

 

Language Proficiency: 

 

  • Strong written and verbal communication skills in English (CEFR C1+)
  • French or Italian is a plus.

What we offer

  • Hybrid/Remote working. Availability to travel to the office.
  • Salary range: $190K–$240K, commesurate with experience.
  • Comprehensive benefits package, including medical, dental, and vision coverage for employees and dependents, as well as a 401(k) plan with 4% company match.
  • Generous paid time off, starting at 20 days per year and increasing to 25 days after 3 years of service.
  • A mission-driven environment focused on delivering scalable, low-carbon energy solutions to meet growing global energy demand.
  • A collaborative and international culture that values technical excellence, transparency, innovation, and cross-functional teamwork.