The Role
Leads Caturus Energy’s cybersecurity program across corporate IT and operational technology environments, including SCADA, ICS, LNG, and field systems. Responsibilities include security operations, vulnerability management, incident response, network segmentation, third-party testing, risk governance, compliance, ITGCs, executive reporting, AI security, vendor oversight, budgeting, and team development. The role requires ensuring security controls protect critical infrastructure without compromising process, personnel, or operational safety.
Summary Generated by Built In
About Us:
The Caturus platform founded by Kimmeridge – an alternative asset manager focused on the energy sector – supports Kimmeridge’s overarching goal of providing low-cost energy on demand with the lowest carbon footprint.
Kimmeridge’s vision in creating Caturus is to build the only independent, fully integrated natural gas and LNG export platform in the U.S. through a combination of its upstream operations and via Commonwealth LNG, a 9.5 million tonnes per annum liquefied natural gas export terminal in southwestern Louisiana on the U.S. Gulf Coast. The combined entities are committed to delivering responsibly sourced, low-emission fuel to domestic and international markets.
Caturus is a Houston-based, private exploration and production company seeking to materially grow production through development of deep, high pressure, dry gas windows of the Eagle Ford and Austin Chalk, as well as Haynesville formations located in Texas and Louisiana while maintaining a relentless focus on safety.
Commonwealth LNG was founded by industry veterans who decided to re-engineer the LNG construction model. Using proven best practices, Commonwealth is committed to building a world-class LNG export facility while focusing on safety, managing risk and achieving best-in-class environmental standards.
The Caturus platform founded by Kimmeridge – an alternative asset manager focused on the energy sector – supports Kimmeridge’s overarching goal of providing low-cost energy on demand with the lowest carbon footprint.
Kimmeridge’s vision in creating Caturus is to build the only independent, fully integrated natural gas and LNG export platform in the U.S. through a combination of its upstream operations and via Commonwealth LNG, a 9.5 million tonnes per annum liquefied natural gas export terminal in southwestern Louisiana on the U.S. Gulf Coast. The combined entities are committed to delivering responsibly sourced, low-emission fuel to domestic and international markets.
Caturus is a Houston-based, private exploration and production company seeking to materially grow production through development of deep, high pressure, dry gas windows of the Eagle Ford and Austin Chalk, as well as Haynesville formations located in Texas and Louisiana while maintaining a relentless focus on safety.
Commonwealth LNG was founded by industry veterans who decided to re-engineer the LNG construction model. Using proven best practices, Commonwealth is committed to building a world-class LNG export facility while focusing on safety, managing risk and achieving best-in-class environmental standards.
Job Description
Position Summary:
The Director, Cybersecurity is responsible for leading Caturus Energy's unified security function across both Information Technology (IT) and Operational Technology (OT) environments. This role owns the full lifecycle of enterprise information security: analysis, operations, governance, and risk management, spanning corporate IT systems, upstream field/SCADA systems, midstream gathering infrastructure, and the Commonwealth LNG terminal's industrial control systems (ICS).
The Director, Cybersecurity is responsible for leading Caturus Energy's unified security function across both Information Technology (IT) and Operational Technology (OT) environments. This role owns the full lifecycle of enterprise information security: analysis, operations, governance, and risk management, spanning corporate IT systems, upstream field/SCADA systems, midstream gathering infrastructure, and the Commonwealth LNG terminal's industrial control systems (ICS).
The Director is accountable for a clear, high-bar outcome: no vulnerable systems left unmanaged. Every asset is inventoried, every known vulnerability is tracked to closure on a defined timeline, every critical system is independently tested by qualified third parties (including regular penetration testing) through to verified closure, and the company can demonstrate, on demand, to auditors, insurers, lenders, regulators, or the Board, exactly how its controls map to NIST and ISO frameworks and how IT General Controls (ITGCs) are operating.
Key Accountabilities:
Key Accountabilities:
- Own day-to-day security operations across corporate IT (endpoints, identity, cloud, applications) and OT/ICS environments (drilling rig systems, gathering system SCADA, LNG terminal control systems).
- Drive IT/OT network segmentation using zone-and-conduit architecture (ISA/IEC 62443) and defense-in-depth aligned to NIST SP 800-82 Rev. 3.
- Build and mature a security operations capability: monitoring, detection, incident response, and threat intelligence, with OT-specific playbooks that respect process safety and well-control constraints; no security action shall compromise safe operation of physical assets.
- Maintain a current, accurate asset inventory across IT and OT, including third-party/vendor-managed systems where Caturus has visibility or contractual security requirements.
- Govern vendor and integrator remote access to wellsite and pipeline equipment: least-privilege access, MFA, session monitoring, and time-bound access for contractors and OEMs.
- Coordinate with Drilling, Midstream, and Commonwealth LNG operations leadership so security operations are integrated into field workflows, aligned with API 1164 and, where relevant, integrated with process-safety (HAZOP) reviews.
- Operate a continuous vulnerability management program across IT and OT: discovery, scoring and prioritization, assigned ownership, and time-bound remediation SLAs by severity and asset criticality.
- Maintain a live vulnerability register with age, status, and owner for every open finding; report aging or overdue items to IT leadership on a defined cadence.
- Ensure OT vulnerability management accounts for patch windows, vendor certification requirements, legacy equipment limitations, and safety systems, with documented risk acceptance where immediate patching is not feasible.
- Deploy or manage OT-aware asset and network visibility tooling to support inventory and detection across the field environment.
- Establish and manage a program of third-party security assessments, including annual (minimum) penetration testing of critical IT and OT environments, periodic vulnerability assessments and configuration reviews, and red team or adversary simulation exercises as risk and maturity warrant.
- Track every finding from every third-party assessment through to verified closure, with re-testing or evidence-based validation required before any finding is marked closed.
- Vet and manage the roster of qualified third-party testing vendors; set scope, rules of engagement, and safety constraints for OT testing so that no testing activity risks physical safety or process integrity.
- Develop and maintain the enterprise information security risk register covering IT and OT risk, with likelihood/impact scoring, ownership, and treatment plans (mitigate, transfer, accept, avoid).
- Present risk posture and trends to IT leadership, executive leadership, and the Board or Audit Committee as needed.
- Own and mature the company's security governance framework: policies, standards, and procedures for both IT and OT.
- Track overall program maturity against a recognized model and report maturity progression to leadership over time.
- Establish security oversight for non-operated assets and joint ventures where Caturus holds an economic interest but not operational control, defining requirements through joint-operating and data-sharing agreements in partnership with Legal and Land/Business Development.
- Support cyber due diligence for M&A activity, including pre-close diligence, post-close integration or separation, and security provisions in transition services agreements.
- Partner with Legal, Internal Audit, and Corporate Affairs on regulatory and contractual security obligations, including CFIUS-related requirements. Maintain current, evidence-backed control mapping to NIST Cybersecurity Framework 2.0, NIST SP 800-53/800-82 Rev. 3, ISO/IEC 27001, and (where relevant to OT) ISO/IEC 27019 or IEC 62443.
- Maintain and report on IT General Controls (ITGCs) supporting financial reporting integrity, in coordination with Internal Audit and external auditors.
- Maintain awareness of, and readiness for, applicable energy-sector regulatory regimes in coordination with Legal, including TSA pipeline security directives, CIRCIA incident-reporting obligations, and conditional NERC CIP applicability.
- Produce, on demand, audit-ready evidence of control operation and compliance status for internal leadership, external auditors, lenders, insurers, or regulators. Lead or support external audits, insurance underwriting security assessments, and customer/partner due diligence security questionnaires.
- Own the Cybersecurity Incident Response Plan covering both IT and OT, and lead periodic executive tabletop exercises, including ransomware scenarios.
- Own secure adoption governance for AI/LLM tooling (e.g., Microsoft Copilot): permission-hygiene remediation, data-leakage prevention, shadow-AI monitoring, and an AI acceptable-use policy.
- Maintain controls against business email compromise and vendor-payment fraud, including out-of-band verification for banking and vendor-master-file changes.
- Build out the cybersecurity function's staffing model, including internal hires, managed security service providers, and OT security specialists, as the program matures.
- Manage relationships with security vendors, MSSPs, and the third-party testing ecosystem.
- Own the cybersecurity budget and multi-year roadmap in partnership with the Head of IT.
- Lead the security-awareness and phishing-simulation program, extending security culture into field operations.
Qualifications
Education, Certificates, and Licenses:
- Bachelor's degree in Information Technology, Computer Science, Information Systems, Engineering, or a related discipline required.
- Master's degree in Business Administration (MBA), Information Systems, or a related discipline preferred.
- Professional certifications such as CISSP, CISM, GICSP, GRID, GIAC ICS (ICS410/ICS515), or similar credentials preferred.
Experience:
- 10+ years of progressive information security experience, including at least 3-5 years in a leadership role spanning both IT and OT/ICS security.
- Experience in energy, midstream, LNG, or another critical-infrastructure sector strongly preferred.
- Demonstrated experience running vulnerability management and third-party penetration testing programs at scale, through to verified closure. Experience with OT/ICS security fundamentals (SCADA, DCS, safety instrumented systems) and the operational constraints of patching and testing production industrial environments.
- Experience building and presenting risk reporting to executive leadership and/or a Board or Audit Committee.
- Experience supporting regulatory compliance programs (TSA pipeline security directives, CIRCIA, NERC CIP as applicable) and IT General Controls audits preferred.
- Experience with non-operated joint ventures, third-party-operated facility risk, or cyber due diligence for M&A/A&D activity preferred.
Knowledge, Skills, and Abilities:
- Working command of NIST Cybersecurity Framework 2.0, NIST SP 800-53/800-82 Rev. 3, ISO/IEC 27001, IEC 62443 zone-and-conduit concepts, and IT General Controls; able to translate framework requirements into operational controls and audit evidence.
- Deep understanding of vulnerability management, penetration testing methodology, and third-party assurance practices.
- Working knowledge of industrial control systems (ICS), SCADA systems, operational technology, and associated cybersecurity considerations, including the operational and safety constraints distinct from corporate IT.
- Understanding of applicable energy-sector regulatory frameworks (TSA pipeline directives, CIRCIA, NERC CIP where applicable) sufficient to build and maintain compliance readiness.
- Ability to develop, quantify, and communicate enterprise risk in both technical and business terms to executive stakeholders.
- Strong cross-functional collaboration skills, particularly with Drilling, Midstream, LNG Operations, Legal, Internal Audit, and Finance.
- Exceptional leadership, organizational, communication, and relationship management skills.
- Ability to develop and execute strategic security plans while managing day-to-day operations and incident response.
- Demonstrated experience building, leading, and mentoring high-performing teams, including vendor and managed-service relationships.
- Excellent analytical, problem-solving, and decision-making capabilities.
- Commitment to safety, operational excellence, continuous improvement, and the secure operation of critical energy infrastructure; ability to ensure security controls never compromise well control, process safety, or personnel safety.
About
The Caturus platform founded by Kimmeridge – an alternative asset manager focused on the energy sector – supports Kimmeridge’s overarching goal of providing low-cost energy on demand with the lowest carbon footprint.Kimmeridge’s vision in creating Caturus is to build the only independent, fully integrated natural gas and LNG export platform in the U.S. through a combination of its upstream operations and via Commonwealth LNG, a 9.5 million tonnes per annum liquefied natural gas export terminal in southwestern Louisiana on the U.S. Gulf Coast. The combined entities are committed to delivering responsibly sourced, low-emission fuel to domestic and international markets.Caturus is a Houston-based, private exploration and production company seeking to materially grow production through development of deep, high pressure, dry gas windows of the Eagle Ford and Austin Chalk, as well as Haynesville formations located in Texas and Louisiana while maintaining a relentless focus on safety.Commonwealth LNG was founded by industry veterans who decided to re-engineer the LNG construction model. Using proven best practices, Commonwealth is committed to building a world-class LNG export facility while focusing on safety, managing risk and achieving best-in-class environmental standards.
Skills Required
- Bachelor’s degree in Information Technology, Computer Science, Information Systems, Engineering, or a related discipline
- 10+ years of progressive information security experience
- 3–5 years in a leadership role spanning IT and OT/ICS security
- Experience running vulnerability management and third-party penetration testing programs through verified closure
- Experience with OT/ICS security fundamentals, including SCADA, DCS, safety instrumented systems, and industrial environments
- Experience presenting cybersecurity risk reporting to executive leadership, a Board, or Audit Committee
- Strong understanding of vulnerability management, penetration testing, and third-party assurance
- Working command of NIST CSF 2.0, NIST SP 800-53, NIST SP 800-82 Rev. 3, ISO/IEC 27001, IEC 62443, and ITGCs
- Ability to develop and communicate enterprise risk in technical and business terms
- Experience building, leading, and mentoring cybersecurity teams and managing vendors or MSSPs
- Master’s degree in Business Administration, Information Systems, or a related discipline
- CISSP, CISM, GICSP, GRID, GIAC ICS, or similar certification
- Experience in energy, midstream, LNG, or critical infrastructure
- Experience with TSA pipeline directives, CIRCIA, NERC CIP, and ITGC audits
- Experience with non-operated joint ventures, third-party-operated facilities, or cyber due diligence for M&A
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Caturus is an integrated natural gas and LNG company based in Houston, Texas. It operates through a 'wellhead-to-water' strategy, combining upstream natural gas production in Texas with downstream LNG export capabilities via its Commonwealth LNG terminal in Louisiana. The company focuses on delivering responsibly sourced, low-emission energy to domestic and international markets, aiming to provide low-cost energy on demand with a minimal carbon footprint.








