Director, Cybersecurity
Listed on 2026-09-14
-
IT/Tech
Cybersecurity
Director, Cybersecurity
Department: Information Technology
Employment Type: Full Time
Location: US TX Houston - Corporate Office
DescriptionAbout Us: The Caturus platform founded by Kimmeridge – an alternative asset manager focused on the energy sector – supports Kimmeridge’s overarching goal of providing low-cost energy on demand with the lowest carbon footprint.
Kimmeridge’s vision in creating Caturus is to build the only independent, fully integrated natural gas and LNG export platform in the U.S. through a combination of its upstream operations and via Commonwealth LNG, a 9.5 million tonnes per annum liquefied natural gas export terminal in southwestern Louisiana on the U.S. Gulf Coast. The combined entities are committed to delivering responsibly sourced, low-emission fuel to domestic and international markets.
Caturus is a Houston-based, private exploration and production company seeking to materially grow production through development of deep, high pressure, dry gas windows of the Eagle Ford and Austin Chalk, as well as Haynesville formations located in Texas and Louisiana while maintaining a relentless focus on safety.
Commonwealth LNG was founded by industry veterans who decided to re‑engineer the LNG construction model. Using proven best practices, Commonwealth is committed to building a world‑class LNG export facility while focusing on safety, managing risk and achieving best‑in‑class environmental standards.
Job DescriptionPosition Summary: The Director, Cybersecurity is responsible for leading Caturus Energy's unified security function across both Information Technology (IT) and Operational Technology (OT) environments. This role owns the full lifecycle of enterprise information security: analysis, operations, governance, and risk management, spanning corporate IT systems, upstream field/SCADA systems, midstream gathering infrastructure, and the Commonwealth LNG terminal's industrial control systems (ICS).
The Director is accountable for a clear, high-bar outcome: no vulnerable systems left unmanaged. Every asset is inventoried, every known vulnerability is tracked to closure on a defined timeline, every critical system is independently tested by qualified third parties (including regular penetration testing) through to verified closure, and the company can demonstrate, on demand, to auditors, insurers, lenders, regulators, or the Board, exactly how its controls map to NIST and ISO frameworks and how IT General Controls (ITGCs) are operating.
Key Accountabilities:
- Own day-to-day security operations across corporate IT (endpoints, identity, cloud, applications) and OT/ICS environments (drilling rig systems, gathering system SCADA, LNG terminal control systems).
- Drive IT/OT network segmentation using zone-and-conduit architecture (ISA/IEC 62443) and defense-in-depth aligned to NIST SP 800-82 Rev. 3.
- Build and mature a security operations capability: monitoring, detection, incident response, and threat intelligence, with OT‑specific playbooks that respect process safety and well-control constraints; no security action shall compromise safe operation of physical assets.
- Maintain a current, accurate asset inventory across IT and OT, including third-party/vendor‑managed systems where Caturus has visibility or contractual security requirements.
- Govern vendor and integrator remote access to wellsite and pipeline equipment: least‑privilege access, MFA, session monitoring, and time‑bound access for contractors and OEMs.
- Coordinate with Drilling, Midstream, and Commonwealth LNG operations leadership so security operations are integrated into field workflows, aligned with API 1164 and, where relevant, integrated with process-safety (HAZOP) reviews.
- Operate a continuous vulnerability management…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).