Novaspect logo

Cybersecurity Lead

Novaspect

On-siteSchaumburg, ILsenior$125k–$145kPosted 2h ago

Job description

Novaspect, Inc., an Emerson Local Business Partner and leader in process automation systems and solutions, is seeking a Cybersecurity Lead (IT/OT) to join our Technology Team in Schaumburg, Illinois. This role will advance Novaspect’s cybersecurity program across enterprise IT and operational technology (OT) environments, setting strategy, managing risk, establishing security standards and architecture, and protecting our systems, data, operations, and customers while strengthening cyber resilience.

This is a hands-on senior cybersecurity role for an experienced professional who combines strong technical expertise with strategic thinking, business acumen, and sound risk-based decision-making. Working across IT, OT, Engineering, Operations, business teams, customers, and external security partners, this individual will evaluate risk, guide security decisions, represent Novaspect effectively in customer cybersecurity discussions, provide cybersecurity direction during significant incidents, and ensure security controls are effective, scalable, and aligned with business and operational needs.

Cybersecurity Lead, Essential Duties and Responsibilities

  • Set direction for Novaspect’s cybersecurity program across IT and OT environments, establishing priorities and maintaining a risk-based roadmap aligned with business needs, operational requirements, customer commitments, and evolving threats, while coordinating internal resources and external cybersecurity expertise to support execution of program priorities.

  • Establish and maintain cybersecurity policies, standards, architecture principles, technical requirements, and secure design practices across enterprise IT, OT, cloud, applications, data platforms, and integrations.

  • Assess cybersecurity risks and vulnerabilities, drive appropriate remediation and compensating controls, and coordinate exceptions, risk acceptance, and escalation, ensuring material risks have clear ownership, appropriate visibility, and a defined path for treatment or acceptance.

  • Evaluate cybersecurity implications and define security requirements for new technologies, software, AI-enabled solutions, infrastructure changes, integrations, customer connectivity, and other significant initiatives, ensuring material risks are identified and addressed early in the technology lifecycle.

  • Partner with IT, OT, Engineering, and Operations teams to strengthen industrial cybersecurity, including asset visibility, network segmentation and industrial DMZs, secure remote and vendor access, identity and privileged access, vulnerability management, patching and lifecycle management, monitoring, and compensating controls for legacy or constrained systems.

  • Establish and oversee Novaspect’s AI governance and security program in partnership with the AI Transformation Lead and business stakeholders, including policies, standards, risk assessments, control requirements, third-party AI risk, governance reviews, and alignment with relevant frameworks, standards, and regulatory requirements such as the NIST AI RMF and ISO/IEC 42001.

  • Provide cybersecurity direction for incident preparedness and response, coordinate cross-functional action during significant incidents, and strengthen response plans through exercises, lessons learned, and continuous improvement.

  • Partner with Technology and business stakeholders on business continuity, disaster recovery, and cyber resilience, ensuring critical technology dependencies, cyber incident scenarios, backup and recovery capabilities, and recovery requirements are appropriately addressed and tested.

  • Oversee cybersecurity assurance and third-party risk activities, including SOC 2, customer security assessments and discussions, audits, penetration testing, vendor risk reviews, and alignment with relevant frameworks and standards such as the NIST Cybersecurity Framework, NIST SP 800-82, and ISA/IEC 62443.

  • Oversee Novaspect’s cybersecurity awareness and education program, including phishing simulations, role-based training, targeted communications, and follow-up activities, using results and trends to strengthen employee behaviors and reduce human-related cybersecurity risk.

  • Monitor and communicate cybersecurity posture, material risks, incidents, remediation progress, and program maturity, providing clear metrics, risk-based recommendations, and decision support to Technology leadership.

  • Provide technical guidance and coaching to Technology Team members and other stakeholders, strengthening cybersecurity capability and accountability across the organization.

Cybersecurity Lead, Required Qualifications

  • Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related field, or equivalent combination of education and relevant professional experience.

  • Eight or more years of progressive cybersecurity experience across security engineering, architecture, operations, risk management, incident response, or related disciplines.

  • Demonstrated experience leading significant cybersecurity initiatives, governance programs, technical workstreams, or security domains, with a track record of driving results across multiple teams.

  • Experience managing and coordinating work performed by managed security providers, cybersecurity consultants, or other external security specialists.

  • Demonstrated cybersecurity experience supporting OT/ICS environments, such as manufacturing, industrial automation, process control, critical infrastructure, or similarly complex operational environments.

  • Strong understanding of enterprise and industrial cybersecurity, including network segmentation, firewalls, secure remote access, identity and privileged access, endpoint security, vulnerability management, security monitoring, cloud security, and cyber recovery.

  • Experience applying recognized cybersecurity frameworks and industry practices such as the NIST Cybersecurity Framework, NIST SP 800-82, CIS Controls, ISA/IEC 62443, or comparable frameworks.

  • Experience developing or applying cybersecurity policies, standards, architecture requirements, and secure design principles across complex technology environments.

  • Experience assessing cybersecurity risk and translating technical findings into practical recommendations, remediation plans, compensating controls, and risk decisions.

  • Experience participating in and coordinating cybersecurity incident investigation, containment, remediation, and recovery, as well as supporting security assessments, audits, customer security reviews, or similar assurance activities.

  • Strong communication, leadership, and influencing skills, with demonstrated experience effectively engaging executives, technical teams, business stakeholders, customers, vendors, auditors, and external security partners on cybersecurity risks, requirements, and recommendations.

Cybersecurity Lead, Preferred Qualifications

  • Significant experience securing OT, ICS, SCADA, distributed control systems, manufacturing, process automation, or other industrial environments.

  • Experience with industrial cybersecurity architecture, OT asset discovery or monitoring, segmentation, industrial DMZs, secure remote access, and compensating controls for legacy systems.

  • Experience with AI governance, AI risk management, responsible AI practices, the NIST AI RMF, or management systems such as ISO/IEC 42001.

  • Experience supporting SOC 2, customer cybersecurity assessments, penetration testing, or third-party cybersecurity risk management.

  • Experience with Microsoft security technologies such as Microsoft Defender, Entra ID, Microsoft 365, Azure security capabilities, or comparable enterprise security platforms.

  • Experience working with industrial vendors, OEMs, systems integrators, or customer-managed environments.

  • Experience leading significant cybersecurity incident response, business continuity, disaster recovery, or cyber resilience exercises.

  • Relevant certifications such as CISSP, GICSP, CISM, CCSP, GIAC, or ISA/IEC 62443 certifications are helpful but not required.

Cybersecurity Lead, Physical Requirements

  • Ability to work extended periods on a computer.

  • Ability to travel periodically to Novaspect, customer, or operational locations as required.

Cybersecurity Lead, Pay:

  • Base Range: $125,000 - $145,000

  • Bonus Potential: 5%

The final offer will be based on several factors, including, but not limited to the candidate's depth of experience, skill set, qualifications, and internal pay equity. Hiring at the top end of the range would not be typical, to allow for future meaningful salary growth in the position.

Cybersecurity Lead, Benefits:

Recognized with a Top Employee Benefit Plan Award, below you will find our outstanding total rewards package when you join our team including:

  • Generous paid time off; starting at 15 vacation days, 10 holidays, and 10 days of Personal, Sick, & Safety Time (PSST)

  • 401K with 6% company match

  • Employee Stock Ownership Plan (ESOP)

  • Excellent health & wellness benefits

  • Student debt & tuition reimbursement

  • Referral bonus

Who We Are:

Novaspect, Inc., is an employee-owned company that engineers, sells, and services industrial process controls. Our Core Purpose is to improve our customer’s performance through the innovative application of technology. We are passionate about creating effective processes and building customer relationships. We position ourselves to attract the best talent, and ensure we are delivering local services with proven technologies.