Our present and future success depends on the creative and dedicated people of our company who demonstrate the principles outlined in the APS Promise: Design for Tomorrow, Empower Each Other and Succeed Together.
Cybersecurity at APS is more than protecting systems. It's about protecting the people and communities who count on us to keep the lights on. We're looking for a senior cybersecurity leader to step into our CISO (Chief Information Security Officer) role and shape how we defend the company, our customers, and the operations behind one of Arizona's most essential services.
The role
You'll set the long-term strategy for cybersecurity and compliance across APS, with accountability for the security of our IT and operational technology, the privacy of customer and employee information, and our standing under SOX, NERC CIP, Export Control, and related regulations. You'll be our company's primary cybersecurity advisor to senior leadership and the Board of Directors, translating risk into the business and financial terms that drive real decisions.
Day to day, you'll lead the enterprise cybersecurity program, security governance, incident response, and the work that keeps our compliance posture strong. You'll partner closely with business units and emergency management to support APS's resiliency goals, oversee internal audits, and represent APS in industry forums and with law enforcement and government partners. You'll also lead and develop the team that makes all this possible.
What we're looking for
Preferred Skills & Experiences
This position may require access to and/or use of information subject to control under the Department of Energy's Part 810 Regulations (10 CFR Part 810), the Export Administration Regulations (EAR) (15 CFR Parts 730 through 774), or the International Traffic in Arms Regulations (ITAR) (22 CFR Chapter I, Subchapter M Part 120) (collectively, 'U.S. Export Control Laws'). Therefore, some positions may require applicants to be a U.S. person, which is defined as a U.S. Citizen, a U.S. Lawful Permanent Resident (i.e. 'Green Card Holder'), a Political Asylee, or a Refugee under the U.S. Export Control Laws. All applicants will be required to confirm their U.S. person or non-US person status. All information collected in this regard will only be used to ensure compliance with U.S. Export Control Laws, and will be used in full compliance with all applicable laws prohibiting discrimination on the basis of national origin and other factors. For positions at Palo Verde Nuclear Generating Stations (PVNGS) all openings will require applicants to be a U.S. person.
Pinnacle West Capital Corporation and its subsidiaries and affiliates ('Pinnacle West') maintain a continuing policy of nondiscrimination in employment. It is our policy to provide equal opportunity in all phases of the employment process and in compliance with applicable federal, state, and local laws and regulations. This policy of nondiscrimination shall include, but not be limited to, recruiting, hiring, promoting, compensating, reassigning, demoting, transferring, laying off, recalling, terminating employment, and training for all positions without regard to race, color, religion, disability, age, national origin, gender, gender identity, sexual orientation, marital status, protected veteran status, or any other classification or characteristic protected by law.
For more information on applicable equal employment regulations, please refer to EEO is the Law poster. Federal law requires all employers to verify the identity and employment eligibility of every person hired to work in the United States, refer to E-Verify poster. View the employee rights and responsibilities under the Family and Medical Leave Act (FMLA).
In compliance with the Drug Free Workplace Act of 1988, the Company is committed to a work environment that is free from the effects of alcohol and controlled substances, and free from the abuse or inappropriate use of prescribed and over-the-counter medications. The Company requires employees to be subject to drug and alcohol testing that is job-related and consistent with business necessity, regulatory requirements and applicable laws.
CIP Requirement:
This position requires Critical Infrastructure Protection (CIP) access consistent with North American Electric Reliability Corporation (NERC) standards. The applicant considered for this role will be required to obtain and maintain CIP access for the duration of employment in this position. A full seven (7) year criminal history will be obtained through the pre-employment background check process (or, for current employees, through supplemental background check process) to fulfill the CIP access requirements. In addition, this position requires an additional background check every seven years to maintain access.
Hybrid: Employees in hybrid roles work both in their home offices (virtually) and alongside their colleagues (in person).
In order for employees to build strong relationships and to promote meaningful in-person interactions, hybrid employees are expected to work about 40% of their time in-person at an APS or other (non-home office) location.