Global Head of Cyber Security

On-site

About this role

The Global Head of Cyber Security is responsible for ensuring the protection and resilience of newcleo’s global technology estate, including IT, OT and critical digital assets (CDAs), across its operations in the US and Europe. The role owns the cyber security governance framework, maturity roadmap and enterprise cyber risk management required to safeguard operations, meet regulatory expectations and support business growth.

Reporting to the Head of IT RUN, the role leads the global Cyber Security function, including capability, budget and strategic suppliers, and coordinates cyber security activities across IT, Engineering and business functions. The role provides transparent reporting on cyber risk to the Head of IT RUN, with visibility to the Audit & Risk Committee, ensuring cyber risks are understood, prioritised and effectively managed across newcleo.

 

Main Activities

Cyber Security Governance & Framework:

  • Define and maintain newcleo’s cyber security governance framework, policies, standards and maturity roadmap.
  • Establish the enterprise security architecture and control framework aligned with nuclear-sector and international standards (e.g. ISO 27001, NIST CSF).
  • Define and oversee core security architecture domains, including identity and access management (IAM), zero trust principles and cloud security, ensuring consistent controls across on-premise, cloud and OT environments.
  • Ensure new technology, systems and digital capabilities are delivered secure by design, with security requirements embedded from project inception.
  • Define cyber security priorities and investment requirements to support risk reduction, regulatory compliance and business growth.

 Leadership & Team Management:

  • Lead and develop the global Cyber Security function, including local security leads across key locations.
  • Build capability through coaching, mentoring and succession planning.
  • Manage cyber security resources, budget and strategic supplier relationships.

 Security Operations & Incident Response:

  • Oversee global cyber defence capabilities, including threat monitoring, vulnerability management, penetration testing and incident response.
  • Lead cyber incident management, crisis response and remediation activities, coordinating with newcleo's wider business continuity and disaster recovery framework.
  • Ensure appropriate security controls and monitoring across IT, OT and critical digital assets.
  • Embed cyber security into operational processes and technology services.

 

Nuclear & Regulatory Compliance:

  • Maintain alignment with relevant regulations and standards, including the US Nuclear Regulatory Commission (NRC) cyber security requirements (10 CFR 73.54), French ANSSI requirements, NIS2, GDPR and IAEA nuclear security guidance.
  • Support regulatory engagement and represent newcleo in cyber security audits, inspections and certifications.
  • Ensure cyber security practices support nuclear safety, security and operational requirements across critical digital assets and OT environments.

 Risk Management & Assurance:

  • Maintain the enterprise cyber risk profile, escalating material risks, incidents and trends through appropriate governance channels.
  • Provide objective challenge and assurance over the effectiveness of cyber security controls across IT, Engineering and business functions.
  • Support third-party and supply chain cyber risk management, particularly for critical nuclear suppliers and partners.

 Culture, Awareness & Training:

  • Build a strong cyber security culture through awareness, training and targeted communications.
  • Establish role-based cyber training for higher-risk functions, including Engineering, OT and Finance.

Experience

 

  • Proven experience as a CISO / Head of Cyber Security in a global, multi-site organisation — ideally within nuclear, energy, or another critical infrastructure or highly regulated sector.
  • Deep expertise across IT, OT/industrial control system (ICS/SCADA) security and critical digital assets (CDAs), ideally within a nuclear or similarly regulated environment.
  • Strong track record engaging Boards, Audit & Risk Committees and regulators on cyber risk.
  • Working knowledge of nuclear-sector regulatory frameworks and international standards (ISO 27001, NIST CSF).
  • Experience leading incident response and crisis management at enterprise scale.
  • Relevant professional certification (e.g. CISSP, CISM, CRISC) desirable.

 

Language Proficiency: 

 

  • Strong written and verbal communication skills in English (CEFR C1+)
  • French or Italian is a plus.

Company at a glance

Since launching in 2021 newcleo has quickly established itself as innovator in the field of nuclear energy. newcleo is working to design, build, and operate Gen-IV Advanced Modular Reactors (AMRs) that are cooled by liquid lead and fuelled by reprocessed nuclear waste.

Through an innovative combination of existing and proven technologies, and by reviving a nuclear industry model based on the manufacture and multi-recycling of Mixed Oxide fuel, newcleo aims to close the nuclear fuel cycle while safely producing clean, affordable, and practically inexhaustible energy required for low carbon economies.

With a EUR 70m group turnover in 2024, EUR 645m of private funding and over 100 partnerships and collaborations across the nuclear industry, the growth of the newcleo group is supported through the targeted acquisition of key companies with strong capabilities in nuclear engineering, manufacturing, and waste management.

Through its workforce of over 900 highly qualified employees across France, the U.S., the UK, Italy, Switzerland and Slovakia, newcleo is not only developing and delivering the skills and services required for the group’s own ambitious project timelines, but also supporting the development of Small Modular Reactor supply chains in Europe and beyond.

Founded2021
Team Size501-1,000 employees
WorkspaceOn-site
IndustryNuclear Electric Power Generation
Location
United States

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?