1

Director Cybersecurity Jobs in Iowa (NOW HIRING)

Exempt; On-site position The Information Systems Director oversees the Information System ... Experience in cybersecurity preferred. Three years experience in healthcare Information Systems ...

VP, Information Security

Des Moines, IA · On-site

$153K - $191K/yr

Direct enterprise vulnerability management, threat assessment, and risk remediation strategies. * Oversee cybersecurity audits, compliance reviews, and security assessments. * Regulatory Compliance ...

VP, Information Security

Des Moines, IA

$153K - $191K/yr

Direct enterprise vulnerability management, threat assessment, and risk remediation strategies. * Oversee cybersecurity audits, compliance reviews, and security assessments. * Regulatory Compliance ...

VP, Information Security

Des Moines, IA · On-site

$153K - $191K/yr

Direct enterprise vulnerability management, threat assessment, and risk remediation strategies. * Oversee cybersecurity audits, compliance reviews, and security assessments. * Regulatory Compliance ...

VP, Information Security

Des Moines, IA

$153K - $191K/yr

Direct enterprise vulnerability management, threat assessment, and risk remediation strategies. * Oversee cybersecurity audits, compliance reviews, and security assessments. * Regulatory Compliance ...

VP, Information Security

Des Moines, IA · On-site

$153K - $191K/yr

Direct enterprise vulnerability management, threat assessment, and risk remediation strategies. * Oversee cybersecurity audits, compliance reviews, and security assessments. * Regulatory Compliance ...

Showing results 21-40

Director Cybersecurity information

See Iowa salary details

$28.7K

$126.9K

$198.8K

How much do director cybersecurity jobs pay per year?

As of Sep 8, 2026, the average yearly pay for director cybersecurity in Iowa is $126,851.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,090.00 and $145,586.00 per year, depending on experience, location, and employer.

What does a director of cybersecurity do?

A Director of Cybersecurity is responsible for overseeing an organization's cybersecurity strategy, policies, and operations. They lead teams to protect sensitive data and systems from cyber threats, manage incident response, and ensure compliance with security regulations. This role often involves collaborating with other executives to align security initiatives with business objectives and staying updated on the latest security technologies and risks. The Director also plays a key role in training staff, conducting risk assessments, and developing disaster recovery plans.

What are the key skills and qualifications needed to thrive as a director of cybersecurity?

To thrive as a Director of Cybersecurity, you need deep expertise in information security management, risk assessment, and incident response, typically supported by a bachelor's or master's degree in a related field and significant industry experience. Familiarity with security frameworks (such as NIST or ISO/IEC 27001), regulatory compliance standards, and certifications like CISSP or CISM is often required. Strong leadership, strategic thinking, and effective communication skills help you guide teams and influence organizational security culture. These skills are crucial for protecting sensitive data, ensuring regulatory compliance, and developing resilient cybersecurity programs.

How does a director of cybersecurity typically collaborate with other departments to ensure organizational security?

A Director of Cybersecurity works closely with various departments, including IT, legal, compliance, and executive leadership, to develop and implement security strategies that align with organizational goals. They often lead cross-functional teams during security incident response, ensure regular communication about risks, and provide guidance on secure practices. Building strong relationships across the organization is essential for fostering a security-aware culture and for integrating security considerations into business processes and projects.

What are the most commonly searched types of Cybersecurity jobs in Iowa?

The most popular types of Cybersecurity jobs in Iowa are:

What are popular job titles related to Director Cybersecurity jobs in Iowa?

For Director Cybersecurity jobs in Iowa, the most frequently searched job titles are:

What job categories do people searching Director Cybersecurity jobs in Iowa look for?

The top searched job categories for Director Cybersecurity jobs in Iowa are:

What cities in Iowa are hiring for Director Cybersecurity jobs?

Cities in Iowa with the most Director Cybersecurity job openings:

Infographic showing various Director Cybersecurity job openings in Iowa as of August 2026, with employment types broken down into 2% As Needed, 82% Full Time, 13% Part Time, 1% Temporary, and 2% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $126,851 per year, or $61 per hour.

Dir, Exposure Management

Berkshire Hathaway Energy

Des Moines, IA • On-site

$178K - $223K/yr

Full-time

This job post has expired today. Applications are no longer accepted.


Key responsibilities

  • Lead the enterprise cybersecurity exposure management program across various environments and assets.

  • Oversee the discovery, prioritization, validation, remediation, and governance of cyber exposures.

  • Partner with teams and leadership to focus on exposures with the greatest business, operational, regulatory, and safety risks.


Berkshire Hathaway Energy rating

6.5

Company rating: 6.5 out of 10

Based on 18 frontline employees who took The Breakroom Quiz


Job description


The Director, Exposure Management leads Berkshire Hathaway Energy's enterprise cybersecurity exposure management program across information technology, operational technology, cloud, applications, software supply chain, and externally accessible environments. Reporting to the Senior Director, Security Governance, Risk & Assurance, this position directs a team of employees and is accountable for executing a risk-based, measurable approach to discovering, prioritizing, assigning ownership, validating, remediating, and governing cyber exposures across Berkshire Hathaway Energy and its affiliates.
The director advances Continuous Threat Exposure Management (CTEM), vulnerability management, external attack surface management, security assessments, application and software supply chain exposure management, offensive security validation, and remediation governance. The role partners with affiliate security teams, technology owners, application and cloud teams, risk and compliance functions, and executive leadership to focus resources on exposures that present the greatest business, operational, regulatory, and safety risk while driving clear ownership, timely remediation, and defensible risk decisions.
Responsibilities
Exposure management strategy and governance (20%)
Develop and execute an enterprise exposure management strategy aligned with cybersecurity, business, operational, regulatory, and resilience objectives. Establish governance for exposure discovery, asset ownership, risk-based prioritization, validation, remediation, exception management, and reporting. Define decision criteria that consider threat intelligence, active exploitation, adversary behavior, known exploited vulnerabilities, exploit prediction, asset exposure, business criticality, operational impact, compensating controls, and regulatory obligations.
CTEM and vulnerability management (20%)
Lead the enterprise vulnerability and exposure management lifecycle for servers, endpoints, network infrastructure, applications, code, third-party components, cloud services, and OT environments. Mature CTEM practices across scoping, discovery, prioritization, validation, and mobilization. Ensure scanning coverage, asset inventory accuracy, data quality, ownership mapping, prioritization, remediation timelines, escalation, and risk acceptance processes are consistently defined and monitored.
External attack surface and exposure discovery (10%)
Oversee continuous identification and monitoring of internet-facing assets and services. Establish processes to identify unknown or unauthorized assets, exposed services, insecure configurations, end-of-life technology, and other externally exploitable conditions. Coordinate with responsible teams to validate ownership and reduce unnecessary attack surface.
Security assessments and validation (10%)
Direct independent security assurance activities application and cloud security assessments, automated security validation, and vendor-supported testing. Confirm whether identified exposures are exploitable, validate corrective actions, and use results to improve security controls and program priorities.
Remediation governance and risk reduction (15%)
Partner with technology and business leaders to develop and track remediation plans for material exposures. Establish a remediation operating model with clear intake, triage, owner assignment, due dates, escalation, validation, closure criteria, and exception processes. Separate routine operating system and technology lifecycle patching from vulnerability-driven remediation while maintaining an integrated view of enterprise exposure. Identify recurring conditions and systemic weaknesses, and sponsor sustainable corrective actions that create lasting ownership and remediation accountability.
Metrics, reporting, and executive communication (10%)
Develop executive-level scorecards, dashboards, and narratives that emphasize measurable risk reduction, exposure reduction, remediation effectiveness, aged exposure reduction, service-level performance, attack surface reduction, asset coverage, ownership quality, validation pass rates, and risk exception trends rather than vulnerability volume alone. Communicate significant exposures, trends, constraints, and decisions to leadership and governance forums.
Affiliate enablement and enterprise consistency (5%)
Establish common exposure management standards, processes, metrics, and governance expectations across Berkshire Hathaway Energy while enabling affiliate-specific execution based on technology environment, operational constraints, regulatory obligations, and business risk. Promote consistent ownership, prioritization, exception handling, and executive reporting while recognizing differences across affiliate operating models.
Leadership, change management, and administration (10%)
Select, coach, develop, and evaluate team members. Set priorities, establish performance expectations, support succession and career development, and foster effective teamwork and high personal integrity. Lead organizational change by helping affiliates and technology teams transition from volume-based vulnerability management to risk-based exposure reduction with clear accountability and measurable outcomes. Manage budgets, vendors, managed services, and contracted assessment resources. Perform additional responsibilities as requested or assigned.
Qualifications
Bachelor's degree in cybersecurity, information technology, computer science, engineering, business, or a related field from an accredited institution, or equivalent related work experience. (Typically, four years of additional related, progressive work experience would be needed for candidates who do not possess a bachelor's degree).
A minimum of ten years of progressive cybersecurity, information technology risk, vulnerability management, security assessment, or related experience, including at least five years leading cybersecurity programs, technical teams, or people.
Demonstrated experience building, leading, or materially maturing an enterprise vulnerability management, threat exposure management, CTEM, attack surface management, offensive security, application security, software supply chain security, or security assurance program in a large or complex organization.
Strong knowledge of risk-based vulnerability prioritization, threat intelligence, exploitability analysis, remediation governance, exception management, vulnerability lifecycle processes, external attack surface management, penetration testing, red teaming, application security testing, software composition analysis, cloud security posture, and security control validation.
Knowledge of IT and OT/ICS technology environments, including networks, operating systems, endpoints, applications, cloud services, industrial control systems, and internet-facing infrastructure.
Working knowledge of recognized cybersecurity and control frameworks such as the NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, and ISO/IEC 27001. Knowledge of electric utility or critical infrastructure regulatory requirements is preferred.
Experience with enterprise security platforms and data sources used for vulnerability scanning, external attack surface management, application security testing, cloud posture management, OT security monitoring, threat intelligence, workflow management, and executive reporting. Experience with tools such as Rapid7, Cortex Xpanse, Horizon3, Microsoft security products, and Axonious is beneficial but not required.
Ability to translate technical findings into business risk, establish practical priorities, assign accountability, challenge assumptions constructively, and drive coordinated action across organizational boundaries without relying solely on direct authority.
Excellent oral and written communication skills, including executive and board-level presentation skills. Effective interpersonal, customer relationship, analytical, problem-solving, negotiation, and decision-making skills.
Strong program and project management skills, including the ability to prioritize and manage multiple complex initiatives concurrently.
Professional certifications such as CISSP, CISM, CRISC, GIAC, or similar credentials are preferred.
About Us
MidAmerican Energy Company, a Midwest utility, provides regulated electric and natural gas service to more than 1.6 million customers in Illinois, Iowa, Nebraska and South Dakota. The company owns and operates a portfolio of power-generating assets, approximately 61% of which is wind generation.
About the Team
MidAmerican Energy Company is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion or religious creed, age, national origin, ancestry, citizenship status (except as required by law), gender (including gender identity and expression), sex (including pregnancy), sexual orientation, genetic information, physical or mental disability, veteran or military status, familial or parental status, marital status or any other category protected by applicable local, state or U.S. federal law. Employees must be able to perform the essential functions of the position, with or without an accommodation.

What Berkshire Hathaway Energy employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom