Chief Information Security Officer CISO
Listed on 2026-09-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Job Description
The Chief Information Security Officer (CISO) is responsible for developing, implementing, and leading the enterprise cybersecurity, information risk management, and compliance strategy across a multi-site manufacturing organization. CISO partners with business leaders, engineering, operations, legal, HR, and executive leadership to protect intellectual property, manufacturing systems, operational technology (OT), industrial control systems (ICS), cloud infrastructure, and enterprise applications while enabling business growth and digital transformation.
CISO provides strategic leadership over cybersecurity governance, regulatory compliance, cyber risk, incident response, disaster recovery, identity management, and secure adoption of emerging technologies including AI and cloud platforms.
The ideal candidate has extensive experience securing both Information Technology (IT) and Operational Technology (OT) environments within manufacturing.
Key Responsibilities Executive Leadership- Develop and execute the enterprise cybersecurity strategy aligned with business objectives.
- Present cybersecurity risks, metrics, investment strategies, and emerging threats to executive leadership.
- Build a security-first culture throughout the organization.
- Develop long-term cybersecurity roadmaps supporting mergers, acquisitions, and business growth.
Lead the enterprise security program including:
- Information Security Governance
- Cyber Risk Management
- Security Policies and Standards
- Enterprise Security Architecture
- Third-Party Risk Management
- Data Governance
- AI Governance
- Security Awareness Program
- Enterprise Vulnerability Management
Develop security scorecards and executive dashboards to measure organizational risk.
Manufacturing & Operational Technology (OT) SecurityLead security initiatives protecting:
- Industrial Control Systems (ICS)
- SCADA Environments
- PLC Networks
- Manufacturing Execution Systems (MES)
- Robotics
- IoT Devices
- Plant Networks
- Building Automation Systems
Responsibilities include:
- Network segmentation
- Zero Trust architecture
- Secure remote vendor access
- Asset inventory
- Patch management
- OT vulnerability assessments
- ICS incident response
- Plant cyber resiliency
Provide oversight for:
- Microsoft 365
- Azure
- Active Directory / Entra
- Identity Governance
- Privileged Access Management (PAM)
- Endpoint Detection & Response (EDR)
- SIEM / SOAR
- Email Security
- Secure Cloud Architecture
- Data Loss Prevention (DLP)
- Network Security
- VPN
- Firewalls
- Secure Remote Access
Ensure compliance with:
- NIST Cybersecurity Framework (CSF)
- NIST SP 800-53
- NIST SP 800-171
- CMMC Level 2 (if applicable)
- ISO 27001
- SOC 2 Type II
- CIS Controls
- ITAR
- DFARS
- GDPR
- CCPA
- PCI-DSS (where applicable)
- HIPAA (where applicable)
Lead internal and external security audits.
Risk ManagementEstablish enterprise processes for:
- Cyber Risk Assessments
- Business Impact Analysis
- Risk Register Management
- Vendor Security Reviews
- Penetration Testing
- Security Architecture Reviews
- Application Security
- Secure Software Development
- M&A Security Due Diligence
Oversee:
- Security Operations Center (SOC)
- Incident Response
- Threat Hunting
- Threat Intelligence
- Digital Forensics
- Vulnerability Management
- Patch Governance
- Security Monitoring
- Identity Monitoring
- Endpoint Protection
Develop and test the Cyber Incident Response Plan.
Business Continuity & Disaster RecoveryLead enterprise resiliency programs including:
- Disaster Recovery
- Business Continuity
- Cyber Recovery
- Ransomware Recovery
- Crisis Management
- Tabletop Exercises
- Executive Incident Simulations
Develop enterprise data protection strategies covering:
- Intellectual Property
- Engineering Designs
- CAD Files
- ERP Data
- Manufacturing Data
- Customer Information
- Financial Information
- Supplier Information
Implement:
- Data Classification
- Encryption
- Rights Management
- Data Loss Prevention
- Secure Collaboration
Provide executive oversight for:
- AI Governance Program
- Secure AI Adoption
- LLM Risk Management
- AI Vendor Assessments
- Responsible AI Policies
- AI Data Protection
- AI Security Controls
- Shadow AI Prevention
- AI Risk Assessments
Develop a mature vendor security program…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).