Vice President & CISO overseeing global Information Security program at a manufacturing company. Leading strategy, governance, and management across U.S., Germany, and India teams.
Responsibilities
Develop and execute the global information security strategy aligned to business objectives and risk appetite.
Provide quarterly cybersecurity updates to the Audit Committee and Executive Management Team.
Establish security governance, policies, and standards consistent with leading frameworks (NIST CSF, ISO 27001, CIS).
Oversee enterprise risk assessments and maintain a risk-based roadmap for continuous improvement.
Lead the design, implementation, and management of all security technologies and controls including endpoint protection, identity & access management, SIEM/SOC operations, cloud security, vulnerability management, and network security.
Ensure proactive monitoring, rapid detection, and response to security incidents across global operations.
Oversee business continuity and disaster recovery security components in partnership with Infrastructure and Applications teams.
Embed security-by-design into IT and business projects, including cloud, ERP, operational technology (OT), and Industry 4.0 initiatives.
Conduct architectural reviews and threat modeling for new technologies and digital transformation efforts.
Partner closely with Legal to ensure compliance with global data privacy laws, including GDPR, CCPA, and emerging regulations.
Oversee data protection practices, records retention security considerations, and reporting obligations related to data privacy incidents.
Lead the global third-party risk management program, including supplier assessments and ongoing monitoring.
Respond to and manage customer security inquiries, audits, and contractual security requirements.
Drive vendor governance for security tools, MSSP partnerships, and other outsourced services.
Lead a global Information Security team of 12 across the U.S., Germany, and India.
Manage a $3M annual operating budget, ensuring cost-effective investments in technology, services, and capabilities.
Mentor, develop, and scale the team to support global manufacturing operations and business growth.
Requirements
10+ years of progressive experience in Information Security leadership roles.
Minimum 3 years as a CISO or a deputy/second-in-command security leader in a larger enterprise.
Deep expertise in security operations, architecture, governance, risk, compliance, and incident response.
Strong working knowledge of NIST CSF, ISO 27001, CIS Controls, and modern cybersecurity technologies.
Experience in global environments and working with distributed teams.
Demonstrated ability to present complex cybersecurity topics to Audit Committees and senior executives.
Manager at PwC contributing to digital transformation in Utilities through technology consulting and stakeholder management. Focused on creating strategies and providing technology solutions in a data - driven world.
Research Associate conducting advanced research in iOS security within a leading institute for applied cybersecurity. Emphasis on secure application development and vulnerability analysis.
Cybersecurity Engineer focused on threat monitoring and incident response for Verizon's network security. Collaborating on security architecture and vulnerability management across multiple locations.
Senior Manager of Application Security leading initiatives to protect applications at Nordstrom through strategic leadership and AI - driven tooling. Collaborating with engineering to ensure secure software development practices.
Information Security Engineer responsible for deploying and supporting security tools across cloud and on - premise systems. Collaborating with IT to mitigate security risks in a hybrid work environment.
Casual Retail Security Officer for MSS Security ensuring safety at Tweed Mall in Tweed Heads. Responsible for patrols, incident response, and customer service.
Financial security advisor at Desjardins developing client relationships and selling life and health insurance products. Focusing on customer satisfaction and personalized financial solutions.
Principal Information Security Consultant at Westpac focusing on security protocols and employee benefits for staff. Hybrid role centrally located with opportunities for professional development and employee perks.
Engineer supporting secure development lifecycle processes for product lines in the energy sector. Collaborating with R&D on security requirements and compliance audits.
Automation Oversight Engineer providing oversight of compliance in automated device configurations for Comcast Business. Managing configuration checks and reporting, ensuring reliable oversight and improvement strategies.