Vice President & CISO overseeing global Information Security program at a manufacturing company. Leading strategy, governance, and management across U.S., Germany, and India teams.
Responsibilities
Develop and execute the global information security strategy aligned to business objectives and risk appetite.
Provide quarterly cybersecurity updates to the Audit Committee and Executive Management Team.
Establish security governance, policies, and standards consistent with leading frameworks (NIST CSF, ISO 27001, CIS).
Oversee enterprise risk assessments and maintain a risk-based roadmap for continuous improvement.
Lead the design, implementation, and management of all security technologies and controls including endpoint protection, identity & access management, SIEM/SOC operations, cloud security, vulnerability management, and network security.
Ensure proactive monitoring, rapid detection, and response to security incidents across global operations.
Oversee business continuity and disaster recovery security components in partnership with Infrastructure and Applications teams.
Embed security-by-design into IT and business projects, including cloud, ERP, operational technology (OT), and Industry 4.0 initiatives.
Conduct architectural reviews and threat modeling for new technologies and digital transformation efforts.
Partner closely with Legal to ensure compliance with global data privacy laws, including GDPR, CCPA, and emerging regulations.
Oversee data protection practices, records retention security considerations, and reporting obligations related to data privacy incidents.
Lead the global third-party risk management program, including supplier assessments and ongoing monitoring.
Respond to and manage customer security inquiries, audits, and contractual security requirements.
Drive vendor governance for security tools, MSSP partnerships, and other outsourced services.
Lead a global Information Security team of 12 across the U.S., Germany, and India.
Manage a $3M annual operating budget, ensuring cost-effective investments in technology, services, and capabilities.
Mentor, develop, and scale the team to support global manufacturing operations and business growth.
Requirements
10+ years of progressive experience in Information Security leadership roles.
Minimum 3 years as a CISO or a deputy/second-in-command security leader in a larger enterprise.
Deep expertise in security operations, architecture, governance, risk, compliance, and incident response.
Strong working knowledge of NIST CSF, ISO 27001, CIS Controls, and modern cybersecurity technologies.
Experience in global environments and working with distributed teams.
Demonstrated ability to present complex cybersecurity topics to Audit Committees and senior executives.
OT Cybersecurity Engineer deploying and managing security solutions for operational technology environments at Solventum. Collaborates with teams to improve security posture and provide user support.
Principal Cybersecurity role at AT&T focusing on cloud security feature design and implementation. Leading innovative security solutions in conjunction with modern cloud technologies and Agile methodologies.
Cloud Security Vulnerability Management Program Specialist ensuring secure configurations of cloud workloads. Focused on vulnerability management, monitoring, and risk remediation across environments at Bank of America.
Security Architect delivering secure solutions for Defence and National Security at SiXworks. Supporting agile teams in technical projects like Kubernetes and security risk management.
CIS Security Manager responsible for EID’s information security strategy and compliance. Ensuring protection of information assets and promoting security culture across the organization.
Cyber Security Subject Matter Expert at CACI supporting a new DoD contract. Working on cloud security with an emphasis on system security engineering and risk management.
Cybersecurity Engineer developing solutions for complex security challenges protecting data and networks. Implementing next generation security solutions for government and commercial clients in hands - on roles.
Information Security Manager responsible for security governance and risk management. Engaging with technical teams for compliance with security standards and best practices.
Security Access Control Specialist at AMERICAN SYSTEMS managing database queries, document processes, and security measures. Supporting federal government programs through effective security operations in McLean, VA.