> Markdown version of [/jobs/ext/1311829-chief-information-security-officer-ciso](https://www.wearedevelopers.com/jobs/ext/1311829-chief-information-security-officer-ciso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer (CISO) - **Company:** Mission Critical Group - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Computer-Aided Design, Microsoft Windows, Active Directory, Artificial Intelligence, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Data Governance, Information Leak Prevention, Digital Forensics, Disaster Recovery, Multi-Factor Authentication, Supervisory Control and Data Acquisition (SCADA), Identity and Access Management, Virtual Private Networks (VPN), Network Security, Network Segmentation, PCI Data Security Standards, Remote Access Technology, Phishing, Zero Trust Network Access, Security Information and Event Management, Software Engineering, Technical Data Management Systems, Software Vulnerability Management, EndPointSecurity, Enterprise Software Applications, Data Classification, Large Language Models, Software Security, Mttr, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Cybercrime, Process Control Systems, Patch Management, Operational Systems, CIS Benchmarks, Vulnerability Analysis - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e5e1d8d69200bc91 ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related field. * 15+ years of progressive IT and cybersecurity leadership experience. * 8+ years leading enterprise cybersecurity organizations. * Experience in securing manufacturing environments. * Experience securing Operational Technology (OT). * Experience presenting to executive leadership and Boards. * Experience leading enterprise incident response. * Experience managing cybersecurity budgets exceeding $5M. * Strong knowledge of Microsoft enterprise security technologies. Certifications Preferred certifications include: * CISSP * CISM * CRISC * CGEIT * CCSP * GIAC (GICSP, GRID, GCIA, GREM) * Certified Information Systems Auditor (CISA) * Microsoft Cybersecurity Architect Expert (SC-100) * Azure Security Engineer (AZ-500) * Certified Ethical Hacker (CEH) Key Competencies * Leadership * Strategic planning * Cyber risk management * Board communication * Manufacturing cybersecurity * OT/ICS security * Crisis leadership * Regulatory compliance * Enterprise architecture * Cloud security * AI governance * Vendor negotiations * Team development * Financial management * Change leadership ## Description The Chief Information Security Officer (CISO) is responsible for developing, implementing, and leading the enterprise cybersecurity, information risk management, and compliance strategy across a multi-site manufacturing organization. CISO partners with business leaders, engineering, operations, legal, HR, and executive leadership to protect intellectual property, manufacturing systems, operational technology (OT), industrial control systems (ICS), cloud infrastructure, and enterprise applications while enabling business growth and digital transformation. CISO provides strategic leadership over cybersecurity governance, regulatory compliance, cyber risk, incident response, disaster recovery, identity management, and secure adoption of emerging technologies including AI and cloud platforms. The ideal candidate has extensive experience securing both Information Technology (IT) and Operational Technology (OT) environments within manufacturing., Executive Leadership * Develop and execute the enterprise cybersecurity strategy aligned with business objectives. * Present cybersecurity risks, metrics, investment strategies, and emerging threats to executive leadership. * Build a security-first culture throughout the organization. * Develop long-term cybersecurity roadmaps supporting mergers, acquisitions, and business growth. Cybersecurity Governance Lead the enterprise security program including: * Information Security Governance * Cyber Risk Management * Security Policies and Standards * Enterprise Security Architecture * Third-Party Risk Management * Data Governance * AI Governance * Security Awareness Program * Enterprise Vulnerability Management Develop security scorecards and executive dashboards to measure organizational risk. Manufacturing & Operational Technology (OT) Security Lead security initiatives protecting: * Industrial Control Systems (ICS) * SCADA Environments * PLC Networks * Manufacturing Execution Systems (MES) * Robotics * IoT Devices * Plant Networks * Building Automation Systems Responsibilities include: * Network segmentation * Zero Trust architecture * Secure remote vendor access * Asset inventory * Patch management * OT vulnerability assessments * ICS incident response * Plant cyber resiliency IT Infrastructure Security Provide oversight for: * Microsoft 365 * Azure * Active Directory / Entra ID * Identity Governance * Privileged Access Management (PAM) * Endpoint Detection & Response (EDR) * SIEM / SOAR * Email Security * Secure Cloud Architecture * Data Loss Prevention (DLP) * Network Security * VPN * Firewalls * Secure Remote Access Compliance & Regulatory Leadership Ensure compliance with: * NIST Cybersecurity Framework (CSF) * NIST SP 800-53 * NIST SP 800-171 * CMMC Level 2 (if applicable) * ISO 27001 * SOC 2 Type II * CIS Controls * ITAR * DFARS * GDPR * CCPA * PCI-DSS (where applicable) * HIPAA (where applicable) Lead internal and external security audits. Risk Management Establish enterprise processes for: * Cyber Risk Assessments * Business Impact Analysis * Risk Register Management * Vendor Security Reviews * Penetration Testing * Security Architecture Reviews * Application Security * Secure Software Development * M&A Security Due Diligence Security Operations Oversee: * Security Operations Center (SOC) * Incident Response * Threat Hunting * Threat Intelligence * Digital Forensics * Vulnerability Management * Patch Governance * Security Monitoring * Identity Monitoring * Endpoint Protection Develop and test the Cyber Incident Response Plan. Business Continuity & Disaster Recovery Lead enterprise resiliency programs including: * Disaster Recovery * Business Continuity * Cyber Recovery * Ransomware Recovery * Crisis Management * Tabletop Exercises * Executive Incident Simulations Data Protection Develop enterprise data protection strategies covering: * Intellectual Property * Engineering Designs * CAD Files * ERP Data * Manufacturing Data * Customer Information * Financial Information * Supplier Information Implement: * Data Classification * Encryption * Rights Management * Data Loss Prevention * Secure Collaboration Artificial Intelligence Governance Provide executive oversight for: * AI Governance Program * Secure AI Adoption * LLM Risk Management * AI Vendor Assessments * Responsible AI Policies * AI Data Protection * AI Security Controls * Shadow AI Prevention * AI Risk Assessments Vendor & Third-Party Security Develop a mature vendor security program including: * Security Assessments * Contract Security Requirements * Continuous Monitoring * Supply Chain Risk Management * Software Risk Reviews * Cloud Vendor Governance Leadership Responsibilities Lead and mentor teams responsible for: * Security Engineering * Security Operations * Governance, Risk & Compliance (GRC) * Identity & Access Management * OT Security * Cloud Security * Security Architecture * Security Awareness * Disaster Recovery Manage cybersecurity budgets, staffing, strategic planning, and technology investments., * Mean Time to Detect (MTTD) * Mean Time to Respond (MTTR) * Enterprise cyber risk score * Critical vulnerability remediation SLA * Phishing susceptibility rate * Multi-factor authentication adoption * Security awareness completion * Third-party risk assessment completion * Audit findings closed on time * Compliance score (NIST/ISO/CMMC) * OT security maturity score * Incident reduction year over year * Disaster recovery testing success rate * Ransomware recovery readiness * Security budget performance ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)