> Markdown version of [/jobs/ext/1915618-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/1915618-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer - **Company:** WolfSpeed Inc. - **Location:** Durham, NC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Systems Engineering, Cyber Security, Information Technology Audit, Information Technology Operations, Information Technology - **Published:** August 4, 2026 - **Apply:** https://www.juju.com/job/00000000glofws ## About the Role This position requires a strong understanding of the semiconductor industry, strategic capabilities that can align our cybersecurity strategy and practices with our business model, objectives, and the risk universe we operate within globally. The role requires a blend of innovative thinking to lead our company staying ahead of the ever-evolving threat landscape, along with strategic planning, technical expertise, and leadership - to ensure our information security posture is robust and resilient against evolving cyber risks. The ideal candidate will have a proven track record in developing and implementing comprehensive security programs in High Tech or Semiconductor manufacturing environments., + Bachelor's or Master's degree in Information Security, Computer Science, or related field. + Professional security management certification, such as a CISSP, CISM, or similar. + 15+ years of experience in a combination of risk management, information security, and IT jobs, with at least 10 years in a senior leadership role. + Experience with NIST (800-171) and ISO (27001) frameworks + Experience with CMMC (Cybersecurity Maturity Model Certification) for USGOV + Deep understanding of the evolving cybersecurity threats facing the semiconductor industry and experience in crafting strategies to mitigate these risks. + Knowledge of relevant legal and regulatory requirements, including export controls + Experience with contract and vendor negotiations and management including managed services. + Strong leadership skills and the ability to work effectively with business managers, IT engineering and IT operations staff, Wolfspeed's vendors and suppliers. + Excellent verbal and written communication skills, including the ability to explain technical concepts and technologies to business leaders, and business concepts to the IT workforce. ## Description + Develop, implement, and monitor a strategic, comprehensive enterprise information security and IT risk management program at a global scale - to ensure the integrity, confidentiality, and availability of information owned, controlled, or processed by the organization, including secrets, patents, and proprietary designs + Lead the enterprise's information security organization, including hiring, training, and mentoring a team of security professionals. + Identify, evaluate, and report on information security risks timely, and in a manner that meets Executive Management and the Board's expectations, meets the compliance and regulatory requirements, and aligns with and supports the risk posture of the enterprise. + Design and implement protective measures for securing proprietary designs, patents, and other sensitive corporate information, considering the unique risks present in the semiconductor industry, given innovation and IP contributes materially to our company's competitive advantage. + Work directly with the business units to facilitate risk assessment and risk management processes, and work with stakeholders throughout the enterprise on identifying acceptable levels of residual risk. + Ensure cybersecurity policies are in alignment with Enterprise business policies, IT policies and the global Enterprise Risk Management framework for Wolfspeed. + Develop and manage information security budgets and adopt cost-effective expense strategies and practices - to reduce and mitigate identified risks. + Establish and oversee the implementation of a cybersecurity incident management program that includes incident detection, response, mitigation, and recovery processes. + Effectively align cybersecurity practices with overall crisis management and incident response strategies, test plans and tabletop exercises - to ensure business continuity for Wolfspeed in the event of a worst-case disaster scenario, whether or not triggered by a security incident. + Liaise with external agencies, such as law enforcement and other advisory bodies as necessary, to ensure that the organization maintains a strong security posture against external threats. + Conduct regular security audits, risk assessments, support annual financial and IT audit objectives, and ensure compliance with industry standards and regulatory requirements specific to the semiconductor industry. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Model Based Systems Engineering in an Agile Product Development Process](https://www.wearedevelopers.com/videos/68-model-based-systems-engineering-in-an-agile-product-development-process) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)