> Markdown version of [/jobs/ext/239836-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/239836-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer - **Company:** Johns Manville - **Location:** Denver, CO, United States - **Experience:** Expert - **Salary:** $200,000.0 - $250,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Microsoft Windows, Artificial Intelligence, Antivirus Softwares, Cloud Computing Security, Cyber Security, Information Systems, Computer Networks, Information Leak Prevention, Linux, Information Technology Audit, Internet Security, Intrusion Detection and Prevention, Microsoft Office, Microsoft PowerPoint, Remote Access Technology, Power BI, Zero Trust Network Access, Software Vulnerability Management, Large Language Models, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Industrial Software, Server Operating Systems & Platforms, Vmware - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7d5e68941d9de83b ## About the Role Applicants can expect to make between $200,000 to $250,000 upon hire. In addition, this position is eligible for a target incentive bonus under our variable incentive plan, as well as to participate in our long-term incentive program. Pay within this range will vary based upon relevant experience, skills, and education among other factors., * BA/BS degree with a master's degree in a business or security discipline preferred * Minimum 15 years of relevant information technology, risk, security, and compliance experience in a global environment; must have a broad range of exposure to all aspects of information security and a significant depth of technical expertise * Minimum 10 years of management experience; experience in building and/or running information security teams. Preferred experience at a director level or above. * Demonstrated experience securing both corporate (IT) and industrial technology (OT) environments with direct knowledge of process control manufacturing systems * Established contacts with law enforcement agencies (FBI, CISA, Secret Service) cyber protection bureaus * Experience working at executive levels and cross functionally across geographically distributed operations to support business strategic goals and plans. * Strong communication skills and demonstrated ability to interact with team members, and executive management. * Strong technical skills relevant to cyber and internet security such as intrusion detection / intrusion prevention, vulnerability management, firewalls, security event management, threat intelligence and zero trust architecture. * Experience with large information security projects, assessments, audits, threat detection, and response. * Experience developing and communicating policies and standards * Strong leadership, communication, influencing, and negotiation skills. * Strategic thinker, keeping big picture in mind while ensuring execution excellence. * Ability to manage complexity, prioritize, and make effective decisions in complex, cross-functional, changing environments. * Proven leadership of high-performing cross-functional global teams. * Information security certification (e.g., CISSP, CISM, etc.) preferred. * Industrial control experience required. Skills Abilities: * Expert + Security Frameworks (NIST CSF, ISO27001, IEC 62443, HIPAA) + Networking design, routing, and segmentation + Vulnerability, threat management, and security operations (SEIM, SOAR) * Solid + Microsoft Office 365, Purview design, and management + Security Architecture Design - Zero Trust + Desktop Operating Systems (Windows, Apple) + Server Operating Systems (Linux, Windows, VMware) + eDiscovery and Forensics + Vendor and Cloud Security Management + Experience reporting and presenting information security concepts, strategy, performance, and incident response to executive leaders. * Proficient in Microsoft PowerPoint, Excel, Word, PowerBI and Copilot. * Verbal and written communications in English * Travel Requirements: Moderate - (11 - 29 days per year) * Environment and Physical Activities: Work environment is typical of an office setting., Incumbent must be physically able to perform essential job functions. Reasonable accommodations may be made to enable individuals with disabilities to perform essential job functions. ## Description The Chief Information Security Officer (CISO) is responsible for the design, implementation, and management of the global information security program in alignment with JM business objectives. The role is a mix of hands-on engagement and leadership. The CISO establishes the standards, practices, and controls to ensure the information security program protects company data and assets and follows required compliance, regulations, and parent company expectations. Scope of the role includes management of corporate and industrial cyber security, cyber threat intelligence, corporate and industrial voice and data networks and data protection. The position reports to the Chief Information Officer (CIO) and chairs the JM Information Security Council. CISO is responsible for informing leadership of risks, mitigations, and readiness as well as building awareness of cyber security within the organization., Security Strategy: * Directs the assessment, mitigation, and actions to reduce cyber security risks for corporate and industrial assets and data * Establishes and maintains information security policy and standards * Directs the reviews and processing cyber intelligence. * Reviews all information security plans across enterprise to ensure alignment with business requirements, JM policies, and standards. * Facilitates continuous risk assessment, analysis, and mitigation activities. * Maintains current knowledge of technical security services and mechanisms and monitors advancements in information security and emerging technologies to manage risks and ensure compliance. * Actively participates in the external information security communities and parent company Cyber Security Council to foster effective communications, knowledge sharing, and best practices. Security Governance: * Organizes and facilitates the Information Security Council meeting to review, align and approve appropriate information security policies, practices, standards, resources, and controls. * Maintain process to safeguard and verify the safety, confidentiality, integrity, and availability of business and industrial systems and data. * Facilitates development and application of data loss prevention standards * Support internal and external audits, coordinate IT audit responses, and track observations to closure. Proactively report issues and challenges to timely completion of audit actions. * Ensures testing and verification of changes to reduce likelihood of repeat findings from internal or external audits. * Manage AI Governance group responsible for the evaluation of operational, cyber and data risks of AI and the required people, process, and technical controls. * Conduct related ongoing compliance monitoring activities in coordination with JM's other compliance and operational assessment functions. * In coordination with Legal and designated personnel, is responsible for supporting JM's compliance with data privacy laws. Security Awareness and Advocacy: * Initiate, facilitate and promote activities to foster information security awareness at corporate, service and manufacturing locations. * Demonstrates visible leadership across the organization to identify, report and resolve cyber risks * Communicate and maintain list of approved uses of tools and technology that meet JM standards Security Operations: * Responsible for the design, operations, and improvements to security infrastructure of the organization and key security initiatives, tools, and standards, (e.g., virus protection, security monitoring, intrusion detection, local and remote access control policies and other technical security services and mechanisms). * Directs an effective Security Operations Center (SOC) for monitoring of corporate and industrial networks and systems * Ensures secure design and operations of global voice and data networks * Perform security assessments of 3rd party information system suppliers and technologies (e.g., cloud solution providers, LLM, AI solutions). * Recommend to the CIO adequate information security staffing needs to support the organization. * Maintain incident response playbook and conduct tabletop exercises to test the readiness and response capabilities for corporate and industrial systems. * Manage installation and operations of hardware and software for physical security cameras and access systems ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)