Chief Information Security Officer CISO

Mission Critical Group

Tempe (AZ)

On-site

USD 180,000 - 260,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Mission Critical Group is seeking a Chief Information Security Officer to lead enterprise cybersecurity for a multi-site manufacturing organization. The role partners with executives to protect IT/OT, ICS, and cloud platforms while enabling digital transformation.

The ideal candidate will have extensive experience securing IT and OT environments in manufacturing, implementing governance, risk, and compliance programs, and guiding AI governance initiatives.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related field.
  • 15+ years of progressive IT and cybersecurity leadership experience.
  • 8+ years leading enterprise cybersecurity organizations.
  • Experience in securing manufacturing environments.
  • Experience securing OT environments.
  • Experience presenting to executive leadership and Boards.
  • Experience leading enterprise incident response.
  • Experience managing cybersecurity budgets exceeding $5M.
  • Strong knowledge of Microsoft enterprise security technologies.

Responsibilities

  • Develop and execute the enterprise cybersecurity strategy aligned with business objectives.
  • Present cybersecurity risks, metrics, investment strategies, and emerging threats to executive leadership.
  • Build a security-first culture throughout the organization.
  • Develop long-term cybersecurity roadmaps supporting mergers, acquisitions, and business growth.
  • Lead the enterprise security program including information security governance, cyber risk management, policies and standards, enterprise security architecture, third-party risk management, data governance, AI governance, security awareness, and vulnerability management.
  • Develop security scorecards and executive dashboards to measure organizational risk.
  • Lead security initiatives protecting ICS, SCADA, PLC networks, MES, robotics, IoT devices, plant networks and building automation systems.
  • Oversee IT infrastructure security areas such as Microsoft 365, Azure, AD/Entra ID, PAM, EDR, SIEM/SOAR, email security, cloud security, DLP, network security, VPN, firewalls, and secure remote access.
  • Ensure compliance with CSF, NIST SPs, ISO 27001, SOC 2 Type II, CIS Controls, ITAR, DFARS, GDPR, CCPA, PCI-DSS, HIPAA.
  • Establish enterprise processes for cyber risk assessments, business impact analysis, risk register management, vendor security reviews, penetration testing, and security architecture reviews.
  • Lead Security Operations Center, incident response, threat hunting, threat intelligence, digital forensics, vulnerability management, patch governance, monitoring, identity monitoring, and endpoint protection.
  • Lead business continuity and disaster recovery programs including tabletop exercises and executive simulations.
  • Develop enterprise data protection strategies covering IP, CAD files, ERP data, manufacturing data, customer data, financial data, and supplier information.

Skills

Leadership
Strategic planning
Cyber risk management
Board communication
Manufacturing cybersecurity
OT/ICS security
Crisis leadership
Regulatory compliance
Enterprise architecture
Cloud security
AI governance
Vendor negotiations
Team development
Financial management
Change leadership

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related field

Tools

Microsoft enterprise security technologies

Job description

Job Description

The Chief Information Security Officer (CISO) is responsible for developing, implementing, and leading the enterprise cybersecurity, information risk management, and compliance strategy across a multi-site manufacturing organization. CISO partners with business leaders, engineering, operations, legal, HR, and executive leadership to protect intellectual property, manufacturing systems, operational technology (OT), industrial control systems (ICS), cloud infrastructure, and enterprise applications while enabling business growth and digital transformation.

CISO provides strategic leadership over cybersecurity governance, regulatory compliance, cyber risk, incident response, disaster recovery, identity management, and secure adoption of emerging technologies including AI and cloud platforms.

The ideal candidate has extensive experience securing both Information Technology (IT) and Operational Technology (OT) environments within manufacturing.

Key Responsibilities
Executive Leadership
  • Develop and execute the enterprise cybersecurity strategy aligned with business objectives.
  • Present cybersecurity risks, metrics, investment strategies, and emerging threats to executive leadership.
  • Build a security-first culture throughout the organization.
  • Develop long-term cybersecurity roadmaps supporting mergers, acquisitions, and business growth.
Cybersecurity Governance

Lead the enterprise security program including:

  • Information Security Governance
  • Cyber Risk Management
  • Security Policies and Standards
  • Enterprise Security Architecture
  • Third-Party Risk Management
  • Data Governance
  • AI Governance
  • Security Awareness Program
  • Enterprise Vulnerability Management

Develop security scorecards and executive dashboards to measure organizational risk.

Manufacturing & Operational Technology (OT) Security

Lead security initiatives protecting:

  • Industrial Control Systems (ICS)
  • SCADA Environments
  • PLC Networks
  • Manufacturing Execution Systems (MES)
  • Robotics
  • IoT Devices
  • Plant Networks
  • Building Automation Systems

Responsibilities include:

  • Network segmentation
  • Zero Trust architecture
  • Secure remote vendor access
  • Asset inventory
  • Patch management
  • OT vulnerability assessments
  • ICS incident response
  • Plant cyber resiliency
IT Infrastructure Security

Provide oversight for:

  • Microsoft 365
  • Azure
  • Active Directory / Entra ID
  • Identity Governance
  • Privileged Access Management (PAM)
  • Endpoint Detection & Response (EDR)
  • SIEM / SOAR
  • Email Security
  • Secure Cloud Architecture
  • Data Loss Prevention (DLP)
  • Network Security
  • VPN
  • Firewalls
  • Secure Remote Access
Compliance & Regulatory Leadership

Ensure compliance with:

  • NIST Cybersecurity Framework (CSF)
  • NIST SP 800-53
  • NIST SP 800-171
  • CMMC Level 2 (if applicable)
  • ISO 27001
  • SOC 2 Type II
  • CIS Controls
  • ITAR
  • DFARS
  • GDPR
  • CCPA
  • PCI-DSS (where applicable)
  • HIPAA (where applicable)

Lead internal and external security audits.

Risk Management

Establish enterprise processes for:

  • Cyber Risk Assessments
  • Business Impact Analysis
  • Risk Register Management
  • Vendor Security Reviews
  • Penetration Testing
  • Security Architecture Reviews
  • Application Security
  • Secure Software Development
  • M&A Security Due Diligence
Security Operations

Oversee:

  • Security Operations Center (SOC)
  • Incident Response
  • Threat Hunting
  • Threat Intelligence
  • Digital Forensics
  • Vulnerability Management
  • Patch Governance
  • Security Monitoring
  • Identity Monitoring
  • Endpoint Protection

Develop and test the Cyber Incident Response Plan.

Business Continuity & Disaster Recovery

Lead enterprise resiliency programs including:

  • Disaster Recovery
  • Business Continuity
  • Cyber Recovery
  • Ransomware Recovery
  • Crisis Management
  • Tabletop Exercises
  • Executive Incident Simulations
Data Protection

Develop enterprise data protection strategies covering:

  • Intellectual Property
  • Engineering Designs
  • CAD Files
  • ERP Data
  • Manufacturing Data
  • Customer Information
  • Financial Information
  • Supplier Information

Implement:

  • Data Classification
  • Encryption
  • Rights Management
  • Data Loss Prevention
  • Secure Collaboration
Artificial Intelligence Governance

Provide executive oversight for:

  • AI Governance Program
  • Secure AI Adoption
  • LLM Risk Management
  • AI Vendor Assessments
  • Responsible AI Policies
  • AI Data Protection
  • AI Security Controls
  • Shadow AI Prevention
  • AI Risk Assessments
Vendor & Third-Party Security

Develop a mature vendor security program including:

  • Security Assessments
  • Contract Security Requirements
  • Continuous Monitoring
  • Supply Chain Risk Management
  • Software Risk Reviews
  • Cloud Vendor Governance
Leadership Responsibilities

Lead and mentor teams responsible for:

  • Security Engineering
  • Security Operations
  • Governance, Risk & Compliance (GRC)
  • Identity & Access Management
  • OT Security
  • Cloud Security
  • Security Architecture
  • Security Awareness
  • Disaster Recovery

Manage cybersecurity budgets, staffing, strategic planning, and technology investments.

Qualifications
Required
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related field.
  • 15+ years of progressive IT and cybersecurity leadership experience.
  • 8+ years leading enterprise cybersecurity organizations.
  • Experience in securing manufacturing environments.
  • Experience securing Operational Technology (OT).
  • Experience presenting to executive leadership and Boards.
  • Experience leading enterprise incident response.
  • Experience managing cybersecurity budgets exceeding $5M.
  • Strong knowledge of Microsoft enterprise security technologies.
Certifications

Preferred certifications include:

  • CISSP
  • CISM
  • CRISC
  • CGEIT
  • CCSP
  • GIAC (GICSP, GRID, GCIA, GREM)
  • Certified Information Systems Auditor (CISA)
  • Microsoft Cybersecurity Architect Expert (SC-100)
  • Azure Security Engineer (AZ-500)
  • Certified Ethical Hacker (CEH)
Key Competencies
  • Leadership
  • Strategic planning
  • Cyber risk management
  • Board communication
  • Manufacturing cybersecurity
  • OT/ICS security
  • Crisis leadership
  • Regulatory compliance
  • Enterprise architecture
  • Cloud security
  • AI governance
  • Vendor negotiations
  • Team development
  • Financial management
  • Change leadership
Key Performance Indicators (KPIs)
  • Mean Time to Detect (MTTD)
  • Mean Time to Respond (MTTR)
  • Enterprise cyber risk score
  • Critical vulnerability remediation SLA
  • Phishing susceptibility rate
  • Multi-factor authentication adoption
  • Security awareness completion
  • Third-party risk assessment completion
  • Audit findings closed on time
  • Compliance score (NIST/ISO/CMMC)
  • OT security maturity score
  • Incident reduction year over year
  • Disaster recovery testing success rate
  • Ransomware recovery readiness
  • Security budget performance

MCG is an equal opportunity employer prohibiting discrimination based on race, color, creed, religion, sex, marital status, physical or mental disability, and any other protected classes stated by applicable federal and state laws. MCG is committed to providing equal employment opportunities to qualified individuals with disabilities and to act in accordance with regulations and guidance issued by the Equal Employment Opportunity Commission (EEOC).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Vivos Holdings • Smyrna (TN)

On-site
USD 120,000 - 190,000
Chief Information Security Officer
Chief Information Security Officer

Jobtailor • Kentucky

On-site
USD 180,000 - 240,000
IT Director
IT Director

Continuum Powders • Houston (TX)

On-site
USD 180,000 - 280,000
Chief Information Security Officer
Chief Information Security Officer

The Security Executive Council • Chicago (IL)

On-site
USD 150,000 - 250,000
Base salary
Incentive bonus opportunities
Medical, dental, vision options
+1
Manager, Cybersecurity
Manager, Cybersecurity

Carey International Group, LLC • Orlando (FL)

On-site
USD 130,000 - 190,000
Director of IT & OT Security Operations and Governance
Director of IT & OT Security Operations and Governance

Spectraforce Technologies • Smyrna (GA)

Hybrid
USD 180,000 - 230,000
Manufacturing CISO: IT/OT Security & AI Governance
Manufacturing CISO: IT/OT Security & AI Governance

Mission Critical Group • Tempe (AZ)

On-site
USD 180,000 - 260,000
Information Security and Compliance Manager
Information Security and Compliance Manager

Transhield, Inc. • Elkhart (IN)

On-site
USD 120,000 - 180,000
Senior Director, Information Security (Relocation eligible)
Senior Director, Information Security (Relocation eligible)

Solving IT • Nashville (TN)

On-site
USD 180,000 - 260,000
Senior Manager, IT Security & Compliance / FSO
Senior Manager, IT Security & Compliance / FSO

Socket.dev • Minneapolis (MN)

On-site
USD 145,000 - 190,000
Stock options
Comprehensive medical insurance
401k plan with match
+1