Delrin® Job Description
Chief Information Security Officer
Job Description:
The Chief Information Security Officer (CISO) is responsible for overseeing the information security needs of the company. You will develop and oversee a comprehensive information security strategy that protects the company from all internal and external threats, while ensuring that the company adheres to all applicable cyber security regulatory, contractual, customer, and audit requirements. You will be required to stay up-to-date on emerging threats and security technologies and partner with the IT, OT, Legal, Compliance, Internal Audit, and business organizations to implement modern cyber security solutions.
In addition, the CISO will own the company’s cyber security incident response program and prepares the company for potential cyber-attacks through documented response plans, testing, training, and executive tabletop exercises. The CISO is accountable for cyber security strategy, governance, risk management, policies, standards, and oversight. IT (Information Technology), OT (Operational Technology), application, data, and business teams remain responsible for operating their respective systems and implementing security controls in accordance with the company’s cyber security requirements.
Key Responsibilities:
- Develop and implement a comprehensive information security strategy aligned with the company’s business objectives, risk tolerance, and IT and OT priorities.
- Establish and maintain a global cyber security governance framework covering IT, OT, cloud, network, application, identity, endpoint, and data security.
- Ensure that IT and OT security controls adhere to applicable regulatory, contractual, customer, audit, and company requirements.
- Own the company’s cyber security risk management program and risk register, including risk identification, treatment, acceptance, remediation, and regular executive reporting.
- Own and maintain the company’s cyber security incident response program, including preparation, escalation, communication, investigation, containment, recovery, corrective action, tabletop exercises, and periodic testing.
- Oversee continuous security monitoring, threat detection, vulnerability management, incident triage, and remediation through internal teams, IT and OT organizations, and managed security service providers.
- Develop security architecture requirements, policies, standards, and control objectives for IT and OT systems in partnership with IT Infrastructure, Enterprise Applications, Data and Analytics, site OT leadership, and other technology stakeholders.
- Provide cyber security governance and guidance for network segmentation, remote access, identity and access management, cloud services, endpoints, applications, data protection, backup protection, and industrial control environments.
- Partner with IT Operations, application teams, and site OT teams to ensure security controls are implemented, maintained, monitored, and continuously improved within the systems and networks they operate.
- Create, implement, maintain, and enforce IT and OT security policies, protocols, standards, procedures, responsibilities, decision rights, and escalation paths.
- Manage IT security personnel and oversee managed security service providers, Security Operations Center services, security vendors, and other external providers, including performance, escalation, control effectiveness, and continuous improvement.
- Lead cyber security audit, assessment, and evidence coordination activities, including regulatory audits, IT general controls audits, customer security assessments, internal assessments, external inquiries, and remediation tracking.
- Establish and oversee third-party cyber security risk management, including due diligence, risk assessments, contractual requirements, ongoing monitoring, vendor negotiations, and remediation.
- Develop and oversee the company’s cyber security awareness and training program, including phishing awareness, employee and contractor training, completion metrics, and education for higher-risk roles.
- Develop and manage the cyber security budget, resource plans, investment priorities, metrics, and key risk indicators, and communicate security posture, emerging threats, costs, business value, and risk reduction to executive leadership and appropriate governance bodies.
Ideal Profile:
- A bachelor's degree in computer science, information technology, cyber security, risk management, or a related field. An MBA or relevant advanced degree is preferable.
- A minimum of nine years' experience in risk management, information security, cyber security, IT, OT security, or a related field, including leadership experience.
- Knowledge of information security management frameworks, such as ISO/IEC 27001 and NIST.
- Experience developing enterprise cyber security strategies, governance frameworks, policies, standards, risk registers, and incident response programs.
- Experience working with IT and OT organizations in a manufacturing or industrial environment.
- Experience overseeing Security Operations Center services, managed security service providers, incident response, vulnerability management, and security remediation.
- Experience supporting regulatory, customer, internal, and external cyber security audits and assessments.
- Experience with third-party cyber security risk management, customer security assurance, and cyber security contractual requirements.
- Outstanding negotiation skills for negotiating contracts and security support services to be rendered.
- Excellent understanding of current legislation, regulations, contractual obligations, and industry requirements relevant to our organization.
- Excellent project management, risk management, and leadership skills.
- Ability to communicate technical cyber security risks in business terms and clearly explain costs, value, risk reduction, and recommended actions to executive leadership.
- First-rate written and verbal communication skills.
- Based in Wilmington, DE or remote in other locations
We offer:
- An exciting opportunity to make an impact in a dynamic and growth-oriented company.
- A competitive remuneration package, including generous benefits.
Our culture is grounded on the foundations of Stewardship, People, Growth, and Excellence, guiding us as we engineer a better future, together.
- Stewardship - We embrace stewardship, upholding the safety and wellbeing of our people, our customers and our communities.
- People - We empower our people, fostering a culture of respect, empowerment and continuous development.
- Growth - We focus on growth, embracing innovation and adaptability to expand possibilities for our customers and our business.
- Excellence - We drive excellence, achieving superior results through agile execution and advanced solutions.