Chief Information Security Officer
Coda Search│Staffing · Dallas-Fort Worth Metroplex
Apply & track with Apply EdgeChief Information Security Officer (CISO)Global Manufacturing OrganizationWe have been retained by a large, global manufacturing organization to identify its next Chief Information Security Officer (CISO).This is an opportunity to lead cybersecurity for a complex global enterprise with a significant manufacturing footprint. The organization has a strong security foundation, an established global team, and mature operational security capabilities. The mandate for the next CISO is not to rebuild a broken security organization. It is to determine what comes next.Reporting to the CIO and working closely with the Executive Leadership Team and Board, the CISO will develop the forward-looking cybersecurity strategy that supports business growth, global manufacturing operations, digital transformation, and the rapidly changing impact of AI.The OpportunityThe CISO will inherit a global security organization of approximately 25 professionals, including five direct reports, with several security capabilities supported by strategic vendor partners.During the first 12–18 months, the CISO will be expected to:Develop a deep understanding of the business, global manufacturing operations, technology environment, and enterprise risk profile.Build strong relationships with the CIO, Executive Leadership Team, Board, Manufacturing, Engineering, and business leadership.Assess the current cybersecurity environment and develop a multi-year cybersecurity roadmap aligned with business priorities and growth.Advance the organization's AI security strategy across both internal AI adoption and external AI-enabled threats.Strengthen cybersecurity across global manufacturing and OT environments.Continue evolving cybersecurity governance, regulatory readiness, privacy, compliance, and enterprise risk management.Establish meaningful cyber risk and resilience metrics that demonstrate business risk reduction and support executive decision-making.IT/OT & Process Manufacturing CybersecurityIT/OT cybersecurity is one of the most important components of this role.We are particularly interested in leaders who have operated within process manufacturing environments such as chemicals, specialty materials, energy, oil & gas, refining, pharmaceuticals, industrial gases, food & beverage, or similarly complex operations.The CISO will establish and evolve the cybersecurity strategy across operational technology, industrial control systems, process control environments, manufacturing networks, plant connectivity, and cyber-physical risk.This includes:OT/ICS cybersecurity strategyProcess control and manufacturing environmentsIT/OT convergenceOT segmentation and access controlsAsset visibility and vulnerability managementManufacturing execution and connected plant environmentsIndustrial IoTRemote and third-party accessPlant modernizationIncident response and cyber recoveryCyber-physical riskThe successful leader must understand that cybersecurity in a manufacturing environment cannot exist independently of safety, reliability, uptime, productivity, and business operations.AI Security & StrategyAI represents both a significant business opportunity and a rapidly evolving cybersecurity challenge. The CISO will help define the enterprise security strategy surrounding the organization's adoption of AI, including generative AI, agentic AI, machine learning, copilots, and AI-enabled business workflows. Internally, this leader will build upon an existing secure-by-design approach, establishing appropriate security guardrails around AI systems, data, access, identity, monitoring, third-party usage, and emerging non-human and AI agent identities.Externally, the CISO will prepare the organization for AI-enabled threats including:AI-enabled phishing and social engineeringDeepfakes and synthetic identitiesAutomated exploitationModel manipulationPrompt injectionData leakageAI-accelerated attacks and emerging threat vectorsWe are looking for someone who can think beyond today's controls and help answer:What does cybersecurity need to look like three to five years from now as AI changes both the business and the threat landscape?Enterprise Cybersecurity LeadershipWhile IT/OT and AI are strategic priorities, this is a full enterprise CISO role.The CISO will maintain executive responsibility for the broader cybersecurity program, including:Enterprise cybersecurity strategy and governanceTechnology risk managementCyber resilience and business recoveryIncident response and crisis managementIdentity and privileged access managementCloud, SaaS, ERP, application, endpoint, network, and data securitySecurity architecture and secure technology modernizationThird-party and supply-chain cyber riskVulnerability management and threat intelligenceRegulatory and public-company cybersecurity governanceData protection and privacy-aligned security controlsSecurity awareness and organizational cultureThe CISO will also continue developing the global security organization, ensuring the team has the leadership, capabilities, and skills necessary to execute the future cybersecurity roadmap.Cyber Resilience & Crisis ReadinessThe CISO will own the enterprise approach to preventing, detecting, responding to, and recovering from significant cybersecurity incidents. This includes partnering with IT, Manufacturing, Enterprise Risk, Business Continuity, Disaster Recovery, Legal, Communications, and executive leadership to establish appropriate response plans, escalation procedures, recovery priorities, tabletop exercises, and crisis-management capabilities. The goal is not simply preventing attacks. It is ensuring the business can continue operating and recover quickly when incidents occur.Business & Board LeadershipTechnical credibility is important. Business judgment is essential.The CISO must be comfortable operating with the CIO, Executive Leadership Team, and Board and translating complex cybersecurity issues into business decisions.The conversation cannot simply be:"Here is the vulnerability and the technology we need to buy."Instead, the CISO must be able to articulate:What is the risk?What is the potential business impact?What will it cost to mitigate?What risk should the organization reasonably accept?What business opportunity could be limited by eliminating the risk entirely?What investment provides the appropriate balance between risk reduction and business value?Significant cybersecurity investments and strategic decisions are made collaboratively across the IT leadership team. The CISO will be expected to bring a strong point of view, challenge assumptions, and advocate for change when there is a compelling business reason to do so. This is not an environment for a security leader whose default answer to risk is "no" or who maintains the status quo simply because it is the status quo.What We're Looking ForThe ideal candidate will bring:12+ years of progressive leadership experience across cybersecurity, technology risk, infrastructure, enterprise architecture, OT security, incident response, or related technology disciplines.Significant experience leading an enterprise-scale cybersecurity organization, ideally as the senior-most security executive.Strong IT/OT cybersecurity experience within complex manufacturing or industrial environments.Process manufacturing experience strongly preferred.Experience developing and executing enterprise cybersecurity strategy rather than simply operating an existing program.Experience owning cybersecurity transformation and being accountable for implementation and business outcomes.Strong understanding of emerging AI security risks, secure enterprise AI adoption, and AI-enabled threat vectors.Experience leading cybersecurity teams while effectively leveraging strategic vendors and managed security partners.Demonstrated Board and executive-level communication skills.Ability to translate cybersecurity into business risk, cost, operational impact, resilience, and opportunity.Experience with cyber resilience, incident response, crisis management, and business recovery.Knowledge of enterprise identity, cloud, ERP, data, application, infrastructure, and platform security.Experience with third-party and supply-chain cybersecurity risk.Experience navigating regulatory, privacy, compliance, and public-company cybersecurity governance requirements.Familiarity with established security frameworks such as NIST CSF, ISO 27001, CIS Controls, or similar frameworks.Global leadership experience, with experience supporting operations in China or broader Asia particularly valuable.Bachelor's degree in information security, computer science, engineering, business, risk management, or a related field.Professional certifications such as CISSP, CISM, CISA, CRISC, GIAC, or CCSP are preferred but are not the primary measure of fit.