Chief Information Security Officer
Wolfspeed · Durham, NC · 3 wk ago
Information TechnologyFull-time
About the role
The Chief Information Security Officer (CISO) will build and lead global cybersecurity and information-assurance strategies, driving innovative protection for intellectual property, customer data, and digital assets. This leadership role requires a deep understanding of the semiconductor industry and the ability to align cybersecurity strategy with business objectives and global risk environments. The ideal candidate combines innovative thinking, strategic planning, technical expertise, and leadership to ensure a robust and resilient information-security posture.
Responsibilities
- Develop, implement, and monitor a strategic, comprehensive enterprise information-security and IT risk-management program at global scale to ensure integrity, confidentiality, and availability of information, including trade secrets, patents, and proprietary designs.
- Lead the enterprise’s information-security organization, including hiring, training, and mentoring a team of security professionals.
- Identify, evaluate, and report on information-security risks in a manner that meets executive-management and board expectations, compliance and regulatory requirements, and aligns with the enterprise’s risk posture.
- Design and implement protective measures for securing proprietary designs, patents, and other sensitive corporate information, addressing the unique risks of the semiconductor industry.
- Work directly with business units to facilitate risk assessment and risk-management processes, identifying acceptable levels of residual risk.
- Ensure cybersecurity policies align with enterprise business policies, IT policies, and the global Enterprise Risk Management framework.
- Develop and manage information-security budgets, adopting cost-effective strategies to reduce and mitigate identified risks.
- Establish and oversee a cybersecurity incident-management program covering detection, response, mitigation, and recovery.
- Align cybersecurity practices with crisis-management and incident-response strategies, including testing plans and tabletop exercises to ensure business continuity.
- Liaise with external agencies (e.g., law enforcement, advisory bodies) to maintain a strong security posture against external threats.
- Conduct regular security audits, risk assessments, support annual financial and IT audit objectives, and ensure compliance with industry standards and regulatory requirements specific to the semiconductor industry.
- Champion global cybersecurity awareness and training programs across all organizational levels.
Qualifications
- Bachelor’s or Master’s degree in Information Security, Computer Science, or related field.
- Professional security-management certification (e.g., CISSP, CISM, or similar).
- 15+ years of experience in risk management, information security, and IT, with at least 10 years in a senior leadership role.
- Experience with NIST (800-171), ISO (27001), and CMMC (Cybersecurity Maturity Model Certification) frameworks.
- Deep understanding of evolving cybersecurity threats in the semiconductor industry and experience crafting mitigation strategies.
- Knowledge of relevant legal and regulatory requirements, including export controls.
- Experience with contract and vendor negotiations, including managed services.
- Strong leadership skills and ability to collaborate with business managers, IT engineering/operations, vendors, and suppliers.
- Excellent verbal and written communication skills, including the ability to explain technical concepts to business leaders and business concepts to IT teams.