Role Purpose The Deputy CISO serves as the principal technical and operational leader for enterprise cybersecurity and acts as the designated second-in-command to the CISO.
This role is accountable for defining, implementing, governing, and continuously improving cybersecurity programs across IT, Operational Technology (OT), manufacturing plants, engineering environments, cloud platforms, product development ecosystems, and global business operations.
A key responsibility of this role is to establish and sustain a globally standardized OT cybersecurity program across multi-country manufacturing operations, ensuring protection of production environments, industrial control systems, connected factories, engineering assets, and critical business services from cyber threats that could impact safety, quality, production continuity, customer commitments, and corporate reputation.
The Deputy CISO must possess deep hands-on experience implementing OT cybersecurity across large manufacturing enterprises with multiple plants globally and be capable of operating at both executive and technical levels.
________________________________________
Key Leadership Expectations The Deputy CISO shall:
Drive cybersecurity strategy execution globally
Own OT cybersecurity as a strategic pillar
Be the technical escalation point for complex cyber risks
Lead global security architecture decisions
Govern MSSPs and security service providers
Sustain ISO 27001 and global compliance programs
Lead cyber resilience and incident response programs
Drive cybersecurity integration for acquisitions and recent factories
Influence board-level cybersecurity decisions
________________________________________
OT Cybersecurity Leadership (Primary Responsibility)
Global OT Security Strategy
Lead design and implementation of a unified OT Cybersecurity Program covering:
Manufacturing plants
Industrial facilities
Warehouses
Utilities
Engineering centers
Connected production environments
Develop OT cybersecurity roadmap aligned to:
IEC 62443
NIST 800-82
NIST CSF
ISO 27001
Industry customer requirements
________________________________________
Multi-Plant OT Cybersecurity Implementation
Must possess proven experience in:
Implementing OT security across 10+ manufacturing sites.
Leading global OT security transformation programs.
Standardizing cybersecurity controls across diverse plant environments.
Managing cybersecurity in brownfield and greenfield plant environments.
Integrating acquired manufacturing facilities into a common cyber baseline.
________________________________________
Industrial Control System (ICS) Security
Strong hands-on expertise required in:
PLC Security
DCS Security
SCADA Security
MES Security
Historian Security
Batch Management Systems
HMI Security
Industrial IoT Security
Robotics Security
Connected Factory Security
Experience with
Siemens
Rockwell
Schneider
ABB
Yokogawa
Honeywell
Emerson industrial environments preferred.
________________________________________
OT Network Security
Design and govern:
Purdue Architecture
ISA/IEC 62443 Zones and Conduits
Industrial DMZ
IT/OT Segmentation
Industrial Firewalls
NAC
Secure Remote Access
Vendor Access Control
Production Network Monitoring
Must be capable of independently reviewing and approving plant security architectures.
________________________________________
OT Threat Monitoring & Incident Response
Lead deployment of:
OT SOC
ICS Threat Monitoring
Passive Asset Discovery
Industrial IDS/IPS
OT SIEM Integration
Experience handling
Production-impacting incidents
Industrial ransomware incidents
Plant network compromises
Vendor-originated threats
Safety-related cyber events
________________________________________
OT Risk & Vulnerability Management
Responsible for:
Asset Criticality Models
OT Risk Assessments
Vulnerability Prioritization
Compensating Controls
Patch Governance
Legacy Platform Protection
Must understand challenges associated with:
Unsupported operating systems
End-of-life equipment
Vendor constraints
Production shutdown limitations
________________________________________
Cyber Defense & Security Operations
Executive ownership of:
SOC
SIEM
XDR
SOAR
Threat Intelligence
Threat Hunting
Must possess expertise in:
MITRE ATT&CK;
Detection Engineering
Adversary Emulation
Incident Command
Ability to independently lead enterprise cyber crises.
________________________________________
Security Architecture & Engineering
Provide technical oversight for
Identity Security
Entra ID
Active Directory
PAM
PIM
Conditional Access
ITDR
Endpoint Security
CrowdStrike
Defender
EDR/XDR Technologies
Network Security
Palo Alto
Zscaler
SASE
ZTNA
CASB
Cloud Security
Azure
AWS
CSPM
CWPP
SaaS Security
Data Security
DLP
DSPM
Data Classification
Encryption
Privacy Controls
AI Security
Secure Copilot Adoption
AI Governance
AI Risk Management
LLM Security
AI Data Protection
________________________________________
Global Governance, Compliance & Risk
Own enterprise-wide execution of:
Standards & Certifications
ISO 27001
IEC 62443
ISO 22301
TISAX
Regulatory Compliance
DPDP Act
GDPR
NIS2
Customer Security Requirements
Responsibilities include
ISMS sustenance
Surveillance audits
Certification audits
Risk treatment governance
Executive reporting
________________________________________
MSSP & Global Vendor Governance
Lead governance of:
SOC Providers
MDR Providers
OT Security Partners
Vulnerability Management Partners
Audit Partners
Key accountability
SLA management
Service effectiveness
Technical assurance reviews
Security metrics
Global service standardization
Must be capable of challenging security vendor recommendations from a technical and architectural standpoint.
________________________________________
Cyber Resilience & Recovery
Lead:
Enterprise Cyber Recovery Program
OT Disaster Recovery
Ransomware Preparedness
Cyber Crisis Management
Ensure
Recovery testing
Immutable backup controls
Plant recovery exercises
Executive tabletop simulations
________________________________________
Experience Requirements
Mandatory
18+ years in Cybersecurity.
10+ years in Cybersecurity Leadership.
5+ years dedicated OT Cybersecurity leadership experience.
Hands-on implementation of OT security in large manufacturing enterprises.