Chief Information Security Office
Job Description
Weyerhaeuser is seeking a Chief Information Security Officer to lead our enterprise cyber and information security program across forests, mills, and corporate operations. This role defines security strategy, governance, and architecture while protecting critical manufacturing, OT, and cloud systems. The CISO leads risk management, incident response, and regulatory compliance, partners with executives and IT to enable secure innovation, and builds a strong security culture aligned with our safety, sustainability, and integrity values. This position offers significant influence, visibility, and impact on a sustainable manufacturing leader.
Responsibilities
-
Define and lead Weyerhaeuser's enterprise information security and cyber risk strategy across manufacturing, forestry, and corporate operations.
-
Build, mentor, and oversee a high-performing security organization, including governance, engineering, operations, and incident response teams.
-
Establish and maintain security policies, standards, and controls aligned with industry frameworks and regulatory requirements.
-
Partner with IT, OT, and business leaders to secure networks, cloud, applications, and manufacturing systems while enabling innovation.
-
Lead enterprise risk assessments, third-party risk management, and security audits; present findings and roadmap to executive leadership and the board.
-
Oversee security monitoring, vulnerability management, and incident response; direct resolution of security incidents and root-cause improvements.
-
Ensure protection of sensitive data, intellectual property, and customer information through robust identity, access, and data security controls.
-
Drive security awareness, training, and culture-building across all levels of the organization, including mills, field, and corporate teams.
-
Evaluate, select, and manage security technologies, tools, and external partners to optimize coverage and value.
-
Align security investments with business priorities and sustainability goals, tracking metrics and reporting on security posture and program maturity.
Required Skills
-
Information security strategy
-
Cybersecurity governance and risk management
-
Security operations and incident response
-
Cloud security (AWS/Azure)
-
Network and infrastructure security
-
OT/ICS security in manufacturing environments
-
Identity and access management
-
Security architecture and design
-
Regulatory compliance and audit (e.g., SOX, privacy)
-
Vendor and third-party risk management
Similar Jobs
Explore similar searches
Browse more roles related to Chief Information Security Office.