Chief Information Security Officer
Johns ManvilleAbout the role
Who We Are
Johns Manville is a leading manufacturer and marketer of premium-quality insulation and commercial roofing, along with glass fibers and nonwovens for commercial, industrial and residential applications. Our products are used in a wide variety of industries including building products, aerospace, automotive and transportation, filtration, commercial interiors, waterproofing and wind energy.
A proud member of the Berkshire Hathaway family of companies, we serve customers in more than 80 countries around the globe. We are committed to delivering positive and powerful experiences, because we are successful only when our employees and customers thrive. We are passionate, we care about people, we perform at a superior level, and we protect others and our environments.
The Chief Information Security Officer (CISO) is responsible for the design, implementation, and management of the global information security program in alignment with JM business objectives. The role is a mix of hands-on engagement and leadership. The CISO establishes the standards, practices, and controls to ensure the information security program protects company data and assets and follows required compliance, regulations, and parent company expectations. Scope of the role includes management of corporate and industrial cyber security, cyber threat intelligence, corporate and industrial voice and data networks and data protection. The position reports to the Chief Information Officer (CIO) and chairs the JM Information Security Council. CISO is responsible for informing leadership of risks, mitigations, and readiness as well as building awareness of cyber security within the organization.
Applicants can expect to make between $200,000 to $250,000 upon hire. In addition, this position is eligible for a target incentive bonus under our variable incentive plan, as well as to participate in our long-term incentive program. Pay within this range will vary based upon relevant experience, skills, and education among other factors.
Responsibilities:
Security Strategy:
- Directs the assessment, mitigation, and actions to reduce cyber security risks for corporate and industrial assets and data
- Establishes and maintains information security policy and standards
- Directs the reviews and processing cyber intelligence.
- Reviews all information security plans across enterprise to ensure alignment with business requirements, JM policies, and standards.
- Facilitates continuous risk assessment, analysis, and mitigation activities.
- Maintains current knowledge of technical security services and mechanisms and monitors advancements in information security and emerging technologies to manage risks and ensure compliance.
- Actively participates in the external information security communities and parent company Cyber Security Council to foster effective communications, knowledge sharing, and best practices.
Security Governance:
- Organizes and facilitates the Information Security Council meeting to review, align and approve appropriate information security policies, practices, standards, resources, and controls.
- Maintain process to safeguard and verify the safety, confidentiality, integrity, and availability of business and industrial systems and data.
- Facilitates development and application of data loss prevention standards
- Support internal and external audits, coordinate IT audit responses, and track observations to closure. Proactively report issues and challenges to timely completion of audit actions.
- Ensures testing and verification of changes to reduce likelihood of repeat findings from internal or external audits.
- Manage AI Governance group responsible for the evaluation of operational, cyber and data risks of AI and the required people, process, and technical controls.
- Conduct related ongoing compliance monitoring activities in coordination with JM's other compliance and operational assessment functions.
- In coordination with Legal and designated personnel, is responsible for supporting JM's compliance with data privacy laws.
Security Awareness and Advocacy:
- Initiate, facilitate and promote activities to foster information security awareness at corporate, service and manufacturing locations.
- Demonstrates visible leadership across the organization to identify, report and resolve cyber risks
- Communicate and maintain list of approved uses of tools and technology that meet JM standards
Security Operations:
- Responsible for the design, operations, and improvements to security infrastructure of the organization and key security initiatives, tools, and standards, (e.g., virus protection, security monitoring, intrusion detection, l
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Supervisory Criminal Investigator (Branch Chief)
Bureau of Alcohol, Tobacco, Firearms and Explosives
$192,275/yr
Chief of Staff
Federal Maritime Commission
$228,000/yr
Canteen Chief - Kerrville TX
Veterans Health Administration
$56,706/yr