Chief Information Security Officer
AlcoaAbout the role
Shape Your World
At Alcoa, you will become an essential part of our purpose: to turn raw potential into real progress. The way we see it, every Alcoan is a work-shaper, team-shaper, idea-shaper, world-shaper.
We are seeking a visionary strategic Chief Information Security Officer who is passionate about leveraging cybersecurity to protect and enhance our sustainable manufacturing processes, supporting our innovation journey to create a more sustainable world.
The CISO will be responsible for driving the information security strategy and operations for Alcoa. This includes defining security requirements and development of technology roadmaps aligned to best practices/regulatory requirements and business objectives of Alcoa, with an emphasis on risk management.
The role will have direct responsibility for a global team that supports the broader organist objectives while effectively working with business and technology teams to identify, assess and address key information and cyber risks and threats.
A key element of the CISO role is to provide comprehensive and credible manner to the company leaders and board providing insight of all areas of cyber security to ensure our corporate and manufacturing assets are adequately protected. The CISO must be able to understand and articulate the value levers and (positive/negative) impact of cyber on the business communicating to senior stakeholders inclusive of the board.
The CISO must be knowledgeable with proven experience in a leadership role working with risk and audit teams as well as 3rd party vendors having an entrepreneurial and creative approach to develop innovative ideas. Should ensure that information systems are maintained in a fully functional and secure mode and are compliant with legal, regulatory, and contractual obligations. He or she serves as the process owner of the appropriate second-line assurance activities not only related to authenticity, but also to the safety, privacy and recovery of information owned or processed by the business in compliance with regulatory requirements. The CISO understands that securing information assets and associated technology, applications, systems, and processes in the wider ecosystem in which the organization operates is as important as protecting information within the organization's perimeter.
Major activities/Key challenges
Establish Governance and Build Knowledge
- Facilitates an information security governance structure leading the information security steering committee or advisory board.
- Provides regular reporting on the current status of the information security program to enterprise risk teams, senior business leaders and the board of directors as part of a strategic enterprise risk management program, thus supporting business outcomes.
- Develops, socializes, and coordinates approval and implementation of security policies.
- Works with the procurement to ensure that information security requirements are included in contracts by liaising with vendor management.
- Directs the creation of a targeted information security awareness training program for all employees, contractors, and approved system users, and establishes metrics to measure the effectiveness of this security training program for the different audiences.
- Understands and interacts with related disciplines, either directly or through committees, to ensure the consistent application of policies and standards across all technology projects, systems, and services, including privacy, risk management, compliance and business continuity management.
- Provides clear risk mitigating directives for projects with components in IT, including the mandatory application of controls.
- Embeds Cyber Judgement across a decentralized or distributed decision-making model.
Lead the Organization
- Leads the information security function across the company to ensure consistent and high-quality information security management in support of the business goals.
- Determines the information security approach and operating model in consultation with stakeholders and aligned with the risk management approach and compliance monitoring.
- Manages the budget for the information security function (opex and capex), monitoring forecasts.
- Manages the cost-efficient information security organization. This includes hiring (and conducting background checks), training, staff development, performance management and annual performance reviews.
- Continue to reorganize the security team addressing gaps. Facilitate and enable training and upskilling.
Set the Strategy
- Define a clear medium-long term roadmap to continue to enhance and protect Operational Technology (OT) in manufacturing environment that is essential for maintain business operations and avoiding
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s