Weyerhaeuser logo

Chief Information Security Office (CISO)

Salary
$238.4K–$367.2K
USD
Moves you to
United States
Support
Relocation support
Posted
Sep 30, 2026
Is this job info correct?

Job Description - Chief Information Security Office (CISO) (01025036) Job Description Chief Information Security Office (CISO) - 01025036 Description At Weyerhaeuser, our IT team is on a mission to transform the timber industry. We are industry leaders in forest products and our customers are at the heart of everything we do. We’re not just in the cloud, we’re implementing technology that will keep us at the forefront of innovation in the forest products industry. We’re using AI to create new ways of bringing exciting products to our customers and we sustainably manage forests and manufacture products that make the world a better place. We’re serious about safety, driven to achieve excellence, and we proudly invest in the communities we are part of. With multiple business lines in locations across North America, we offer a range of exciting career opportunities for smart, talented people who are passionate about making a difference. The Chief Information Security Officer (CISO), working in collaboration with Weyerhaeuser’s strategic initiatives, is an executive responsible for protecting our people, data, reputation, and manufacturing business operations by leading a business-aligned information security and cybersecurity program. This role sets the strategic direction for the security governance, risk management, incident response, third-party security, data protection, and security awareness programs. Operating as a trusted advisor to Weyerhaeuser’s executive leadership team, the CISO ensures the confidentiality, integrity, and availability of secure data while enabling innovation, responsible AI adoption and operational resilience. The CISO works closely with the business community and IT to provide objective risk oversight, policy leadership, executive reporting, and continuous improvement of Weyerhaeuser’s security posture. The CISO is responsible for creating a strategy to ensure our cybersecurity programs aligns with the company’s commitment to sustainability and operational resilience. The CISO is also responsible for identifying, evaluating and reporting on legal and regulatory, IT, and cybersecurity risk to information assets, while supporting and advancing business objectives. This role reports to the CIO who is accountable for enterprise IT, data, AI, and cyber security. Responsibilities Enterprise Cybersecurity Strategy and Leadership Develop an information security strategy that is aligned to growth initiatives, organizational priorities and enables achievement of the organization's business objectives while minimizing risks. Design, implement and manage a strategic, comprehensive information security program to ensure appropriate levels of confidentiality, integrity, availability, safety, privacy and recovery of information assets owned, controlled or/and processed by the organization. Align cybersecurity investments and priorities with enterprise risk appetite, regulatory demands, and business strategy. Serve as key advisor to Weyerhaeuser’s senior executives on cyber risk, emerging threats, and security-related business impacts. Translate technical security requirements into actionable business-focused plans across the enterprise. Monitor industry trends, threat intelligence, and emerging technologies to inform strategic direction. Risk Management, Governance and Compliance Drive the development and enforcement of enterprise-wide cybersecurity policies, standards, and frameworks. Ensure compliance with relevant legal and regulatory frameworks. Lead enterprise cybersecurity risk assessments and guide business units in risk treatment planning. Engage with internal audit, legal, finance, and compliance teams to manage regulatory obligations and audit readiness. Promote accountability and transparency through structured governance and reporting mechanisms. Security Architecture Provide leadership and strategic oversight for security engineering, infrastructure and application protection, and operations. Support adoption of secure architecture and development practices, including cloud and hybrid environments. Enhance our information security management framework based on the Institute of Standards and Technology (NIST) Cybersecurity Framework. Create and manage a unified and flexible control framework to integrate and normalize the wide variety and changing requirements resulting from global laws, standards and regulations. Develop and maintain a document framework of continuously up-to-date information security policies, standards and guidelines. Oversee the approval and publication of these information security policies and practices. Facilitate a metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitate appropriate resource allocation, and increase the maturity of the information security, and review it with stakeholders at the executive and board levels. Sits on the Architectural Counsel and ensures alignment between security and enterprise architectures ensuring that information security requirements are met and security is built in by design. Qualifications Bachelor’s degree in Information Security, Information Technology, Cybersecurity or related field Minimum of 15 years of progressive, relevant information security, cybersecurity or information technology leadership roles required 10+ years experience leading an information security team including advancing all security practices and programs Experience leading cybersecurity in a manufacturing environment including national and/or global distributed manufacturing field operation facilities is strongly preferred. Experience with Artificial Intelligence (AI) is strongly preferred Expert level skills with identity and access management, cloud security, vulnerability management, security operations and regulatory compliance required Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate information security and risk-related concepts to technical and nontechnical audiences at various hierarchical levels, ranging from board members to technical specialists Strategic leader who can effectively collaborate and communicate with and strategically influence executives and leaders across the organization in executing security methodologies, practices and policies Strong business acumen and expert level knowledge of information security risk management and cybersecurity technologies Up-to-date knowledge of methodologies and trends in manufacturing, threat intelligence (including AI) and emerging technologies Strategic critical thinker, with strong problem-solving and exceptional collaboration skills at all levels of the organization with the ability to plan, build and execute full scale security programs effectively Knowledge and understanding of relevant legal and regulatory requirements including Sarbanes-Oxley Act (SOX) Proven track record and experience in developing information security policies and procedures, as well as successfully executing programs that meet objectives in a dynamic manufacturing business environment Excellent analytical skills, the ability to manage multiple projects under strict timelines, as well as the ability to work well in a demanding, dynamic environment and meet overall objectives Project management skills: financial/budget management, scheduling and resource management Ability to communicate the vision for, lead and motivate the information security team to achieve strategic goals in alignment with business objectives and risk measures Professional security management certification preferred such as CISSP, CISM, CISA, CRISC, CCSP, HCISPP or other similar credentials Knowledge of common information security management frameworks, such as ISO/IEC 27001, ITIL, COBIT as well as those from NIST, including 800-53 and Cybersecurity Framework Demonstrated experience with contract and vendor negotiations Excellent stakeholder management skills including the ability to effectively collaborate, build trust and execute implementation of security solutions and programs across the enterprise High level of personal integrity, as well as the ability to professionally handle confidential matters and show an appropriate level of EQ, judgment and maturity High degree of initiative, dependability and ability to work autonomously while being resilient to change About Weyerhaeuser We sustainably manage forests and manufacture products that make the world a better place. We’re serious about safety, driven to achieve excellence, and proud of what we do. With multiple business lines in locations across North America, we offer a range of exciting career opportunities for smart, talented people who are passionate about making a difference. We know you have a choice in your career. We want you to choose us. What We Offer: Compensation: This role is eligible for our annual merit-increase program, and we are targeting a salary range of $238,432-$367,204 based on your level of skills, qualifications and experience. You will also be eligible for our Annual Incentive Program, which offers a cash bonus targeting 40% of base pay. Potential plan funding may range from zero to two times that target. This position is also eligible to receive $161,000 in restrictive stock units on an annual basis, as part of our Long-Term Incentive Plan. Benefits: When you join our team, you and your dependents will be offered coverage under our comprehensive employee benefits plan, which includes medical, dental, vision, short and long-term disability, and life insurance. We offer a pre-tax Health Savings Account option which includes a company contribution. Other benefit options are also available such as voluntary Long-Term Care and Employee Assistance Programs. We also support personal volunteerism, sponsor a host of diversity networks, promote mentoring, and provide training and development opportunities to help you chart your path to a fulfilling career. Retirement: Employees are able to enroll in our company’s 401k plan, which includes a paid company match in addition to our annual contribution equal to 5% of your base salary. Paid Time Off or Vacation: We provide eligible employees who are scheduled to work 25 hours or more per week with 3-weeks of paid vacation to use during your first year of employment. In addition, after being employed for six months, eligible employees begin to accrue vacation for future use. We also recognize eleven paid holidays per year, providing a total of 88 holiday hours and paid parental leave for all full-time employees. Weyerhaeuser is an equal opportunity employer. Inclusion is one of our five core values and we strive to maintain a culture where all our people feel a sense of belonging, opportunity and shared purpose. We are committed to recruiting a diverse workforce and supporting an equitable and inclusive environment that inspires people of all backgrounds to join, stay and thrive with our team. #salary Job Information Technology Primary Location USA-WA-Seattle Schedule Full-time Job Level Senior Executive Job Type Experienced Shift Day (1st) Relocation Assistance Available . Any personal information you provide is subject to the terms of our Privacy Policy California residents: Our California Privacy Notice for Job Applicants details what personal information we collect and for what purposes. Connect with us Timberlands Recreation Land Wood Products Energy Sustainability Investors Careers Company | Legal Notices

Similar jobs

Apply for this job