Deputy Chief Information Security Officer (Deputy CISO)

Howmet Aerospace
Pittsburgh, PA

The Deputy Chief Information Security Officer serves as a senior leader within the Global Cybersecurity Organization, responsible for driving enterprisewide security strategy, governance, and operational resilience across a complex, highly regulated aerospace manufacturing environment. This role reports directly to the CISO and partners to safeguard intellectual property, protect critical manufacturing systems, ensure compliance with international defense and export regulations, and strengthen the companys global cyber defense posture.

The Deputy CISO acts as the CISO’s primary delegate, overseeing daytoday security operations, leading crossfunctional security initiatives, and assists with representing the cybersecurity function with internal and external stakeholders.

 

Key Responsibilities

Strategic Leadership & Governance

  • Support the CISO in developing and executing the global cybersecurity strategy aligned to business, engineering, and manufacturing priorities.
    • Lead enterprise security governance, risk management, and compliance programs across multiple regions and regulatory environments.
    • Drive adoption of security frameworks such as NIST 800‑171, NIST CSF, ISO 27001, CMMC, NIS2 and aerospace/defensespecific requirements (e.g., ITAR, DFARS, EAR).
    • Serve as acting CISO when required, including executive briefings, board presentations, and crisis leadership.

Cyber Defense & Operations

  • Partner with CISO to oversee global Security Operations Center (SOC), threat intelligence, incident response, and digital forensics capabilities, cyber investigations, Data Loss Preventions and cyber architecture and maintain cybersecurity regulatory/legal requirements.
    • Ensure rapid detection, containment, and remediation of cyber threats targeting manufacturing systems, OT/ICS environments, R&D networks, and supply chain partners.
    • Lead development of advanced defense capabilities including zero trust architecture, identity security, and endpoint/OT protection.

Risk Management & Compliance

  • Direct enterprise cyber risk assessments, supplier security evaluations, tabletop and penetration testing  and compliance audits across global operations.
    • Partner with Legal, Compliance, Information Technology, and Export Control teams to ensure adherence to aerospace and defense regulatory requirements.
    • Oversee thirdparty risk management, ensuring secure collaboration with suppliers, contractors, and jointventure partners.

Product, Engineering & OT Security

  • Collaborate with engineering and manufacturing leaders to embed security into product design, avionics systems, and industrial control systems.
    • Lead security programs for factory automation, robotics, additive manufacturing, and other advanced aerospace production technologies.
    • Ensure secure integration of IT/OT systems and protection of proprietary aerospace designs and intellectual property.

Leadership & Stakeholder Engagement

  • Mentor and develop global cybersecurity leaders and technical teams.
  • Build strong partnerships with business units, engineering, operations, and executive leadership.
  • Represent the cybersecurity function with regulators, government agencies, defense customers, and industry partners.

Key Competencies

  • Experience reporting to the Board of Directors
  • Strategic thinking and enterprise‑level decision‑making
  • Strong communication and executive presence
  • Crisis leadership and resilience
  • Technical depth across IT, OT, cloud, and product security
  • Ability to balance security, innovation, and operational continuity
  • High integrity and commitment to protecting sensitive aerospace data
// // //