- Salary
- $137k – $229k
- Location
- Waltham, MA, United States of America
- Workplace
- Remote
- Type
- Full-time
- Department
- Administration
- Seniority
- Senior
- Education
- Bachelor
- Closing date
- Today
- Source
- Workday
Description
PURPOSE AND SCOPE:
The Business Information Security Officer (BISO) works closely with the information security teams and business units' leadership to ensure cybersecurity and privacy are seamlessly integrated into daily operations. This role provides expert guidance on risk management, drives the implementation of by-design security and privacy controls, and serves as the primary link between business and functions. We’re looking for someone who combines strong strategic thinking with hands-on execution and can operate as a self-starter who fostering a culture of security awareness, supports compliance initiatives, and ensures security practices align with the organization’s overall business strategy.
The right candidate must have excellent engagement and communication skills and must have a strong customer-focused, team-oriented, approach that balances security needs and user experience to provide best-in-class security to the organization with subject matter expertise in enterprise security architecture governance and industry standard cyber security frameworks, cloud computing, and cloud architecture.
PRINCIPAL DUTIES AND RESPONSIBILITIES:
Ensure that the organization's information assets are protected against unauthorized access, theft, damage, and disruption.
Responsible for implementing and maintaining a segment-wide information security strategy aligned to the enterprise strategy.
Engage regularly with ITS Business Partners to align business strategy and cybersecurity & privacy strategy.
Provide business segment support in navigating cybersecurity and privacy assessments.
Contribute to the ongoing information security initiatives and improvements in development, implementation and maintenance of information security.
Work closely with engineering, operations, and security specialists to ensure adequate data security solutions and controls are in place throughout all systems and platforms to mitigate identified risks sufficiently, and to meet business objectives and regulatory requirements.
Assess and understand the organization’s current security posture and future architecture requirements, providing recommendations for improvement and risk reduction.
Provides guidance and advocacy regarding the prioritization of investments that impact information security.
Supports the implementation of technical artifacts (frameworks, standards, and repeatable patterns, etc.) that constitute the enterprise information security architecture and solutions and work with infrastructure teams to ensure adoption.
Contribute the creation of security policies, access controls, and authentication mechanisms based on data security and protection principles.
Manage the tactical execution of short- and long-term objectives through the coordination of activities with a direct responsibility for results, including costs, methods, and staffing.
PHYSICAL DEMANDS AND WORKING CONDITIONS:
The physical demands and work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
SUPERVISION:
None
EDUCATION:
Bachelor's degree in management information systems, Computer Science, or business/science related field required.
EXPERIENCE AND REQUIRED SKILLS:
6-10 years of experience working with internal/external audits or risk management - methods and techniques for the assessment and management of risk.
Exceptional executive presentation and communication skills
Ability to be comfortable delivering messages across a wide spectrum of individuals having varying degrees of technical understanding
Strong leadership skills and qualities which enable you to work with peers and various levels of management
Strong understanding of network architecture, protocols, and security technologies.
Familiarity with cloud computing platforms, such as AWS, Azure, or Google Cloud, and their associated security services.
Proficiency in security frameworks and standards, such as ISO 27001, NIST, and CIS.
Ability to operate as a proactive and result-driven problem solver with excellent analytical and interpersonal skills.
Ability to understand business processes, management objectives of risk appetite and tolerances and impact of objectives, of changes to risk profiles.
CISA, CISSP, CRISC, or other relevant certification(s) are desired.
Strong client services orientation and communication skills coupled with a high sense of urgency to keep appropriate partners informed, including solutions to overcome obstacles to deliver to expectation.
Experience in IT governance, risk, and controls, including governance frameworks.
Demonstrated writing, communication, and presentation skills.
Ability to work effectively in a team environment.
Creativity in addressing technical challenges.
Proven record to deliver results while working in a mixed matrix environment
The rate of pay for this position will depend on the successful candidate’s work location and qualifications, including relevant education, work experience, skills, and competencies.
Annual Rate: $137,000.00 - $229,000.00
Non-Bonus Eligible Positions: include language below.
Benefit Overview: This position offers a comprehensive benefits package including medical, dental, and vision insurance, a 401(k) with company match, paid time off, parental leave.
Bonus Eligible Positions – include language below.
Benefit Overview: This position offers a comprehensive benefits package including medical, dental, and vision insurance, a 401(k) with company match, paid time off, parental leave and potential for performance-based bonuses depending on company and individual performance.