Enterprise Security BISO - Director

New Yesterday

Job Title: Enterprise Security BISO - Director (IC)
Location: California – San Francisco, Indiana - Indianapolis, Virginia - McLean, Washington - Seattle, New York - New York, Texas - Dallas
About the Role The Business Information Security Officer - Director role is part of our Enterprise Security Team. This role will act as a pivotal liaison between the Enterprise Security team and technology business units, ensuring alignment of security controls, policies, and strategies with organizational goals. As an individual contributor, the BISO will drive security initiatives, ensure foundational control compliance, influence strategic investment opportunities and policy changes, and provide strategic guidance to their assigned business units.
Responsibilities
Strategic Security Alignment: Partner with business units to integrate cybersecurity strategies into business processes, ensuring alignment with organizational objectives and risk tolerance.
Risk Management and Compliance: Conduct risk assessments, identify control gaps, and develop mitigation strategies in alignment with industry standards.
Security Architecture Oversight: Provide technical guidance on secure development patterns. For example, basic understanding of firewalls, intrusion detection/prevention systems (IDS/IPS), endpoint detection and response (EDR), and security information and event management (SIEM) systems.
Policy Development and Governance: Refine, and enforce security policies, standards, and procedures, which are applicable to the enterprise environment, ensuring compliance with regulations and emerging risks.
Strategic Security Risk Prioritization: Lead the coordination of security remediation efforts for business units, through a risk register which helps prioritize all work (bugs, transformational initiatives, compliance findings, etc).
Stakeholder Relationship Management: Build and maintain strong relationships with business leaders, IT teams, and external partners to foster a culture of security awareness and collaboration. Influence leadership when strategic investments are needed.
Security Awareness and Training: Develop and deliver tailored security awareness programs for business units, promoting best practices in areas such as phishing prevention and secure data handling, when needed.
Metrics and Reporting: Develop and present key performance indicators (KPIs) and key risk indicators (KRIs) to senior leadership, providing insights into the organization’s security posture.
Minimum Qualifications
Education: Bachelor’s degree in Computer Science, Information Security, or a related field;
Experience:
10+ years in cybersecurity, with at least 5 years in a senior-level role focusing on business-aligned security strategy.
Proven experience as an individual contributor in a high-impact, director-level role within a complex enterprise environment.
Deep technical expertise in understanding security principles across the corresponding infrastructure, including cloud security (AWS, Azure, GCP), network security, encryption protocols (e.g., TLS, AES), and identity and access management (IAM) solutions.
Proven understanding of security and compliance frameworks (e.g. NIST CSF, ISO 270001/2, etc).
Technical Skills:
Proficiency with security tools such as SIEM (e.g., Splunk, QRadar), EDR (e.g., CrowdStrike, SentinelOne), and vulnerability management platforms (e.g., Qualys, Tenable).
Strong understanding of secure software development lifecycle (SDLC) and DevSecOps practices.
Experience with zero trust architecture and multi-factor authentication (MFA) implementations.
Process and Relationship Skills:
Exceptional ability to translate complex technical concepts into business-friendly language for non-technical stakeholders.
Strong project management skills, with experience leading cross-functional initiatives.
Proven track record of building trusted relationships with C-suite executives, business unit leaders, and technical teams.
Proven experience influencing stakeholders to invest in strategic security initiatives to buy down risk.
Excellent communication and presentation skills, with the ability to influence and drive consensus across diverse groups.
Industry Knowledge: Deep understanding of current cybersecurity trends, threat landscapes, and regulatory requirements specific to the technology industry.
Preferred Qualifications
Certifications: CISSP, CISM, CRISC, CISA, or equivalent certifications are highly desirable.
Strategic thinker with a proactive, risk-based approach to cybersecurity.
Ability to work independently, prioritize tasks, and deliver results in a fast-paced environment.
Strong problem-solving skills and a passion for staying ahead of evolving cyber threats.
Experience in a regulated industry with a focus on compliance and governance.
Experience managing risk across AI and SaaS ecosystems.
#J-18808-Ljbffr
Location:
United States
Salary:
$250,000 +
Category:
IT & Technology