Business Information Security Officer
Core
Acts as the primary liaison between Information Security and business units to align security strategies with business goals, manage risk, and ensure regulatory compliance within the Private Client Group.
Role type
Business Information Security Officer (BISO)
Builds
Security-aligned business strategies, compliance frameworks, and risk mitigation plans for the Private Client Group
Domain
Financial Services / Information Security
Required skills
Risk assessment, regulatory compliance (GLBA, SOX, FFIEC), incident management, policy development, stakeholder engagement, audit coordination, disaster recovery planning, secure SDLC, identity and access management
Preferred skills
Financial services experience, CISSP/CISM/CISA/CRISC certifications, ITIL/ISO 27001/CoBIT knowledge, vulnerability assessment, penetration testing, third-party risk assessment
Technologies
Windows, UNIX, SQL, Tandem, ITIL, ISO 17799, CoBit
Responsibilities
Articulate security perspectives to business leaders, counsel units on regulatory compliance, represent business in policy development, manage internal audits, report on security risk posture, investigate security incidents, design disaster recovery plans, and support digital strategy formulation
Seniority
Mid-level, hands-on IC
