Business Information Security Officer (BISO) - Hybrid - (Must have fluency in English both Written & Verbal)

São Paulo, BRA, Brazil

FactSet

FactSet provides best-in-class financial data, global market insights and analytics, trusted by industry leaders to keep you ahead in finance.

View all jobs at FactSet

Apply now Apply later

The Business Information Security Officer (BISO) serves as a trusted security advisor to lines of business. The BISO understands security risks and technologies and is able to effectively communicate them to business units. The BISO works in tandem with the business across multiple services and platforms to address risk, while advising business leaders to ensure they are making decisions with security in mind. The BISO is an advanced role supporting the cybersecurity program. This individual provides leadership, executive support, and strategic and tactical guidance for a world-class cybersecurity program supporting enterprise security initiatives. As a business enabler, the BISO is an effective communicator with the technical aptitude to drive security fundamentals into aspects of the business. 

The BISO must be capable of working closely with senior management, third parties, project managers and business subject matter experts (SMEs). Additionally, the BISO must be personable and able to translate cybersecurity issues to business leader initiatives. The BISO must have a technical background and be able to understand technologies, their purpose, and their security requirements and data protection needs, wherever they reside. BISOs should also understand threats, as well as risk mitigations and technical controls recommended by security leaders.

Responsibilities:

  • Serve as a trusted security advisor with business unit leadership.
  • Act as a liaison to ensure cybersecurity practices are built into business unit initiatives for the entire lifecycle.
  • Act as a trusted point of contact across business units.
  • Work closely with security leadership to instill cybersecurity policies and practices throughout business units to address security operations, incident response, application security and infrastructure.
  • Be actively informed and engaged in security projects across the business.
  • Provide disaster recovery and business continuity planning advice when working with leaders for business and cybersecurity resiliency.
  • Enforce the strong security culture set forth by the CISO, ensuring uniformity across business units and employees.
  • Foster strong relationships with internal business units and excel in cybersecurity communication.
  • Advise business units on enterprise-wide people, process and technology security recommendations.
  • Maintain up-to-date knowledge related to security threats, vulnerabilities and mitigations set forth to reduce the attack surface; circulate this knowledge through the business units.
  • Ensure business projects are focused on cybersecurity from the beginning.
  • Identify and document threats and vulnerabilities that may impact the business and address them regularly with business units.
  • In conjunction with security and business leaders, define key performance indicators (KPIs) and metrics aligning with business initiatives and deliver them to non-technical teams in terms that are accessible and comprehensible.
  • Provide motivation to business units to adopt cybersecurity controls.
  • Remove complexity and obstacles that hinder efficient security controls enterprise wide.
  • Build relationships with business units to deliver security-by-design controls incorporated into projects, architecture, infrastructure and applications.
  • Stay abreast of new laws, regulations and standards, and assess their impact to the business.
  • Verify security content training initiatives and internal/external communication are conducted regularly.
  • Openly support the CISO, management team and executive leadership, even during tumultuous times.
  • Perform other duties as assigned.

Minimum Requirements:

  • 15+ years of relevant Cybersecurity experience with minimum 5 years as Cybersecurity Architect or Lead Engineer
  • Must have fluency in English both written & verbal

Critical Skills:

  • Experience collaborating with IT teams to implement technology solutions that enable business initiatives and reduce risk
  • Knowledge of relevant enterprise architecture methodology.
  • Ability to determine key security requirements by evaluating business strategies and requirements; researching information security standards; conducting system security and vulnerability analyses and risk assessments; studying architecture/platform; and identifying integration issues
  • Knowledge of relevant Cloud architecture standards, methodology, and technology
  • Expert knowledge of security issues, techniques and implications
  • Advanced knowledge of common systems, software and web application vulnerabilities (e.g., OWASP Top 10)
  • Must have fluency in English both written & verbal
  • Experience performing Root Cause Analysis (RCA) for control failures and advising IT Management with risk treatment plans
  • Experience mentoring Cybersecurity and IT team members

Additional Skills:

  • Capable of working with diverse teams and promoting an enterprise-wide positive security mindset/culture.
  • Adept at understanding business focus and processes and ability to inject cybersecurity into the business through teamwork and influence.
  • Ability to translate design into bill of materials and prepare cost estimates.
  • Experience with risk assessments of new product development as well as externally purchased applications and cloud services
  • General understanding of project management best practices
  • Ability to translate technical designs into bill of materials for procurement, collaborate with procurement team, draft Request for Quote/Purchase/Information (RFQ/RFP/RFI), and manage vendor relationships,
  • Familiarity of SSDLC (Secure Software Development Life Cycle) or SDL (Secure Development Lifecycle)
  • Experience assisting with third-party risk assessments and security control design validation
  • Able to deliver quality results in a high-energy/high-pressure environment
  • Ability to multi-task and manage demands of many projects, issues, and tasks.
  • Ability to perform duties with minimal supervision
  • Excellent interpersonal and teamwork skills
  • Excellent communications skills, both verbal and written
  • Experience performing research and communicating findings to technical and non-technical audience
  • Ability to credibly speak with clients regarding requests for information, integration, risk management, and compliance
  • Experience technically leading and influencing teams without depending on management authority

Education:

  • Bachelor’s degree in information Cybersecurity, Cybersecurity Assurance, Computer Science or related fields
  • Relevant certifications preferred include CISSP, CISM, GSEC, etc.

Required: Must have fluency in English both written & verbal

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: Application security BISO CISM CISO CISSP Cloud Compliance Computer Science GSEC Incident response KPIs OWASP RFPs Risk assessment Risk management SDLC SSDLC Vulnerabilities

Region: South America
Country: Brazil

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.