Business Information Security Officer

2 weeks ago


Andhra Pradesh, India FactSet Full time ₹ 15,00,000 - ₹ 20,00,000 per year

The Business Information Security Officer (BISO) serves as a trusted security advisor to lines of business. The BISO understands security risks and technologies and is able to effectively communicate them to business units. The BISO works in tandem with the business across multiple services and platforms to address risk, while advising business leaders to ensure they are making decisions with security in mind. The BISO is an advanced role supporting the cybersecurity program. This individual provides leadership, executive support, and strategic and tactical guidance for a world-class cybersecurity program supporting enterprise security initiatives. As a business enabler, the BISO is an effective communicator with the technical aptitude to drive security fundamentals into aspects of the business. The BISO must be capable of working closely with senior management, third parties, project managers and business subject matter experts (SMEs). Additionally, the BISO must be personable and able to translate cybersecurity issues to business leader initiatives. The BISO must have a technical background and be able to understand technologies, their purpose, and their security requirements and data protection needs, wherever they reside. BISOs should also understand threats, as well as risk mitigations and technical controls recommended by security leaders.

Job Responsibilities:

  • Serve as a trusted security advisor with business unit leadership.
  • Act as a liaison to ensure cybersecurity practices are built into business unit initiatives for the entire lifecycle.
  • Act as a trusted point of contact across business units.
  • Work closely with security leadership to instill cybersecurity policies and practices throughout business units to address security operations, incident response, application security and infrastructure.
  • Be actively informed and engaged in security projects across the business.
  • Provide disaster recovery and business continuity planning advice when working with leaders for business and cybersecurity resiliency.
  • Enforce the strong security culture set forth by the CISO, ensuring uniformity across business units and employees.
  • Foster strong relationships with internal business units and excel in cybersecurity communication.
  • Advise business units on enterprise-wide people, process and technology security recommendations.
  • Maintain up-to-date knowledge related to security threats, vulnerabilities and mitigations set forth to reduce the attack surface; circulate this knowledge through the business units.
  • Ensure business projects are focused on cybersecurity from the beginning.
  • Identify and document threats and vulnerabilities that may impact the business and address them regularly with business units.
  • In conjunction with security and business leaders, define key performance indicators (KPIs) and metrics aligning with business initiatives and deliver them to non-technical teams in terms that are accessible and comprehensible.
  • Provide motivation to business units to adopt cybersecurity controls.
  • Remove complexity and obstacles that hinder efficient security controls enterprise-wide.
  • Build relationships with business units to deliver security-by-design controls incorporated into projects, architecture, infrastructure and applications.
  • Stay abreast of new laws, regulations and standards, and assess their impact to the business.
  • Verify security content training initiatives and internal/external communication are conducted regularly.
  • Openly support the CISO, management team and executive leadership, even during tumultuous times.
  • Perform other duties as assigned.

Job Responsibilities:

  • 15+ years of relevant Cybersecurity experience with minimum 5 years as Cybersecurity Architect or Lead Engineer.
  • Bachelor's degree in Information Cybersecurity, Cybersecurity Assurance, Computer Science or related fields.
  • Relevant certifications preferred including CISSP, CISM, GSEC, etc.
  • Capable of working with diverse teams and promoting an enterprise-wide positive security mindset/culture
  • Adept at understanding business focus and processes and ability to inject cybersecurity into the business through teamwork and influence
  • Experience collaborating with IT teams to implement technology solutions that enable business initiatives and reduce risk.
  • Knowledge of a relevant enterprise architecture methodology.
  • Ability to determine key security requirements by evaluating business strategies and requirements; researching information security standards; conducting system security and vulnerability analyses and risk assessments; studying architecture/platform; and identifying integration issues.
  • Ability to translate design into bill of materials and preparing cost estimates.
  • Knowledge of a relevant Cloud architecture standards, methodology, and technology.
  • Experience with risk assessments of new product development efforts as well as externally purchased applications and cloud services.
  • Expert knowledge of security issues, techniques and implications.
  • Advanced knowledge of common system, software and web application vulnerabilities (e.g., OWASP Top 10).
  • General understanding of project management best practices.
  • Ability to translate technical designs into bill of materials for procurement, collaborate with procurement team, draft Request for Quote/Purchase/Information (RFQ/RFP/RFI), and manage vendor relationships.
  • Familiarity of SSDLC (Secure Software Development Life Cycle) or SDL (Secure Development Lifecycle).
  • Experience assisting with third-party risk assessments and security control design validation.
  • Experience performing Root Cause Analysis (RCA) for control failures and advising IT Management with risk treatment plans.
  • Able to deliver quality results in a high-energy/high-pressure environment.
  • Ability to multi-task and manage demands of many projects, issues, and tasks.
  • Ability to perform duties with minimal supervision.
  • Excellent interpersonal and teamwork skills.
  • Excellent communications skills, both verbal and written.
  • Experience performing research and communicating findings to technical and non-technical audience.
  • Ability to credibly speak with clients regarding requests for information, integration, risk management, and compliance.
  • Experience technically leading and influencing teams without depending on management authority.
  • Experience mentoring Cybersecurity and IT team members.

Diversity:

At FactSet, we celebrate diversity of thought, experience, and perspective. We are committed to disrupting bias and a transparent hiring process. All qualified applicants will be considered for employment regardless of race, color, ancestry, ethnicity, religion, sex, national origin, gender expression, sexual orientation, age, citizenship, marital status, disability, gender identity, family status or veteran status. FactSet participates in E-Verify.

Return to Work:

Returning from a break? We are here to support you If you have taken time out of the workforce and are looking to return, we encourage you to apply and chat with our recruiters about our available support to help you relaunch your care



  • Noida, Uttar Pradesh, India Transaction Network Services Full time

    An extraordinarily talented group of individuals work together every day to drive TNS' success, from both professional and personal perspectives. Come join the excellence! Overview The Risk Management area is responsible for identifying, assessing, and mitigating risk. May include establishing risk management procedures and processes to ensure adherence to...

  • Security Engineer

    4 days ago


    madhya pradesh, India Altered Security Full time

    We are looking for talented Security Engineers to join our team!Altered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information security training, cyber ranges, online labs and security assessments. We have trained more than...


  • Noida, Uttar Pradesh, India Gamemano Full time

    **Key Responsibilities**: **1.Information Security Leadership**: - Develop and implement an information security strategy and governance framework aligned with business objectives. - Lead efforts to protect the company's networks, systems, and data from cybersecurity threats and vulnerabilities. - Conduct regular security assessments, audits, and...

  • Security Officer

    2 weeks ago


    Visakhapatnam, Andhra Pradesh, India Choksi Heraeus Pvt Ltd Full time

    **Hiring Now: Security Officer with Army Experience (Field Posting)** **Location**: 58B, JNPC Thadi Street, Paravada, Visakhapatnam, Thadi, Andhra Pradesh 31 019 **Industry**: Manufacturing **We Are Looking for Army Veterans with Field Posting Experience** Are you a non-trade Army professional with field posting experience? We have an exciting opportunity...


  • Andhra Pradesh, India The Cigna Group Full time

    **Information Protection Associate Advisor - HIH - Evernorth** **Position Summary**: The Security Architect role will report to the Senior Director of CIP Global Security Architecture and will be responsible for the development and maintenance of the Enterprise Security Architecture documents that comprise the security guidance library to support the...

  • Security Officer

    2 weeks ago


    Indore, Madhya Pradesh, India OCEAN UNICARE SECURITY SERVICES PVT. LTD. Full time

    security officer : age limit 48 to 50 years. Civilian with experience 5 years Ex-service personnel fresher or more Experienced would be preferred to handle 50 odd security personnel at a unit. Immediately required. Investigate suspicious activity ,Monitoring and analysing cctv camera footage Responding to emergencies, Responds to alarms Conduct security...


  • Andhra Pradesh, India The Cigna Group Full time ₹ 15,00,000 - ₹ 28,00,000 per year

    Senior Manager of Penetration TestingJob Description: The Senior Manager of Penetration Testing is responsible for leading and managing the penetration testing program for the organization, integrating security best practices, and ensuring robust security measures are in place. This includes developing and implementing policies and procedures for conducting...

  • Security Officer

    2 weeks ago


    Andhra Pradesh, India BARDWOOD SUPPORT SERVICES Full time

    **Location**: - ** - Meneghy House AP **Role Requirement**: - ** - Duties: - Undertake regular inspections and patrols of the building, including patrols of common areas in accordance with local procedures /damage or defects - Always maintain an active presence in the building, remaining awake and vigilant whilst on duty - Monitor behaviour of high-risk...


  • Andhra Pradesh, India Ameriprise Financial Full time US$ 1,04,000 - US$ 1,30,878 per year

    The Information security Architect should have: Specializes in cloud security, primarily AWS, working consultatively with the Information Security department and Cloud Engineering teams.AWS security experience including Identity and Access Management (IAM roles, policies, federation), network security (VPCs, security groups, NACLs, VPC Flow Logs), data...


  • Andhra Pradesh, India Ameriprise Financial Full time

    The Information security Architect should have: Specializes in cloud security, primarily AWS, working consultatively with the Information Security department and Cloud Engineering teams. AWS security experience including Identity and Access Management (IAM roles, policies, federation), network security (VPCs, security groups, NACLs, VPC Flow Logs), data...