BISO - Business Information Security Officer
Remote - San Diego, California, United States
EVOTEK™ is North America's premier enabler of digital business with a focus on innovation. With technology offerings in data center and cloud, EVOTEK is uniquely equipped to enable customers with the industry shift from traditional IT computing to secure multi-cloud. With services practices in cybersecurity, mobility, platform engineering and AIOps, EVOTEK is moving up the value chain, closer to the part of digital business that matters most. EVOTEK was named to Inc. Magazine’s “Best Places to Work” in 2018 and 2020. For five consecutive years, from 2016-2020, EVOTEK was listed in The San Diego Business Journal's “Best Places to Work” and recognized in CRN's “Solution Provider 500” list, CRN's “Next-Generation 250” list, CRN’s “Triple Crown” and highlighted as CRN's “Top 150 Growth Companies”, holding the #1 spot in 2017 as the fastest growing system integrator in the country. In 2020, EVOTEK was named to the Inc. 5000 list as one of the fastest growing companies in America.
The Business Information Security Officer (BISO) will be responsible for helping drive the security strategy by developing and executing security initiatives that span technology, process, and culture. The (BISO) will be tasked with taking the existing strategy, direction and vision and evolving and expanding it to ensure the line of businesses meet and exceed security demands. In this role, you will be supporting a group/team to develop a deep understanding of the business to provide guidance on information security topics, policies, and controls.
- Develop, drive, and implement the overall information security program (goals, objectives, and policies) while establishing departmental goals and priorities to execute on that vision.
- Establish a defined, consistent security architecture standard and work with business units to implement technical controls in line with cutting edge best in class security and privacy standards.
- Drive domestic and international projects to meet emerging cyber security requirements, data protection and privacy laws.
- Implement approved policies and procedures to ensure information security efforts are properly coordinated and in compliance to make recommendations for changes and improvements to reduce the overall security risk.
- Monitor and assess the compliance of the organization with information security policies and procedures, while ensuring third-party compliance.
- Oversee incident response planning, data loss prevention and remediation of breaches, serving as the focal point for response delivery.
- Implement an ongoing risk assessment program targeting information security and privacy matters; recommend methods for vulnerability detection and remediation and perform and/or oversee vulnerability testing.
- Coordinate and deliver information security reporting and assessments as required by regulatory agencies, clients, and management.
- Work with peers across the company to review customer feedback/ requirements and ensure that security strategy and roadmaps are aligned with the security needs of customers.
- Keep current on latest security and privacy legislation, regulations, alerts, and vulnerabilities pertaining to the organization. Conduct continual research to maintain knowledge of technology, customer needs and overall requirements.
- Participate in key initiatives and projects to ensure that cybersecurity controls are accounted for early within the project and software development lifecycles.
- Work with the division to ensure risk assessments are conducted on high-risk business applications. Provide escalation for high-risk issues arising from those assessments. Ensure remediation plans are tracked to completion.
- 10+ years of Information Technology experience, with a background in Security and Compliance.
- Seasoned track record of assessing threat and vulnerability from a business and technical perspective.
- Ability to develop and champions pragmatic security solutions that support growth of the business.
- Experience developing a strategic, comprehensive enterprise information security and IT risk and privacy management program.
- Experience with supporting customer-facing products, not just internal.
- Ability to create a culture of accountability and security.
- Service Level Management experience.
- Ability to communicate and engage effectively with a diverse audience, including front line technical staff, non-technical staff, management, executives, and vendors/providers.
- Self-starter with the ability to lead tasks with demonstrated ability to work independently.
- Strong company culture.
- Competitive compensation.
- Benefits package that includes 100% paid medical, dental and vision for the employee.
- 401(k) with employer match.
- Flexible PTO policy.
- Flexible working arrangements.
- Annual company overnight retreat (employee + significant other).
Equal Opportunity Employer
EVOTEK believes that everyone has the ability to make an impact, and we are proud to be an equal opportunity employer committed to providing employment opportunity regardless of sex, race, creed, color, gender, religion, marital status, domestic partner status, age, national origin or ancestry, physical or mental disability, medical condition, sexual orientation, pregnancy, military or veteran status, citizenship status, and genetic information.
Explore more Information Security career opportunities
- Open Senior Information Security Engineer jobs
- Open Vulnerability Analyst jobs
- Open Cyber Security Architect jobs
- Open IT Security Engineer jobs
- Open Personnel Security Officer jobs
- Open Staff Security Engineer jobs
- Open Senior Penetration Tester jobs
- Open Senior Infrastructure Security Engineer jobs
- Open Threat Intelligence Response Analyst jobs
- Open Principal Security Engineer jobs
- Open Cybersecurity Analyst jobs
- Open Senior Incident Response Analyst jobs
- Open Information Security Architect jobs
- Open Chief Information Security Officer jobs
- Open SOC Analyst jobs
- Open Sr. Product Security Engineer jobs
- Open Azure Security Engineer jobs
- Open Information Security Officer jobs
- Open Cybersecurity Engineer jobs
- Open Senior Information Security Analyst jobs
- Open Sr. Software Engineer - Detection Engineering jobs
- Open Staff Engineer, Cloud Security jobs
- Open Security Officer 3 jobs
- Open Software Security Engineer jobs
- Open Privacy Manager jobs
- Open Threat intelligence-related jobs
- Open PCI-related jobs
- Open Clearance-related jobs
- Open IDS-related jobs
- Open Machine Learning-related jobs
- Open Forensics-related jobs
- Open CEH-related jobs
- Open Open Source-related jobs
- Open Splunk-related jobs
- Open Intrusion detection-related jobs
- Open Encryption-related jobs
- Open Ruby-related jobs
- Open Security assessments-related jobs
- Open OSCP-related jobs
- Open Threat detection-related jobs
- Open Docker-related jobs
- Open GDPR-related jobs
- Open IPS-related jobs
- Open HIPAA-related jobs
- Open DevSecOps-related jobs
- Open TCP/IP-related jobs
- Open Unix-related jobs
- Open PowerShell-related jobs
- Open DNS-related jobs