Business Information Security Officer- Digital and Industrial Solutions

WSP
United States
27 days ago
Apply on us.experteer.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services User Authentication Microsoft Azure Software as a Service Cloud Computing Security Cloud Engineering Control Objectives for Information and Related Technology (COBIT) Cyber Security Continuous Integration Data Security
+9 more
Information Security Management Open Source Technology Public Key Infrastructure Systems Development Life Cycle Software Vulnerability Management Google Cloud Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

Experteer Overview In this role you own the security of WSP’s externally-facing digital and industrial solutions, partnering with Digital Solutions, product, engineering and go-to-market teams to embed security-by-design. You govern the Secure SDLC, provide security architecture guidance for cloud-native and IoT/OT solutions, and lead risk, compliance and customer assurance efforts to accelerate growth with trust. Compensation / Benefits * Single point of security accountability for externally-facing products, platforms and services * Embed security-by-design and privacy-by-design across the solution lifecycle * Govern Secure SDLC / DevSecOps including threat modelling, SAST/DAST/SCA, CI/CD security, vulnerability management * Provide security architecture guidance for cloud-native, data-intensive, AI/ML and IoT/OT solutions * Identify, assess and track security risks; drive remediation and reporting to leadership * Act as security authority for bids, proposals and customer engagements * Establish and evidence security certifications and compliance (ISO/IEC 27001, SOC 2, etc.) * Manage supply-chain, third-party and open-source security including SBOM and vendor assessment * Monitor emerging technologies and translate to practical security guidance * Coordinate with Global Information Security Framework and report solution-security posture Tasks * Bachelor’s degree or equivalent * 12+ years of senior-level information security experience with product, application or cloud security exposure * Proven experience securing customer-facing products, SaaS or cloud platforms * Working knowledge of Secure SDLC/DevSecOps practices (threat modelling, SAST/DAST/SCA, CI/CD security, vulnerability management) * Cloud-native security knowledge across Azure, AWS, GCP (identity, networking, data-protection, workload security) * Familiarity with application/API/data security, encryption, authentication/authorization, PKI * Professional certifications (CISSP, CISM, CCSP, CSSLP, or cloud-security cert); governance/audit assets useful * Experience with governance frameworks (ISO/IEC 27001, NIST, SOC 2, COBIT, ITIL) * Risk management experience (analysis, mitigation, monitoring) * Knowledge of information security and privacy regulations relevant to WSP and markets served Key requirements * Medical, dental and vision coverage * Disability and life insurance * Retirement savings plan * Paid sick leave * Paid time off * Parental leave

Requirements

to * Establish and evidence security certifications and compliance (ISO/IEC 27001, SOC 2, etc.) * Manage supply-chain, third-party and open-source security including SBOM and vendor assessment * Monitor emerging technologies and translate to practical security guidance * Coordinate with Global Information Security Framework and report solution-security posture Tasks * Bachelor’s degree or equivalent * 12+ years of senior-level information security experience with product, application or cloud security exposure * Proven experience securing customer-facing products, SaaS or cloud platforms * Working knowledge of Secure SDLC/DevSecOps practices (threat modelling, SAST/DAST/SCA, CI/CD security, vulnerability management) * Cloud-native security knowledge across Azure, AWS, GCP (identity, networking, data-protection, workload security) * Familiarity with application/API/data security, encryption, authentication/authorization, PKI * Professional certifications (CISSP, CISM, CCSP, CSSLP, or aaaaa products, cert); governance/audit assets useful * Experience with governance frameworks (ISO/IEC 27001, NIST, SOC 2, COBIT, ITIL) * Risk management experience (analysis, mitigation, monitoring) * Knowledge of information security and privacy regulations relevant to WSP and markets served Key requirements * Medical, dental and vision coverage * Disability and life insurance * Retirement savings plan * Paid sick leave * Paid time off * Parental leave

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi · World Congress 2022

Videos

See all

Related articles

See all