> Markdown version of [/jobs/ext/2399610-business-information-security-officer-digital-and-industrial-solutions](https://www.wearedevelopers.com/jobs/ext/2399610-business-information-security-officer-digital-and-industrial-solutions). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Business Information Security Officer- Digital and Industrial Solutions - **Company:** WSP - **Location:** United States - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, User Authentication, Microsoft Azure, Software as a Service, Cloud Computing Security, Cloud Engineering, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Continuous Integration, Data Security, Information Security Management, Open Source Technology, Public Key Infrastructure, Systems Development Life Cycle, Software Vulnerability Management, Google Cloud, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 9, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/business-information-security-officer-digital-and-industrial-solutions-usa-58893537 ## About the Role to * Establish and evidence security certifications and compliance (ISO/IEC 27001, SOC 2, etc.) * Manage supply-chain, third-party and open-source security including SBOM and vendor assessment * Monitor emerging technologies and translate to practical security guidance * Coordinate with Global Information Security Framework and report solution-security posture Tasks * Bachelor's degree or equivalent * 12+ years of senior-level information security experience with product, application or cloud security exposure * Proven experience securing customer-facing products, SaaS or cloud platforms * Working knowledge of Secure SDLC/DevSecOps practices (threat modelling, SAST/DAST/SCA, CI/CD security, vulnerability management) * Cloud-native security knowledge across Azure, AWS, GCP (identity, networking, data-protection, workload security) * Familiarity with application/API/data security, encryption, authentication/authorization, PKI * Professional certifications (CISSP, CISM, CCSP, CSSLP, or aaaaa products, cert); governance/audit assets useful * Experience with governance frameworks (ISO/IEC 27001, NIST, SOC 2, COBIT, ITIL) * Risk management experience (analysis, mitigation, monitoring) * Knowledge of information security and privacy regulations relevant to WSP and markets served Key requirements * Medical, dental and vision coverage * Disability and life insurance * Retirement savings plan * Paid sick leave * Paid time off * Parental leave ## Description Experteer Overview In this role you own the security of WSP's externally-facing digital and industrial solutions, partnering with Digital Solutions, product, engineering and go-to-market teams to embed security-by-design. You govern the Secure SDLC, provide security architecture guidance for cloud-native and IoT/OT solutions, and lead risk, compliance and customer assurance efforts to accelerate growth with trust. Compensation / Benefits * Single point of security accountability for externally-facing products, platforms and services * Embed security-by-design and privacy-by-design across the solution lifecycle * Govern Secure SDLC / DevSecOps including threat modelling, SAST/DAST/SCA, CI/CD security, vulnerability management * Provide security architecture guidance for cloud-native, data-intensive, AI/ML and IoT/OT solutions * Identify, assess and track security risks; drive remediation and reporting to leadership * Act as security authority for bids, proposals and customer engagements * Establish and evidence security certifications and compliance (ISO/IEC 27001, SOC 2, etc.) * Manage supply-chain, third-party and open-source security including SBOM and vendor assessment * Monitor emerging technologies and translate to practical security guidance * Coordinate with Global Information Security Framework and report solution-security posture Tasks * Bachelor's degree or equivalent * 12+ years of senior-level information security experience with product, application or cloud security exposure * Proven experience securing customer-facing products, SaaS or cloud platforms * Working knowledge of Secure SDLC/DevSecOps practices (threat modelling, SAST/DAST/SCA, CI/CD security, vulnerability management) * Cloud-native security knowledge across Azure, AWS, GCP (identity, networking, data-protection, workload security) * Familiarity with application/API/data security, encryption, authentication/authorization, PKI * Professional certifications (CISSP, CISM, CCSP, CSSLP, or cloud-security cert); governance/audit assets useful * Experience with governance frameworks (ISO/IEC 27001, NIST, SOC 2, COBIT, ITIL) * Risk management experience (analysis, mitigation, monitoring) * Knowledge of information security and privacy regulations relevant to WSP and markets served Key requirements * Medical, dental and vision coverage * Disability and life insurance * Retirement savings plan * Paid sick leave * Paid time off * Parental leave ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)