Cybersecurity Business Information Security Officer (BISO)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- For Reston, VA position: Salary Range: $ 168,900 - $ 244,300 annually (salary range is based on market data; final salary offered is determined by education, experience, and qualifications of the applicant.)
Extraordinary teams building inspiring projects:
Since 1898, we have helped customers complete more than 25,000 projects in 160 countries on all seven continents that have created jobs, grown economies, improved the resiliency of the world’s infrastructure, increased access to energy, resources, and vital services, and made the world a safer, cleaner place.
Differentiated by the quality of our people and our relentless drive to deliver the most successful outcomes, we align our capabilities to our customers’ objectives to create a lasting positive impact. We serve the Infrastructure; Nuclear, Security & Environmental; Energy; Mining & Metals, and the Manufacturing and Technology markets. Our services span from initial planning and investment, through start-up and operations.
Core to Bechtel is our Vision, Values and Commitments. They are what we believe, what customers can expect, and how we deliver. Learn more about our extraordinary teams building inspiring projects in our Impact Report. Job Summary:
Reporting to the Manager of Business Engagement, the Cybersecurity Business Information Security Officer - BISO, serves as the primary interface between Bechtel’s Global Business Units (GBUs) and the enterprise cybersecurity organization. The role ensures cybersecurity strategy, risk management, and assurance activities are embedded into business operations, engineering delivery, and project execution. The role is accountable for proactively identifying, assessing, and managing cybersecurity risks within the business; providing assurance that controls meet Bechtel policies, standards, and regulatory obligations; and ensuring alignment with evolving business, customer, and regulatory cybersecurity requirements. Enables secure innovation, facilitates technology adoption, and leads cybersecurity risk posture and assurance.
*This position can be based in Reston, VA or Houston, TX. Major Responsibilities:
Risk Management & Assurance:
Servesas the primarycybersecurity risk advisorto assignedGBU’s, ensuring cyber risks are proactively assessedand managed in alignment with Bechtel’s risk appetite.
Owns and overseestheGBU cybersecurity risk posture, ensuringappropriate governance, assurance, audit readiness, and compliance.
Drivesand alignscybersecurity risk assessments forbusiness processes, digital engineering platforms, cloud solutions, AIinitiativesand third-party integrations.
Ensuresremediation plans foridentifiedrisks are clearly defined, tracked, and executed.
Supportsinternal and external audits, regulatory reviews, and customer-driven cybersecurity assessments.
PartnerswithThird-Party Risk Managementto assess and manage cybersecurity risks associated with suppliers, joint ventures, subcontractors, and strategic partners.
Business Alignment & Secure Enablement:
Acts as the primary bridge between business leadership and cybersecurity, ensuring security priorities align with business objectives, project delivery timelines, and regulatory obligations.
Advises business stakeholders through IT and digital intake processes as it relates to cybersecurity, including review of technical documentation and facilitation of cybersecurity and enterprise architecture reviews for new and changed technologies.
Works directly with GBU leadership to understand customer-driven, contract-driven, and regulatory cybersecurity requirements in the regions and sectors they operate.
Translates business requirements into clear cybersecurity needs and work with central cybersecurity teams to ensure alignment, feasibility, and timely delivery of controls.
Enables the secure adoption of emerging technologies (e.g., cloud platforms, digital engineering solutions, data analytics, AI, and OT systems) while maintaining appropriate risk management and assurance.
Advisory, Communication & Change Leadership:
Advisesbusiness leaders, project teams, and functional stakeholders on cybersecurity requirements, risk considerations, and best practices.
Serves as GBU POC and coordinatesincident response activitieswithinCyber Defense Center.
Promotesa culture of shared accountability for cybersecurity risk and operational resilience.
Providesleadership with tailored dashboards, metrics, and reports on cybersecurity risk posture, trends, compliance status, and assurance outcomes.
Acts as a change ambassador, supporting business units through technology and process changes while maintaining resilience and delivery commitments.
Requirements
Requires bachelor’s degree in a relevant discipline plus 8 years progressive experience in information security, cybersecurity, or risk management roles - including 2 years working directly with business units or in a liaison role aligning technology and business objectives.
Prefer 3-5 years’ experience in governance, risk, compliance, or regulated environments (e.g., FIMSA, GBLA, export controls, or large-scale infrastructure programs). Required Knowledge and Skills:
Demonstrated experience instakeholder engagement and executive-level communication, with the ability to influenceInfoSec/Cyber/Assuranceoutcomes across complex, matrixed organizations.
Experience with industry-recognized frameworks and standards such asNIST,ISO/IEC 27001/27002,CSA, or equivalent.
Demonstrated experience drivingproactive identification and mitigation of cybersecurity riskswithin business and project delivery environments.
Experience managing or influencingenterprise-level initiatives, including application portfolios, digital platforms, and IT intake and governance processes.
Demonstrated project and program management skills.
Prefer Project Management Professional (PMP) Certification or formal Project Management training.
Prefer Certified Information Systems Security Professional (CISSP).
Prefer Certified Information Security Manager (CISM). Total Rewards/Benefits
Benefits & conditions
$168,900.00 - $244,300.00 / yr parental leave, paid time off, paid holidays, 401(k), At Bechtel, our employees enjoy a competitive total rewards package that includes comprehensive medical, dental, and vision plans, along with optional disability and supplemental insurance options, generous paid time off (160 hours annually, accrued 6.16 hours per pay period), nine paid holidays, paid parental leave, discretionary bonuses, and a well-designed 401K plan with matching and profit-sharing components
About the company
For decades, Bechtel has worked to inspire the next generation of employees and beyond! Because our teams face some of the world’s toughest challenges, we offer robust benefits to ensure our people thrive. Whether it is advancing careers, delivering programs to enhance our culture, or providing time to recharge, Bechtel has the benefits to build a legacy of sustainable growth. Learn more at Bechtel Total Rewards Diverse teams build the extraordinary:
As a global company, Bechtel has long been home to a vibrant multitude of nationalities, cultures, ethnicities, and life experiences. This diversity has made us a more trusted partner, more effective problem solvers and innovators, and a more attractive destination for leading talent.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Best Paying Jobs in Technology
Best Companies to Work For in Berlin: Top 14 Companies in 2023Â
9 Ways to Make Money Hacking
Top-Paying Tech Jobs (with Salaries)