> Markdown version of [/jobs/ext/266248-cybersecurity-business-information-security-officer-biso](https://www.wearedevelopers.com/jobs/ext/266248-cybersecurity-business-information-security-officer-biso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Business Information Security Officer (BISO) - **Company:** Bechtel Corporation - **Location:** Reston, VA, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Digital Architecture, Information Systems Security Architecture Professional, Cloud Services, Web Platforms, Data Analytics, Cyber Warfare - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c996884568f1f4e2 ## About the Role Requires bachelor's degree in a relevant discipline plus 8 years progressive experience in information security, cybersecurity, or risk management roles - including 2 years working directly with business units or in a liaison role aligning technology and business objectives. Prefer 3-5 years' experience in governance, risk, compliance, or regulated environments (e.g., FIMSA, GBLA, export controls, or large-scale infrastructure programs). Required Knowledge and Skills: Demonstrated experience in stakeholder engagement and executive-level communication, with the ability to influence InfoSec/Cyber/Assurance outcomes across complex, matrixed organizations. Experience with industry-recognized frameworks and standards such as NIST, ISO/IEC 27001/27002, CSA, or equivalent. Demonstrated experience driving proactive identification and mitigation of cybersecurity risks within business and project delivery environments. Experience managing or influencing enterprise-level initiatives, including application portfolios, digital platforms, and IT intake and governance processes. Demonstrated project and program management skills. Prefer Project Management Professional (PMP) Certification or formal Project Management training. Prefer Certified Information Systems Security Professional (CISSP). Prefer Certified Information Security Manager (CISM). ## Description Reporting to the Manager of Business Engagement, the Cybersecurity Business Information Security Officer - BISO, serves as the primary interface between Bechtel's Global Business Units (GBUs) and the enterprise cybersecurity organization. The role ensures cybersecurity strategy, risk management, and assurance activities are embedded into business operations, engineering delivery, and project execution. The role is accountable for proactively identifying, assessing, and managing cybersecurity risks within the business; providing assurance that controls meet Bechtel policies, standards, and regulatory obligations; and ensuring alignment with evolving business, customer, and regulatory cybersecurity requirements. Enables secure innovation, facilitates technology adoption, and leads cybersecurity risk posture and assurance., Serves as the primary cybersecurity risk advisor to assigned GBU's, ensuring cyber risks are proactively assessed and managed in alignment with Bechtel's risk appetite. Owns and oversees the GBU cybersecurity risk posture, ensuring appropriate governance, assurance, audit readiness, and compliance. Drives and aligns cybersecurity risk assessments for business processes, digital engineering platforms, cloud solutions, AI initiatives and third-party integrations. Ensures remediation plans for identified risks are clearly defined, tracked, and executed. Supports internal and external audits, regulatory reviews, and customer-driven cybersecurity assessments. Partners with Third-Party Risk Management to assess and manage cybersecurity risks associated with suppliers, joint ventures, subcontractors, and strategic partners. Business Alignment & Secure Enablement: Acts as the primary bridge between business leadership and cybersecurity, ensuring security priorities align with business objectives, project delivery timelines, and regulatory obligations. Advises business stakeholders through IT and digital intake processes as it relates to cybersecurity, including review of technical documentation and facilitation of cybersecurity and enterprise architecture reviews for new and changed technologies. Works directly with GBU leadership to understand customer-driven, contract-driven, and regulatory cybersecurity requirements in the regions and sectors they operate. Translates business requirements into clear cybersecurity needs and work with central cybersecurity teams to ensure alignment, feasibility, and timely delivery of controls. Enables the secure adoption of emerging technologies (e.g., cloud platforms, digital engineering solutions, data analytics, AI, and OT systems) while maintaining appropriate risk management and assurance. Advisory, Communication & Change Leadership: Advises business leaders, project teams, and functional stakeholders on cybersecurity requirements, risk considerations, and best practices. Serves as GBU POC and coordinates incident response activities within Cyber Defense Center. Promotes a culture of shared accountability for cybersecurity risk and operational resilience. Provides leadership with tailored dashboards, metrics, and reports on cybersecurity risk posture, trends, compliance status, and assurance outcomes. Acts as a change ambassador, supporting business units through technology and process changes while maintaining resilience and delivery commitments., For decades, Bechtel has worked to inspire the next generation of employees and beyond! Because our teams face some of the world's toughest challenges, we offer robust benefits to ensure our people thrive. Whether it is advancing careers, delivering programs to enhance our culture, or providing time to recharge, Bechtel has the benefits to build a legacy of sustainable growth. Learn more at Bechtel Total Rewards ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Project Fugu: Extending the web](https://www.wearedevelopers.com/videos/832-project-fugu-extending-the-web) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Keith Cirkle of GitHub on React Fatigue](https://www.wearedevelopers.com/videos/1265-keith-cirkle-of-github-on-react-fatigue) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)