CybersecurityJobs.io
← Back to all jobs

Job Description

The BISO Engineer is an embedded cybersecurity practitioner aligned to an assigned business unit, responsible for translating enterprise security direction into practical controls and programs across enterprise and operational technology environments.

Role Summary

In this position, you act as a bridge between overall enterprise security strategy and operational execution. The work focuses on identifying risk, driving remediation, and converting security requirements into actionable unit-level initiatives. You will coordinate with multiple security platforms and stakeholders to maintain an effective security posture across applications, infrastructure, and OT.

Responsibilities

  • Serve as the primary cybersecurity liaison for assigned business unit(s), converting enterprise security policies into unit-specific controls and procedures
  • Conduct and support risk assessments, vulnerability management reviews, and security posture evaluations across applications, infrastructure, and OT environments
  • Lead or support security initiatives covering WAF/firewall configurations, identity and access management reviews, endpoint protection, and cloud security posture
  • Represent the business unit in change management and security governance forums
  • Coordinate with enterprise SIEM, network security, and application security platforms to ensure appropriate monitoring and enforcement
  • Support M&A integration activities, including network segmentation, firewall onboarding, and security baseline validation
  • Develop and maintain security documentation such as policies, runbooks, risk acceptance memos, and remediation plans
  • Engage stakeholders across technical and leadership groups, and present risk posture and program status to senior management

Required Qualifications

  • 5+ years of experience in cybersecurity engineering, architecture, or risk management
  • Hands-on experience with WAF, NGFW, SIEM, or vulnerability management platforms
  • Strong understanding of NIST CSF, CMMC, or equivalent frameworks
  • Proven ability to manage cross-functional security programs with minimal oversight

Preferred Skills

  • Experience in energy, utilities, or OT/ICS environments
  • Familiarity with relevant cloud WAF, segmentation, SIEM, or firewall management tools
  • CISSP, CISM, or equivalent certification
  • Experience supporting M&A cybersecurity integration

Technology and Framework Focus

  • WAF, NGFW, SIEM, vulnerability management platforms
  • NIST CSF, CMMC
  • Security posture evaluations, identity and access management
  • Endpoint protection, cloud security posture
  • Network segmentation, firewall onboarding
  • Enterprise SIEM, network security, application security platforms

Location and Work Setting

United States, onsite. The position requires physical office presence.

Engagement Dates and Compensation

  • Start and end date: 05 Oct 2026 – 05 Oct 2027
  • Indicative hourly rate: $50 – $55 per hour
  • Respond by: 01 Oct 2026

Additional Information

  • Languages: English (professional working proficiency)
  • Skill areas (intermediate): security engineering, security requirements, security information and event management, vulnerability management, network security, network segmentation, merger and acquisitions, and software security

Similar Jobs