Business Information Security Officer

Raymond James Financial, Inc.

Saint Petersburg (FL)

Hybrid

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Raymond James Financial, Inc. in Saint Petersburg, FL, United States, is seeking an experienced information security professional.

The role requires articulating security risks to the business, aligning security with strategy, and guiding audits, policy development, and regulatory compliance within a hybrid work model. The position emphasizes risk management, incident response, disaster recovery planning, and collaboration with senior leadership to ensure effective controls and remediation.

Qualifications

  • Financial services experience highly preferred.
  • Knowledge of information security programs including audit reviews, risk assessment, awareness and training, IAM, data protection, secure SDLC, incident management, vulnerability assessment, third-party assessment, secure configurations and patch management.
  • Advanced knowledge of infrastructure and security technology with ITIL, ISO 17799 and COBIT processes.

Responsibilities

  • Articulates the security perspective to the business and helps them understand impact and controls.
  • Ensures security is aligned with business strategy and needs.
  • Counsels business units on regulatory information security compliance requirements.
  • Represents the business unit in development of policies and standards.
  • Acts as primary point of contact for IT internal audits and coordinates with senior leadership.
  • Ensures owners are accountable for controls and risk remediation.
  • Reports on the enterprise information security risk posture and vulnerabilities.
  • Focuses on process improvement to manage risk and automate where possible.
  • Investigates security incidents and recommends corrective actions.
  • Tests and implements security plans, products, and control techniques.
  • May lead security projects and strategy.
  • Designs disaster recovery and contingency plans to protect data.
  • Develops procedures and monitors implementation.
  • Engages stakeholders and promotes understanding and commitment.

Skills

InfoSec knowledge
Risk management
Audit & compliance
Regulatory knowledge
Security governance
Communication skills
Strategic thinking

Education

Bachelor's degree in Information Security or related field
CISSP / CISM / CISA / CRISC certifications

Tools

ITIL
COBIT
ISO 17799
PCI DSS

Job description

This position follows our hybrid workstyle policy **: Expected to be in a Raymond James office location a minimum of 3 days a week.**

****

Please note: This role is not eligible for Work Visa sponsorship, either currently or in the future.

Responsibilities:
  • Articulates the security perspective to the business and helps them understand the potential impact and possible controls in business terms

  • Communicates business knowledge and requirements to the Information Security organization thus ensuring security is aligned with business strategy and need

  • Counselsbusiness units in understanding regulatory information security compliance requirements and helps ensure compliance

  • Represents the business unit in development of policies and standards

  • Act as primary point of contact for all IT internal audits, participates in scoping, deliverable requests and collaborates with senior leadership to clear audit reports and ensure action plans are complete and effective

  • EnsuresIT owners are held accountable for their controls and understand responsibilities as to risk mitigation and remediation as well as compliancetosecurity policy and standards to reduce liabilities

  • Understands and reports on the overall information security risk posture of the businessunit, andprovides an enterprise view of vulnerabilities and associated risks to both the business and information security

  • Focuses on process improvement to manage risk, proactively prevent problems and identify opportunities for efficiencies and automation.

  • Investigates security incidents for the business and works with Information Security teams to recommend/implement appropriate corrective actions

  • Understands, tests and implements security plans, products, strategies and control techniques

  • May lead or participate in security related projects and strategy

  • Design and implement disaster recovery and contingency plans to protect company data

  • Help develop procedures for an area of the organization and monitor their implementation

  • Contribute to stakeholder engagement by identifying stakeholders; by finding out their needs, issues, and concerns; and by reacting to these needs, issues, and concerns, arranging meetings and events and drafting supporting materials to promote understanding and commitment

  • Develop own capabilities by participating in assessment and development planning activities as well as formal and informal training and coaching; gain or maintain external professional accreditation, where relevant, to improve performance and fulfill personal potential. Maintain an understanding of relevant technology, external regulation, and industry best practices through ongoing education, attending conferences, and reading specialist media

  • Support strategy formulation for digital by exploring how information technology can be used to help the organization become more responsive to customer needs and changing business requirements

  • Provide specialist advice on the interpretation and application of policies and procedures, resolving queries and issues andreferringvery complex or contentious issues to others

  • Performs other duties and responsibilities as assigned

Skills:
  • Financial services experience highly preferred

  • Knowledge of Information Security programsincluding, but not limited to, audit reviews, risk assessment, awareness and training, identity and access management, dataprotections, secure SDLC, incident management, vulnerability assessment, penetration testing, third-party assessment, secure configurations and patch management

  • Advanced knowledge of infrastructure and logical security technology with experience working with ITIL, ISO 17799 and/ orCoBitprocesses and procedures

  • Experience translating business drivers and priorities into security design

  • Knowledge of government and other regulations related to Information Security (e.g., GLBA, SOXA 404, FFIEC, PCI, Privacy, HIPAA, etc.)

  • Technical skills and proficiency in a wide array of platforms and systems (e.g., Windows, UNIX, SQL, Tandem)

  • Uses clear and effective verbal communications skills without supervision and provides technical guidance when required on expressing ideas, requesting actions and formulating plans or policies

  • Works without supervision and provides technical guidance when required on achieving full compliance with applicable rules and regulations in management and/or operations

  • Works without supervision and provides technical guidance when required on maintaining the security, integrity, compliance and continuity of IT systems and services

  • Works without supervision and provides technical guidance when required on developing, monitoring, interpreting and understanding policies and procedures, while making sure they match organizational strategies and objectives

  • Needsguidance (but not supervision) to communicate with other people by speaking in a clear, concise and compelling manner

Licenses/Certifications:
  • Security and control certificationshighlypreferred (CISSP, CISM, CISA, CRISC
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Business Information Security Officer
Business Information Security Officer

Raymondjames • Saint Petersburg (FL)

Hybrid
USD 140,000 - 190,000
Business Information Security Officer
Business Information Security Officer

Raymond James • Saint Petersburg (FL)

Hybrid
USD 150,000 - 190,000
Health benefits
Retirement plan
Paid time off
Business Information Security Officer
Business Information Security Officer

Raymond James Financial, Inc. • Town of Florida (NY), Northern (KY)

Hybrid
USD 120,000 - 170,000
Hybrid workstyle
Benefits package
Business Information Security Officer
Business Information Security Officer

100 Raymond James & Associates, Inc. • Saint Petersburg (FL)

Hybrid
USD 120,000 - 190,000
IT Security Manager
IT Security Manager

SmartRecruiters, Inc. • Olathe (KS)

On-site
USD 90,000 - 120,000
Principal Analyst, IT Security
Principal Analyst, IT Security

Raymond James Financial, Inc. • Saint Petersburg (FL)

Hybrid
USD 90,000 - 120,000
Senior Manager, Information Security
Senior Manager, Information Security

Uniting Holding • Houston (TX)

On-site
USD 120,000 - 150,000
Information Security Officer
Information Security Officer

City First Bank • Inglewood (CA)

On-site
USD 100,000 - 140,000
Business Information Security Officer (BISO) - CFO and GRM
Business Information Security Officer (BISO) - CFO and GRM

Bank of America • Chicago (IL)

On-site
USD 120,000 - 180,000
Information Security Analyst I
Information Security Analyst I

Sonora Quest Laboratories / Laboratory Sciences of Arizona • Yakima (WA)

On-site
USD 90,000 - 120,000