Business Information Security Officer

Conti-Electric

Sterling Heights (MI)

On-site

USD 140,000 - 190,000

Full time

17 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Equans seeks a Business Information Security Officer for OT and customer-facing solutions in Sterling Heights, MI (or Montreal, CAN). You will own the security program for OT environments and customer solutions, driving secure onboarding, documenting standards, and leading risk assessments.

This cross-functional role requires deep technical security expertise, stakeholder communication, and experience with ICS/OT security standards. Reports to the NORAM CISO.

Qualifications

  • Minimum 7+ years in information security with at least 3 years focused on OT/ICS security or customer-facing solution security in a solutions provider, or managed services context.
  • Demonstrated experience conducting security design reviews, architecture assessments, and risk analysis for complex networked environments.
  • Working knowledge of OT/ICS security standards and frameworks.
  • Familiarity with enterprise IT security frameworks.
  • Experience managing security documentation programs.
  • Strong understanding of network security principles; segmentation, DMZ design, firewall policy, remote access, identity and access management.
  • Excellent verbal and written communication skills; ability to present security risk to both technical and non-technical audiences.

Responsibilities

  • Leading the security onboarding process for new OT Systems and customer facing solutions, ensuring all assets are assessed, documented and approved before production deployment.
  • Define and enforce security requirements, including network segmentation standards, access control models, and identity management policies for OT and customer solution environments.
  • Coordinate with procurement, legal and IT teams to ensure that third party vendors meet security baseline requirements through contract review and vendor risk assessments.

Skills

Information security
OT/ICS security
Risk analysis
Security design reviews
Security architecture
Documentation management
Stakeholder communication
Vulnerability management

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Business Information Security Officer

Full Time Sterling Heights, MI, US

4 days ago Requisition ID: 1229

Purpose:

The Business Information Security Officer (BISO) for Operational Technology (OT) and Customer Facing solutions serves as the primary security liaison between the cyber security organization and business units responsible for OT environments and externally delivered solutions. This role owns the security program for these domains, driving secure onboarding of systems and partners, maintaining documentation standards, participating in design and architecture reviews and leading security assessments for both OT networks and customer-facing solutions.

This is a highly cross functional role requiring deep technical security knowledge, strong stakeholder communication skills and an understanding of industrial control systems (ICS), and enterprise solution delivery. The BISO acts as a security strategist ensuring that security is embedded into processes from initial designs through ongoing operations post-delivery.

Reports to:

NORAM Chief Information Security Officer (CISO)

Location: Sterling Heights, MI or Montreal, CAN
Department: IT Cyber Security Services
  • Leading the security onboarding process for new OT Systems and customer facing solutions, ensuring all assets are assessed, documented and approved before production deployment.
  • Define and enforce security requirements, including network segmentation standards, access control models, and identity management policies for OT and customer solution environments.
  • Coordinate with procurement, legal and IT teams to ensure that third party vendors meet security baseline requirements through contract review and vendor risk assessments.
Documentation & Standards Management
  • Own the security documentation library for OT and customer-facing solution domains including network diagrams, network flows, security control matrices, security plans and backup solutions.
  • Develop and maintain security standards and procedures specific to OT environments.
  • Ensure documentation remains current through periodic review cycles and is aligned with applicable compliance frameworks.
  • Collaborate with engineering, operations and product teams to capture security architecture decisions and maintain accurate as
  • Participate in architecture design review as a security SME. EQUANS is an equal opportunity employer.
Security Review & Risk Assessment
  • Review proposed OT system architectures, network designs and customer solution designs for security gaps
  • providing documented findings and remediation recommendations.
  • Lead security reviews for OT network changes, new customer-facing solutions and significant modifications to existing deployments, producing risk assessment reports with prioritized findings.
  • Coordinate penetration testing and vulnerability assessments activities scoped to OT and customer solution environments; track findings through remediation.
  • Assess and communicate residual risk to business stakeholders and CISO, facilitating informed risk acceptance decisions when appropriate.
  • Serve as the security point of contact for customer security questionnaires, audits and third party security assessments related to delivered solutions.
Minimum Qualifications Required Education/Experience
  • Minimum of 7+ years in information security with at least 3 years focused on OT/ICS security or customer-facing solution security in a solutions provider, or managed services context.
  • Demonstrated experience conducting security design reviews, architecture assessments, and risk analysis for complex networked environments.
  • Working knowledge of OT/ICS security standards and frameworks.
  • Familiarity with enterprise IT security frameworks
  • Experience managing security documentation programs
  • Strong understanding of network security principles; segmentation, DMZ design, firewall policy, remote access, identity and access management.
  • Excellent verbal and written communication skills; ability to present security risk to both technical and non-technical audiences.
Preferred
  • CISSP, CISM, GICSP or equivalent
  • Direct experience with DCS, PLCs, historians or industrial IOT networks
  • Experience working alongside regulated industries such as energy/utilities or manufacturing.
  • Background in solutions delivery or managed security services
  • Experience with security tooling relevant to OT and enterprise environments
  • Familiarity with secure remote access solution implementations and designs.

The working environment characteristics described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is not exposed to weather conditions. The noise level in the work environment is usually moderate. The position could require some lifting.

All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

OT Security Leader for Business Solutions
OT Security Leader for Business Solutions

Conti-Electric • Sterling Heights (MI)

On-site
USD 140,000 - 190,000
Operational Technology Security Engineer
Operational Technology Security Engineer

Goldbelt, Inc. • Dayton (OH)

On-site
USD 80,000 - 100,000
Medical insurance
401(k) plan with matching
Paid time off
Operational Technology Security Engineer
Operational Technology Security Engineer

Goldbelt, Inc. • Ogden (UT)

On-site
USD 90,000 - 120,000
Medical, dental, and vision insurance
401(k) plan with company matching
Paid time off
Operational Technology Security Engineer
Operational Technology Security Engineer

Goldbelt, Inc. • Battle Creek (MI)

On-site
USD 100,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+3
Operational Technology Security Engineer
Operational Technology Security Engineer

Nisga'a Tek, LLC • New Cumberland

On-site
USD 110,000 - 150,000
Security Engineer – Operational Technology
Security Engineer – Operational Technology

TriCom Technical Services • Kansas City (KS)

On-site
USD 90,000 - 120,000
Medical/Dental Benefits
Paid time off
Paid Holidays
+1
Operational Technology Security Engineer
Operational Technology Security Engineer

Goldbelt, Inc. • Pennsylvania

On-site
USD 120,000 - 180,000
Medical, dental, vision insurance
401(k) with company matching
Paid time off
Operational Technology Security Engineer
Operational Technology Security Engineer

Goldbelt, Inc. • New Cumberland

On-site
USD 90,000 - 120,000
Medical, dental, and vision insurance
401(k) plan with company matching
Paid time off
+1
DHS Sr. Operational Technology (OT) Security Engineer
DHS Sr. Operational Technology (OT) Security Engineer

OneZero Solutions • Washington

On-site
USD 120,000 - 160,000
Health/Dental/Vision Insurance
401K with Company Matching
PTO & Paid Holidays
+1
Information Security, Technical Lead I - OT
Information Security, Technical Lead I - OT

Lincoln Electric • Euclid (OH)

On-site
USD 125,000 - 156,000