Enable job alerts via email!

Business Information Security Officer - Remote/Defense Industrial Base (DIB) Exp

EVOTEK

San Diego (CA)

Remote

USD 150,000 - 190,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Business Information Security Officer to drive their security strategy and initiatives. This role involves developing a comprehensive information security program, ensuring compliance with regulations, and leading efforts to assess and mitigate risks. The ideal candidate will have a strong background in cybersecurity, particularly within the oil or defense sectors, and will be adept at communicating with diverse stakeholders. Join a company recognized for its award-winning culture and commitment to innovation, where your contributions will have a significant impact on the organization's security posture.

Benefits

100% paid medical, dental, and vision
401(k) with employer match
Flexible PTO policy
Flexible working arrangements
Annual company overnight retreat
Performance bonuses
Strong company culture

Qualifications

  • 10+ years of cybersecurity experience, ideally in oil or defense sectors.
  • Expertise in NIST 800-171, CMMC, and DFARS compliance.
  • Ability to create a culture of accountability and security.

Responsibilities

  • Develop and implement a comprehensive information security program.
  • Monitor compliance with security policies and procedures.
  • Oversee incident response planning and vulnerability testing.

Skills

Cyber Compliance Assessments
Regulatory Compliance (NIST 800-171, CMMC, DFARS)
Cybersecurity
Threat and Vulnerability Assessment
Strategic Information Security Development
Communication Skills
Self-starter

Job description

Join EVOTEK: North America’s Premier Digital Business Enabler

As North America's premier enabler of secure digital business, we integrate cutting-edge technical expertise across data center, network, security, cloud, and communications domains. By delivering cohesive digital solutions, we help businesses drive measurable impact and accelerate their transformation.

Our award-winning culture is the cornerstone of everything we do. Recognized multiple times by Inc. Magazine as a "Best Place to Work", we’re proud to create an environment where innovation and collaboration thrive. Locally, we’ve been honored by The San Diego Business Journal as a "Best Place to Work" more than seven times, and our excellence is reflected in accolades like CRN's "Solution Provider 500", "Tech Elite 250", and "Top 150 Growth Companies”. We’ve also earned a spot among CRN’s "Triple Crown” award winners.

If you’re ready to be part of a team that values innovation, culture, and business impact, EVOTEK is the place for you.

Position Overview

The Business Information Security Officer (BISO) will be responsible for helping drive the security strategy by developing and executing security initiatives that span technology, process, and culture. The (BISO) will be tasked with taking the existing strategy, direction and vision and evolving and expanding it to ensure the line of businesses meet and exceed security demands. In this role, you will be supporting a group/team to develop a deep understanding of the business to provide guidance on information security topics, policies, and controls.

Key Responsibilities
  • Develop, drive, and implement Client overall information security program (goals, objectives, and policies) while establishing departmental goals and priorities to execute on that vision.
  • Establish a defined, consistent security architecture standard and work with Clients to implement technical controls in line with cutting edge best in class security and privacy standards.
  • Drive Client domestic and international projects to meet emerging cyber security requirements, data protection and privacy laws.
  • Implement approved policies and procedures to ensure information security efforts are properly coordinated and in compliance to make recommendations for changes and improvements to reduce Client overall security risk.
  • Monitor and assess the compliance of Client organizations with information security policies and procedures, while ensuring third-party compliance.
  • Oversee Client incident response planning, data loss prevention and remediation of breaches, serving as the focal point for response delivery.
  • Implement ongoing Client risk assessment programs targeting information security and privacy matters; recommend methods for vulnerability detection and remediation and perform and/or oversee vulnerability testing.
  • Coordinate and deliver information security reporting and assessments as required by regulatory agencies, clients, and management.
  • Work with peers across the company to review customer feedback/ requirements and ensure that security strategy and roadmaps are aligned with the security needs of Clients.
  • Keep current on the latest security and privacy legislation, regulations, alerts, and vulnerabilities pertaining to the organization. Conduct continual research to maintain knowledge of technology, customer needs and overall requirements.
  • Participate in key initiatives and projects to ensure that cybersecurity controls are accounted for early within the project and software development lifecycles.
  • Ensure risk assessments are conducted on Client high-risk business applications. Provide escalation for high-risk issues arising from those assessments. Ensure remediation plans are tracked to completion.
Minimum Qualifications
  • Cyber Compliance Assessments & Regulatory Compliance experience specifically NIST 800-171, CMMC and DFARS.
  • 10+ years of Cybersecurity experience ideally within the oil industry or Defense Industrial Base Sector, with a background in Security and Compliance.
  • Seasoned track record of assessing threat and vulnerability from a business and technical perspective.
  • Ability to develop and champion pragmatic security solutions that support growth of the business.
  • Experience developing a strategic, comprehensive enterprise information security and IT risk and privacy management program.
  • Experience with supporting customer-facing products, not just internal.
  • Ability to create a culture of accountability and security.
  • Ability to communicate and engage effectively with a diverse audience, including front line technical staff, non-technical staff, management, executives, and vendors/providers.
  • Self-starter with the ability to lead tasks with demonstrated ability to work independently.
Compensation and Benefits
  • Salary commensurate with years of experience, technical expertise and geographic location.
  • Salary range: $150,000 to $190,000.
  • Performance bonuses.
  • Benefits package that includes 100% paid medical, dental and vision for the employee.
  • 401(k) with employer match.
  • Strong company culture.
  • Flexible PTO policy.
  • Flexible working arrangements.
  • Annual company overnight retreat.

EVOTEK believes that everyone has the ability to make an impact, and we are proud to be an equal opportunity employer committed to providing employment opportunity regardless of sex, race, creed, color, gender, religion, marital status, domestic partner status, age, national origin or ancestry, physical or mental disability, medical condition, sexual orientation, pregnancy, military or veteran status, citizenship status, and genetic information.

Apply for this job

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.