Divisional Business Information Security Officer

CBRE

Dallas (TX)

On-site

USD 180,000 - 250,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

CBRE is seeking a Divisional Business Information Security Officer (BISO) to bridge cybersecurity with business operations in the Dallas area. The role centers on aligning security strategy with division goals, reducing risk, and enabling business growth through secure product and service delivery.

The BISO will guide risk-based decision-making, coordinate with legal, audit and compliance teams, and drive security culture across the organization.

Qualifications

  • Bachelor’s degree in cybersecurity, computer science, or IT.
  • 3+ years experience in technology or tech-adjacent fields.
  • 3-5 years in cyber domains (SOC, security engineering, IAM, etc.).
  • 1-3 years in risk management within tech environments.
  • Certifications such as CISSP, CISM, CRISC or equivalent are a plus.
  • Familiarity with ISO27001, NIST CSF, NIST 800-171, GDPR.

Responsibilities

  • Provide executive briefings on security posture, risks and risk reduction efforts.
  • Bridge voice of the business with CISO and Global BISO teams.
  • Drive cyber risk assessment, tracking, and remediation planning.
  • Collaborate with security operations, incident response and client assurance teams.
  • Support regulatory compliance activities and control adoption in divisions.
  • Advise on security requirements for new initiatives and products.
  • Promote security awareness and training across the division.

Skills

Cybersecurity
Risk management
Communication
Stakeholder management
Executive presence

Education

Bachelor's in Cybersecurity
Bachelor's in Computer Science
Bachelor's in Information Technology
3+ years technology experience
3-5 years cyber domain experience
1-3 years risk management
Certifications (ITIL, CISSP, CISM, CRISC, CISA)
Familiarity with ISO27001, NIST CSF, GDPR

Job description

About the role

CBRE is seeking a Divisional Business Information Security Officer (BISO), to join CBRE’s Global

Business Information Security team, and serve as a trusted advisor between cybersecurity and business operations. The individual will serve as a catalyst for aligning security with business goals, contributing to the overall success of CBRE. At a high level, the BISO plays a valuable and pivotal role in the following key objectives:

  • Execution of corporate cybersecurity strategy within the assigned division, in alignment with the business needs and regulatory environment,

  • Reduction of cybersecurity risk,

  • Facilitation of cyber risk-based decision-making,

  • Enablement of the business, through alignment of security products and services with business objectives.

  • Addressing security-related business challenges,

  • Promoting the security culture.

What you'll do

Communication & Collaboration: BISOs serve as a liaison between cybersecurity and the business as well as between cybersecurity and technology teams that support the business. In that role, BISOs facilitate effective communication between the various teams while also communicating with other critical partners (i.e. legal, risk teams, internal audit, etc.) including the following:

  • Provide regular briefings to divisional leadership on security posture, risks, and risk reduction/mitigation efforts.

  • Bring ‘voice of the business’ insights to the CISO, Global BISO and the broader Global

  • Cybersecurity Office to drive business awareness with cyber teams and partner on improvements.

  • Collaborate with Global BISO, Cyber Incident Response, Security Operations Center and

  • Client Assurance teams, in response to division-specific security incidents, coordinating with broader security, technology, legal, compliance and corporate communication teams, as needed.

  • Drive cyber control adoption, as well as remediation of cybersecurity issues (including audit findings, regulatory compliance items, contractual compliance issues, regulatory compliance requirements) and cybersecurity control gaps through coordination of and communication of remediation plans.

  • Assist the CBRE Client Assurance team with division-related client requests by providing business insights and leveraging your knowledge of the business to connect the team with appropriate stakeholders.

Risk Management

A key focus of BISOs is to assist with cybersecurity risk management. BISOs, in partnership with Cybersecurity Governance, Risk & Compliance teams as well as Enterprise Risk Management, assist with identification, assessment, mitigation and overall reduction of cybersecurity risk.

  • Assist with risk analysis and assessment, identifying potential security threats, and developing mitigation strategies tailored to the business risk profile and specific business needs.

  • Translate corporate security policies, standards and cyber-related regulatory requirements into actionable plans for the assigned division, ensuring awareness within the business and assisting to drive adherence to policies, standards and compliance requirements.

  • Assist with development, implementation, and evolution of cybersecurity-related processes, including but not limited to application registration, cyber risk evaluation, cybersecurity control self-assessment processes while partnering with product and technology teams to drive successful and timely execution of these processes.

  • Serve in a consulting/advising function to effectively identify relevant cybersecurity requirements (example – MFA, WAF, etc.) for new and existing projects/initiatives, in partnership with appropriate product teams and subject-matter experts, ultimately driving the implementation of security into the division’s products and services, balancing business needs with security requirements.

  • Monitor the assigned division’s cybersecurity objectives and measures and assist the division’s business and technology teams with prioritization of cybersecurity-related efforts needed to address control adoption and/or operational control deficiencies.

Training & Awareness

BISOs promote a security culture where cybersecurity is valued as an enabler of the business. They serve as advocates for security best practices, cybersecurity strategy and programs with an understanding that cybersecurity policies and standards are purpose-built and not simply compliance requirements.

  • Educate division staff on cybersecurity best practices, integration of cybersecurity controls, and importance of meeting targets for cybersecurity-related operational measures.

  • Ensure training is relevant, impactful and aligned with the specific needs of the assigned division.

  • Facilitate and assist with creation, delivery and evaluation of security awareness training for employees, to reduce human-centric security risks.

  • Monitor effectiveness of training programs and assist with tailoring of training as needed.

  • Provide division-level actionable insights to leadership.

What you'll need
  • Strong and broad understanding of cybersecurity, risk management and technology with ability to deep dive into specific technology domains, as needed.

  • Excellent business acumen with ability to understand business operations and priorities within the division to effectively align security strategies.

  • Excellent communication skills, with proven ability to translate and explain complex security concepts to non-technical stakeholders, influence decision-making and articulate vision across both technical and business teams.

  • Must be a self-starter who takes initiative, can work independently, is eager to learn and has a passion for cybersecurity and technology.

  • Demonstrated ability to build and maintain strong relationships with key stakeholders, including at the executive level, as well as with technical subject-matter experts.

  • Demonstrated executive presence and emotional intelligence.

  • Ability to assess and prioritize security risks based on their potential impact on the business.

  • Must be proficient with MS Office suite of productivity tools as well as collaboration tools.

Education and Experience
  • Bachelor’s Degree, from an accredited four-year college or university, in Cybersecurity,

  • Computer Science, Information Technology, Business Administration.

  • Prior experience serving as a BISO or ISO is preferred.

  • 3+ years working in technology or technology-adjacent field.

  • 3-5 years working in, or closely with, one or more cyber domains (i.e. security operations, security engineering, network security, identity and access management, etc.)

  • 1-3 years working in or with a risk management domain (i.e. technology risk, cybersecurity risk, enterprise risk, etc.); prior experience within cybersecurity risk management is preferred.

  • Certifications are a plus, including ITIL, CISSP, CISM, CRISC, CISA, Cloud Security Practitioner.

  • Familiarity with key cybersecurity compliance standards (i.e. ISO27001, etc.), frameworks (i.e.

  • NIST CSF, NIST 800-171, etc.) and regulations relevant to cybersecurity (i.e. DORA, GDPR, etc.)

Why CBRE

When you join CBRE, you become part of the global leader in commercial real estate services and investment that helps businesses and people thrive. We are dynamic problem solvers and forward-thinking professionals who create significant impact. Our collaborative culture is built on our shared values — respect, integrity, service and excellence — and we value the diverse perspectives, backgrounds and skillsets of our people. At CBRE, you have the opportunity to chart your own course and realize your potential. We welcome all applicants.

Our Values in Hiring

At CBRE, we are committed to fostering a culture where everyone feels they belong. We value diverse perspectives and experiences, and we welcome all applications.

Disclaimers

Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.

Applicant AI Use Disclosure

We value human interaction to understand each candidate's unique experience, skills and aspirations. We do not use artificial intelligence (AI) tools to make hiring decisions, and we ask that candidates disclose any use of AI in the application and interview process.

Equal Employment Opportunity

CBRE is an equal opportunity employer that values diversity. We have a long-standing commitment to providing equal employment opportunity to all qualified applications regardless of race, color, religion, national origin, sex, sexual orientation, gender identity, pregnancy, age, citizenship, marital status, disability, veteran status, political belief, or any other basis protected by applicable law.

Candidate Accommodations

CBRE values the differences of all current and prospective employees and recognizes how every employee contributes to our company’s success. CBRE provides reasonable accommodations in job application procedures for individuals with disabilities. If you require assistance due to a disability in the application or recruitment process, please submit a request via email at recruitingaccommodations@cbre.com or via telephone at +1 866 225 3099 (U.S.) and +1 866 388 4346 (Canada).

CBRE, Inc. is an Equal Opportunity and Affiantitve Action Employer (Women/Minorities/Persons with Disabilities/US Veterans)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Divisional Business Information Security Officer
Divisional Business Information Security Officer

CBRE Group, Inc. • Dallas (TX), Northern (KY)

Hybrid
USD 150,000 - 190,000
HSE Consultant - Data Center, Safety Specialist
HSE Consultant - Data Center, Safety Specialist

CBRE • Phoenix (AZ)

On-site
USD 90,000 - 120,000
HSE Consultant - Safety Specialist
HSE Consultant - Safety Specialist

CBRE • Kuna (ID)

On-site
USD 70,000 - 100,000
HSE Consultant - Safety Specialist
HSE Consultant - Safety Specialist

CBRE • Albuquerque (NM)

On-site
USD 70,000 - 100,000
Procurement Technology Director
Procurement Technology Director

CBRE • Richardson (TX)

On-site
USD 150,000 - 210,000
VP, Head of BOE Data Engineering
VP, Head of BOE Data Engineering

CBRE • Richardson (TX)

On-site
USD 170,000 - 210,000
HSE Consultant
HSE Consultant

CBRE • Huntsville (AL)

On-site
USD 65,000 - 95,000
Business Unit Leader (Facilities Management) - Milwaukee, WI
Business Unit Leader (Facilities Management) - Milwaukee, WI

CBRE • Milwaukee (WI)

On-site
USD 120,000 - 170,000
HSE Supervisor
HSE Supervisor

CBRE • Sparks (NV)

On-site
USD 75,000 - 115,000
Office Services Supervisor
Office Services Supervisor

CBRE • Orlando (FL)

On-site
USD 55,000 - 85,000