What are the responsibilities and job description for the Business Information Security Officer position at Info Way Solutions?
Job Title : Business Information Security Officer (BISO)
Location : Raleigh, NC
Overview :
We are seeking an experienced Business Information Security Officer (BISO) to ensure the security and integrity of our information systems. The ideal candidate will consult on security controls, manage regulatory compliance, support risk management activities, and help implement security technologies in a collaborative and evolving environment.
Key Responsibilities :
Security Consulting : Provide expert advice on security controls and policies.
Regulatory Compliance : Collaborate on regulatory initiatives, including GDPR, HIPAA, PCI-DSS, and other standards.
Employee Training : Work with internal teams to promote awareness and training related to information security.
Third-Party Risk Management : Support and manage third-party risk assessments.
Policy Creation & Maintenance : Develop and maintain security policies, procedures, and standards.
Risk Assessments : Conduct risk assessments to identify vulnerabilities and ensure adequate security controls are in place.
Incident Response : Investigate and manage security incidents, ensuring timely resolution.
Technology Implementation : Lead efforts to deploy new security technologies and ensure integration with existing systems.
Required Skills & Experience :
Strong knowledge and experience in Risk Management.
Expertise with regulatory frameworks such as GDPR, HIPAA, PCI-DSS, and NIST.
Experience conducting risk assessments and investigating security incidents.
Ability to develop and maintain security policies and procedures.
Strong communication and collaboration skills.
Preferred Skills :
Project management skills for tracking and managing security initiatives.
Experience in security technology implementation.
Education & Experience :
Relevant certifications in information security (e.g., CISSP, CISM) are preferred.
5 years of experience in a similar role, preferably in an organization with complex regulatory requirements.