Business Information Security Officer
Hanover, PA - USA
Job Summary
The BISOs primary responsibility is to ensure that Allegis Global Solutions Inc.s (AGS) information security and data privacy initiatives support the global business strategy while complying with industry best practices cybersecurity frameworks such as NIST Cybersecurity (CSF) and Privacy Frameworks and ISO27001 and in alignment with the parent companys policies and conjunction with the Head of Global Information Security of Allegis Group Inc. the parent company the AGS BISO will provide vision and leadership for developing and supporting information security and data privacy initiatives in a federated environment (at an operating company level in concert with a shared services corporate model) and will oversee and direct the implementation of controls designed to protect the confidentiality integrity and availability of the data that AGS processes internally and on behalf of its customers. This individual is also responsible for evaluating auditing and making recommendations regarding existing business operations and systems protecting against security and privacy breaches and vulnerabilities while directing the administration and education of security policies activities and standards. Information security and data privacy functions align to the Risk Team managed by the AGS Global Director of Risk and Compliance.
Key Responsibilities:
Strategy & Planning
- On an ongoing basis evaluate the information security and data privacy posture for AGS and provide a regular update to the Global Director of Risk and Compliance as well as make recommendations for future state to address evolving business needs and minimize risk to the organization.
- Participate as a member of the global enterprise risk team in governance processes of the organizations security and privacy strategies.
- Recommend and implement changes in security and data privacy policies and practices in accordance with changes in local federal or international regulation.
- Develop and communicate security and privacy strategies and plans to executive team staff partners customers and stakeholders.
- Remain informed on trends and issues in the security industry including current and emerging technologies. Advise counsel and educate executive and leadership teams on their relative importance and financial impact.
Operational Management
- Act as advocate and primary liaison for AGS security vision via regular written and in-person communications with executives leadership and end users.
- Participate in customer and vendor contract review/negotiations on information security and data privacy. Provide training and guidance in conjunction with the legal department on these topics periodically.
- Supervise recruitment development retention and organization of security and privacy staff in accordance with AGS budgetary objectives and personnel policies.
- Oversee responses to customer security questionnaires and liaise with AGS program teams and customers as needed.
- Oversee the AGS Security Incident Response Process (SIRP) and ensure alignment with the Allegis Group Information Security team.
- In coordination with a third-party auditor oversee security certification audits such as SOC1/SOC2 Type II and ensure controls are working effectively.
- Work closely with Allegis Group IS and Information Security on corporate technology development to fully secure information computer network and processing systems.
- Review educate and enforce information security policies.
- Ensure that facilities premises and equipment of the corporate headquarters as well as local and global remote offices adhere to all applicable laws and regulations.
- In conjunction with Allegis Group IS Information Security and independently as needed providing resolution to security problems in a cost-effective manner.
- Promote and oversee strategic security relationships between internal resources and external entities including government vendors and partner organizations.
- Coordinate associated activities with employee/contractor end of assignment/de-provisioning project solutions.
Qualifications :
- University degree in the field of cybersecurity information services or business administration Masters in one these fields preferred.
- Certifications such as CISSP CISM Security CySA ITIL v3 and other information security or data privacy-related preferred but not required.
- 3- 5 years experience involved in or managing an IS team and/or security operations team.
- 7-10 years experience working in the IS industry or business operations.
- Experience in planning and executing security policies and standards development.
- Considerable knowledge of business theory business processes management budgeting and business office operations.
- Detailed knowledge of technology efforts regarding IS internal controls risk management information security legal contractual and litigation concerns.
- Good understanding of computer systems characteristics features and integration capabilities.
- Experience with common security certifications and frameworks such as SOC2 Type II ISO27001 CMMC and NIST.
- Knowledge of applicable global data privacy and security regulations.
- Ability to provide coaching and mentoring to team members in the areas of technical skills & competencies.
- In-depth knowledge of applicable laws and regulations as they relate to security and privacy.
- Proven leadership ability.
- Ability to set and manage priorities judiciously and independently.
- Excellent written and oral communication skills.
- Excellent interpersonal skills.
- Strong negotiating skills.
- Ability to present ideas in business-friendly and user-friendly language.
- Exceptionally self-motivated and directed.
- Superior analytical evaluative and problem-solving abilities.
- Exceptional service orientation.
- Ability to motivate in a team-oriented collaborative environment.
Employee Attributes
- Alignment with AGS Core Values:
- Commitment to Excellence
- Open Communication
- Relationships
- Serving Others
- Customer Service
- Building Relationships
- Business Knowledge / Organizational Acumen
- Initiative and Drive
- Leading Self and Others
Additional Information :
Per Pay Transparency Acts: The range for this position is $112500 bonus potential of up to $20000.
Benefits are subject to change and may be subject to specific elections plan or program terms. This role is eligible for the following:
- Medical dental & vision
- 401(k)/Roth
- Insurance (Basic/Supplemental Life & AD&D)
- Short and long term disability
- Health & Dependent Care Spending Accounts (HSA & DCFSA)
- Transportation benefits
- Employee Assistance Program
- Tuition assistance
- Time off/Leave (PTO primary caregiver/parental leave)
The company is an equal opportunity employer and will consider all applications without regard to race sex age color religion national origin veteran status disability sexual orientation gender identity genetic information or any characteristic protected by law. If you would like to request a reasonable accommodation such as the modification or adjustment of the job application process or interviewing process due to a disability please email for other accommodation options.
*Location disclaimer: this position is open to North America locations outside of California Colorado New Jersey New York and Washington.
Remote Work :
No
Employment Type :
Full-time
About Company
Working at Allegis Global Solutions (AGS) is more than just a job. Its a career. Its a community of people who invest in your development and empower you to blaze your own trail. Each of us is here to create real, measurable impact that moves needles. We operate beyond "roles" or "j ... View more