Subscribe job alerts


Remote Job

Business Information Security Manager

Altria
  • Posted : one year ago

Are you interested in managing a team that partners with technology leaders and supported business areas to provide thought leadership and information security guidance on a wide array of business strategy objectives for a fortune 200 company? If so, then we are looking for you!


We are currently seeking a highly motivated and qualified individual to join our IT Risk Management team in Richmond, VA as a Business Information Security Manager - BISM. The successful candidate will function in this role to support various business services and operating companies. We are open to remote working arrangements.


Responsibilities Include:

• Representing the Chief Information Security Officer (CISO) to Altria's business lines and/or operating companies, delivering comprehensive risk assessment and mitigation strategies crafted to improve the overall cybersecurity posture of the company.

• Managing the Business Information Security Officer (BISO) team in the delivery of comprehensive cyber services to improve risk understanding and cyber-strategies across the enterprise (e.g. corporate risk metrics)

• Crafting and managing a strategy, along with quality control, of routine BISO briefings to business executives on cybersecurity threats, initiatives and open risks. Managing BISO expectations to serve as liaisons to gather information on technology strategies within support business lines

• Interpreting information security policies, standards (i.e. NIST, CIS, OWASP, etc.), and other requirements with respect to specific internal information systems and assisting with the implementation of these and other information security requirements.

• Supporting the BISOs in providing business and technical advice on a variety of IT risk issues, concerns, problems, and projects ensuring all business processes incorporate adequate information security

• Developing and presenting security and compliance requirements to technology and system owners and key business partners in support of business-area initiatives

• Providing users and management with security guidance for selecting technology products, as well as ongoing integrations and improvements of such products

• Assessing and qualifying risk related to third party service providers and supporting the Supplier Risk Management program, including driving remediation of findings and supporting contract negotiations.

• Providing support for the Threat and Vulnerability Management program, including web application security, in-house IT environments and cloud-based infrastructure, driving risk insights via reporting in support of effective vulnerability management.

• Serving as a technical leader for periodic information system and application risk assessments, including those associated with the development of new or significantly improved business applications.

• Monitoring current and proposed laws, regulations, industry standards and ethical requirements related to IT risk, information security and privacy

• Providing support for internal security assessments and corporate audit assessments, including active engagement in high-risk auditable areas, risk management and remediation of audit findings, and ongoing information security governance.

• Ensuring BISOs serve as the SME for technology operating in their supported business lines, establishing strong working relationships with IT professionals supporting those systems, and supporting effective incident response.


Key Qualifications:

• Bachelor's degree in Computer Science, Information Systems, Engineering or related subject area

• 10+ years of IT experience with 6+ years in an IT risk or information security role.

• Broad knowledge of IT technologies, operating systems, application platforms and emerging technology.

• Detailed understanding of IT information security fundamentals, risk assessment and risk management fundamentals, defense-in-depth practices, modern networking technologies and IT security controls.

• Agile development practices (e.g. SecDevOps)

• Payment Card Industry Data Security Standard (PCI DSS) compliance

• NIST security controls frameworks, including the NIST Cyber Security Framework

• Excellent verbal and written communication and interpersonal skills.

• Certified Information System Security Professional (CISSP), Certified Information System Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or similar certification desired.

Skills
  • infosec
  • security
  • risk management
  • cyber security
  • cloud

Similar Jobs

Remote Job

OpenStack Cloud Engineer (DevOps)

VEXXHOST, Inc.
  • a month ago
  • We are seeking someone with a strong background in Linux and cloud technologies. In this role, you will not only support our customers using Atmosphere, our open-source cloud product, but also provide critical support to our internal CloudOps team that manages our public and private cloud infrastruc

Remote Job

Cybersecurity Writer (Remote)

Eleven Writing
  • a month ago
  • We are currently looking for writers with professional or first-hand experience in Cybersecurity and/or Digital Password Protection to help us create high-performing blog articles for our client who is a major player in the space of IT and Technology.Our ideal applicants have one or more of the foll

Remote Job

UX/UI Designer

Modivcare
  • 2 months ago
  • Are you passionate about making a difference in people's lives? Do you enjoy working in a service-oriented industry? If so, this opportunity may be the right fit for you!Modivcare is looking for an experienced UX/UI Designer. In this role, you will help establish the user experience by designing dig

Remote Job

Frontend Engineer

1st10
  • 3 months ago
  • 1st10 is a new recruiting venture that works with early-stage founders to build early engineering teams. The team behind 1st10 helped build early Robinhood, Pinterest, Ripple, Parse, Firebase and many more.-------------------------------------------------------------------------------Join a seed-fun

Remote Job

Marketing Specialist

Oter app
  • 3 months ago
  • Oter, a micro book appUnlock wisdom from the world’s greatest books with Oter. We are on a mission to make world’s books knowledge available to everyone. We are here to transform your reading experience by making reading easy, convenient, social and fun. Marketing specialist at OterWe are seekin

Remote Job

Sales Representative - Cloud Infrastructure

VEXXHOST, Inc.
  • 3 months ago
  • About VEXXHOSTVEXXHOST specializes in providing high-performance cloud solutions, leveraging a fully integrated OpenStack environment to deliver scalable and secure infrastructure services for businesses of all sizes.About the Role:We are seeking a motivated and results-driven Sales Representative w

Remote Job

Marketing Specialist

Oter app
  • 3 months ago
  • Oter, a micro book appUnlock wisdom from the world’s greatest books with Oter. We are on a mission to make world’s books knowledge available to everyone. We are here to transform your reading experience by making reading easy, convenient, social and fun. Marketing specialist at OterWe are seekin

Remote Job

Senior Data Engineer

Proxify
  • 3 months ago
  • About us:Talent has no borders. Proxify's mission is to connect top developers around the world with opportunities they deserve. So, it doesn't matter where you are; we are here to help you fast-track your independent career in the right direction. 🙂Since our launch, Proxify's develop

Remote Job

Marketing Specialist

Oter app
  • 3 months ago
  • Oter, a micro book appUnlock wisdom from the world’s greatest books with Oter. We are on a mission to make world’s books knowledge available to everyone. We are here to transform your reading experience by making reading easy, convenient, social and fun. Marketing specialist at OterWe are seekin

Remote Job

Senior IT Writer

Jumpfactor Marketing
  • 3 months ago
  • Jumpfactor is an Award-winning 6-time Growth500 Fastest Growing Agency in Canada, and we are expanding our team to include international talent. We are a dynamic, fast-paced, and integrated digital inbound marketing agency. Our expertise lies in B2B services and technology marketing.If you are a sma

View All