Senior BISO Engineer (Cybersecurity)

Delan Associates, Inc

  • Houston, TX
  • 10 days ago

    Highlights

    The BISO (Business Information Security Officer) Engineer serves as an embedded cybersecurity practitioner within a assigned business unit, bridging the gap between enterprise security strategy and day-to-day operational technology environments. Coordinate with enterprise SIEM (Splunk), network security (Palo Alto/Panorama), and application security platforms (e.g., Imperva Cloud WAF) to ensure appropriate monitoring and enforcement.

    Numbers & Facts

    LocationHouston, TX

    Description

    The BISO (Business Information Security Officer) Engineer serves as an embedded cybersecurity practitioner within a assigned business unit, bridging the gap between enterprise security strategy and day-to-day operational technology environments. This role partners closely with IT, OT, and business stakeholders to identify risk, drive remediation, and translate security requirements into actionable programs.

    Key Responsibilities
    Serve as the primary cybersecurity liaison for assigned business unit(s), translating enterprise security policies into unit-specific controls and procedures
    Conduct and support risk assessments, vulnerability management reviews, and security posture evaluations across applications, infrastructure, and OT environments
    Lead or support security initiatives including WAF/firewall configurations, identity & access management reviews, endpoint protection, and cloud security posture
    Represent the business unit in change management and security governance forums
    Coordinate with enterprise SIEM (Splunk), network security (Palo Alto/Panorama), and application security platforms (e.g., Imperva Cloud WAF) to ensure appropriate monitoring and enforcement
    Support M&A integration activities including network segmentation, firewall onboarding, and security baseline validation
    Develop and maintain security documentation: policies, runbooks, risk acceptance memos, and remediation plans
    Engage stakeholders across technical and leadership levels; present risk posture and program status to senior management.

    Required:
    5+ years in cybersecurity engineering, architecture, or risk management
    Hands-on experience with WAF, NGFW (Palo Alto preferred), SIEM, or vulnerability management platforms
    Strong understanding of NIST CSF, CMMC, or equivalent frameworks
    Proven ability to manage cross-functional security programs with minimal oversight

    Preferred:
    Experience in energy, utilities, or OT/ICS environments
    Familiarity with Imperva Cloud WAF, Illumio, Splunk, or Panorama
    CISSP, CISM, or equivalent certification
    Experience supporting M&A cybersecurity integration

    Similar Jobs

    See more jobs