Find your dream job faster with JobLogr
AI-powered job search, resume help, and more.
Try for Free
WSP

WSP

via Oraclecloud

All our jobs are verified from trusted employers and sources. We connect to legitimate platforms only.

Business Information Security Officer- Digital and Industrial Solutions

New York, New York
Full-time
Posted 8/10/2026
Direct Apply
Key Skills:
Information security
Risk management
Compliance

Compensation

Salary Range

$85K - 130K a year

Responsibilities

Lead security for digital and industrial solutions, integrating security-by-design and managing product security risks.

Requirements

Bachelor's degree and 12+ years senior-level info security experience with certifications like CISSP or CISM.

Full Description

Position Summary WSP’s Information Security Office (ISO) is responsible for the deployment of the information security framework across both the IT organisation and the wider business community. This includes the governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our clients. The Business Information Security Officer (BISO) – Digital & Industrial Solutions is a business-facing role dedicated to securing the digital and industrial solutions that WSP’s business lines design, build and bring to market for external customers and for general consumption. This role focuses on the security of the products, platforms and services WSP sells, ensuring that security, privacy and trust are engineered into every solution from concept through go-to-market and ongoing operation. This is a role at the intersection of technology, security, innovation and commercial strategy. The BISO works hand-in-hand with the Digital Solutions team, product managers, engineering and architecture, and go-to-market functions to embed security-by-design, meet customer and regulatory security expectations, and position security as a competitive differentiator that accelerates sales rather than slowing them. This position requires a senior professional who combines strong information and product security expertise with genuine commercial and product acumen — comfortable in engineering and DevOps environments, fluent in cloud-native, application, data and operational-technology (OT/IoT) security, and equally capable of engaging engineers, executives and customers.    Responsibilities * Product security ownership — serve as the single point of security accountability for WSP’s externally-facing digital and industrial solutions — the products, platforms and services built by the business lines for customers and for commercial sale. * Security-by-design partnership — partner directly with the Digital Solutions team, product owners, engineering and architecture leaders to embed security-by-design and privacy-by-design across the full solution lifecycle, from ideation and business case through development, launch and ongoing operation. * Secure development lifecycle — Govern a Secure SDLC / DevSecOps model for solution teams, including threat modelling, secure-coding standards, code and dependency scanning (SAST/DAST/SCA), CI/CD pipeline security, vulnerability management and pre-release penetration testing. * Solution security architecture — provide security architecture guidance for cloud-native, data-intensive, AI/ML and connected (IoT/OT) solutions, ensuring appropriate controls for multi-tenant platforms, customer-data protection, identity and access, and secure integration with third-party and client systems. * Product risk management — identify, assess, document and track security risks in each solution; drive remediation with delivery teams; and provide clear, risk-based reporting to business and CISO leadership. * Go-to-market and sales enablement — act as security authority for bids, proposals and customer engagements — responding to customer security questionnaires and due-diligence requests, articulating each solution’s security posture, and helping win and retain business by giving customers confidence in WSP’s solutions. * Compliance and certification — establish and evidence the security certifications, attestations and compliance the market expects of commercial solutions (e.g., ISO/IEC 27001, SOC 2, and industry-, region- and contract-specific obligations), and maintain the artefacts needed to demonstrate them to customers and auditors. * Supply-chain and third-party security — manage third-party, open-source and supply-chain security for solution components, including software bill of materials (SBOM), vendor security assessment, and secure use of external  * Innovation and emerging technology — track emerging technology (AI and generative AI, digital twins, edge/OT, connected infrastructure) and translate new threats and opportunities into practical guidance so the business can innovate safely and at speed. * Global framework alignment — work with the CISO and ISO on the Global Information Security Framework — adapting corporate policies and standards for the product/solutions context, feeding product-security requirements back into the framework, and providing regular reporting on solution-security posture and metrics. * Security culture — build security awareness and capability within solution and engineering teams, championing a culture in which product and engineering teams own security as part of quality.   Leadership and People Responsibilities   * Displays leadership and independence in performing the role, with the ability to make complex, business-impacting decisions with limited input and review from senior staff. * High level of personal integrity, and the ability to professionally handle confidential matters with the appropriate level of judgment and maturity. * Builds trusted, influential relationships with product, engineering, commercial and executive stakeholders — leading through influence rather than authority. * Capable of rapidly assimilating and internalizing complex business, technology, product and risk-management concepts and their dependencies. * Capable of clearly defining, presenting and selling recommended security strategies to senior management, engineering teams and customers. * Coaches and uplifts solution and engineering teams on secure-development and risk-assessment practices. * Critical thinker with strong problem-solving, project-management, prioritisation, scheduling and resource-management skills. * Excellent written and verbal communication, interpersonal and collaborative skills, with the ability to translate between engineering, business and customer audiences. * Accommodation of schedule for international collaboration and conference calls across time zones.   Requirements Required   * Bachelor's degree or equivalent * 12+ years of related senior-level experience in information security, with meaningful exposure to product, application or cloud security and to software / solution delivery. * Demonstrated experience securing customer-facing products, SaaS or cloud platforms, or digital services — as opposed to purely internal enterprise IT. * Working knowledge of secure software development and DevSecOps practices — threat modelling, secure coding, SAST / DAST / SCA, CI/CD security, and vulnerability and patch management. * Working knowledge of cloud-native security across major providers (e.g., Azure, AWS, GCP), including identity, network, data-protection and workload security. * Familiarity with application, API and data security, encryption, authentication and authorisation, PKI, and secure integration patterns. * Professional certification in one or more relevant disciplines — e.g., CISSP, CISM, CCSP, CSSLP, or a recognised cloud-security certification; IT governance (CGEIT) or audit (CISA) an asset. * Experience with security and IT governance frameworks such as ISO/IEC 2700x, NIST, SOC 2, COBIT and ITIL. * Experience of risk management — risk analysis, mitigation and monitoring — in a delivery or engineering context. * Knowledge of information security and privacy regulations applicable to WSP and to the markets its solutions serve.   Preferred * Experience with operational-technology (OT), industrial control systems (ICS / SCADA), IoT or connected-infrastructure security. * Exposure to AI / ML and generative-AI security. * Experience supporting sales, bids or customer security due diligence, and responding to customer security assessments. * Experience achieving or maintaining product / service security certifications (e.g., ISO/IEC 27001, SOC 2 Type II). * Product-management, go-to-market or commercial experience alongside a security background. * Master’s degree in IT, computer science, engineering or a related field.     WSP Benefits: WSP provides a comprehensive suite of benefits focused on a providing health and financial stability throughout the employee’s career. These benefits include coverage related to medical, dental, vision, disability, and life; retirement savings; paid sick leave; paid vacation (or other personal time); paid parental leave; and paid time off for purposes of bereavement, voting, and/or attendance at naturalization proceedings.  Compensation: Expected Salary (all locations): $153,400.00 - $257,800.00 WSP USA is providing the compensation range that the company in good faith believes it might pay and offer for this position, based on the successful applicant’s education, experience, knowledge, skills, abilities in addition to internal equity and specific geographic location. WSP USA reserves the right to ultimately pay more or less than the posted range and offer additional benefits and other compensation, depending on circumstances not related to an applicant’s sex or other status protected by local, state, and/or federal law. Expected Salary (Colorado only): $153,400.00 - $241,900.00 WSP USA is providing the compensation range that the company in good faith believes it might pay and/or offer for this position within the state of Colorado, based on the successful applicant’s education, experience, knowledge, skills, and abilities in addition to internal equity and specific geographic location. WSP USA reserves the right to ultimately pay more or less than the posted range and offer additional benefits and other compensation, depending on circumstances not related to an applicant’s sex or other status protected by local, state, and/or federal law.   About WSP WSP USA is the U.S. operating company of WSP, one of the world's leading engineering and professional services firms. Dedicated to serving local communities, we are engineers, planners, technical experts, strategic advisors and construction management professionals. WSP USA designs lasting solutions in the buildings, transportation, energy, water and environment markets. With more than 15,000 employees in over 300 offices across the U.S., we partner with our clients to help communities prosper. www.wsp.com [https://www.wsp.com/] WSP provides a flexible and agile workplace model while meeting client needs. Employees are also afforded a comprehensive suite of benefits including medical, dental, vision, disability, life, and retirement savings focused on providing health and financial stability throughout the employee’s career. At WSP, we want to give our employees the challenges they seek to grow their careers and knowledge base. Your daily contributions to your team will be essential in meeting client objectives, goals and challenges. Are you ready to get started? WSP USA (and all of its U.S. companies) is an Equal Opportunity Employer Race/Age/Color/Religion/Sex/Sexual Orientation/Gender Identity/National Origin/Disability or Protected Veteran Status. The selected candidate must be authorized to work in the United States. NOTICE TO THIRD PARTY AGENCIES: WSP does not accept unsolicited resumes from recruiters, employment agencies, or other staffing services. Unsolicited resumes include any resume or hiring document sent to WSP in the absence of a signed Service Agreement where WSP has expressly requested recruitment/staffing services specific to the position at hand.  Any unsolicited resumes, including those submitted to hiring managers or other business leaders, will become the property of WSP and WSP will have the right to hire that candidate without reservation – no fee or other compensation will be owed or paid to the recruiter, employment agency, or other staffing service.

This job posting was last updated on 8/12/2026

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt