Point your AI agent at freehire and let it find you a job.

Get the CLI →

delan-associates-inc

NewBe an early applicant

Senior BISO Engineer (Cybersecurity)

Posted Updated
Discussion

Summary

An embedded cybersecurity engineer (BISO) who acts as the security liaison for a business unit, running risk assessments, driving remediation, and translating enterprise security policy into operational controls across IT and OT environments. Core tooling includes Palo Alto/Panorama firewalls, Splunk SIEM, Imperva Cloud WAF, and cloud/endpoint security platforms.

The BISO (Business Information Security Officer) Engineer serves as an embedded cybersecurity practitioner within a assigned business unit, bridging the gap between enterprise security strategy and day-to-day operational technology environments. This role partners closely with IT, OT, and business stakeholders to identify risk, drive remediation, and translate security requirements into actionable programs.

Key Responsibilities
Serve as the primary cybersecurity liaison for assigned business unit(s), translating enterprise security policies into unit-specific controls and procedures
Conduct and support risk assessments, vulnerability management reviews, and security posture evaluations across applications, infrastructure, and OT environments
Lead or support security initiatives including WAF/firewall configurations, identity & access management reviews, endpoint protection, and cloud security posture
Represent the business unit in change management and security governance forums
Coordinate with enterprise SIEM (Splunk), network security (Palo Alto/Panorama), and application security platforms (e.g., Imperva Cloud WAF) to ensure appropriate monitoring and enforcement
Support M&A integration activities including network segmentation, firewall onboarding, and security baseline validation
Develop and maintain security documentation: policies, runbooks, risk acceptance memos, and remediation plans
Engage stakeholders across technical and leadership levels; present risk posture and program status to senior management.

Required:
5+ years in cybersecurity engineering, architecture, or risk management
Hands-on experience with WAF, NGFW (Palo Alto preferred), SIEM, or vulnerability management platforms
Strong understanding of NIST CSF, CMMC, or equivalent frameworks
Proven ability to manage cross-functional security programs with minimal oversight

Preferred:
Experience in energy, utilities, or OT/ICS environments
Familiarity with Imperva Cloud WAF, Illumio, Splunk, or Panorama
CISSP, CISM, or equivalent certification
Experience supporting M&A cybersecurity integration

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available