Information Security Engineer – Deputy BISO
Job: Information Security Engineer – Deputy BISO
Location: Bangalore
Job description: The Information Security Engineer – Deputy BISO will support the Business Information Security Officer (BISO) in managing day-to-day information security engagement with the business. The role will serve as a key security partner to business and technology stakeholders, providing security consultation, risk management support, governance oversight, and coordination across Information Security teams.
Responsibilities:
• Serve as the primary point of contact for day-to-day information security engagement with business and technology stakeholders.
• Partner with business leaders to understand strategic priorities, technology initiatives, associated security risks and requirements.
• Provide security consultation and guidance for new projects, applications, technology implementations and business initiatives.
• Ensure security requirements and risk considerations are incorporated early in project, product and technology lifecycles.
• Identify, assess, document, communicate and track information security risks impacting the business.
• Support security risk assessments, risk acceptances, exceptions, remediation plans and risk-based decision making.
• Track security risks, vulnerabilities, findings and remediation activities through appropriate closure and escalation.
• Coordinate with Security Architecture, Application Security, Cloud Security, IAM, Data Security, Vulnerability Management and other security teams to address business security requirements.
• Support execution of BISO governance processes and monitor adherence to applicable security policies, standards and controls.
• Facilitate coordination between business, technology, risk, compliance, audit and Information Security stakeholders to resolve security issues and dependencies.
• Represent Information Security and the BISO function in relevant business, technology, project and governance forums.
• Maintain BISO security metrics, KPIs, KRIs, risk dashboards and management reporting to provide visibility into the business security posture.
• Identify emerging, systemic or material security risks and ensure timely escalation to the BISO and appropriate leadership.
• Support strategic business, digital transformation, cloud, technology and third-party initiatives by providing risk based security guidance while minimizing unnecessary business friction.
Required Qualifications:
• Experience in Information Security, Security Architecture, Security Governance or a related field.
• Experience working with business and technology stakeholders on security requirements and risk decisions.
• Working knowledge of areas such as application security, cloud security, IAM, data protection, vulnerability management, and third-party security.
• Experience supporting security assessments, risk remediation, governance or compliance activities.
• Strong stakeholder management, communication and influencing skills.
• Ability to translate technical security risks into clear business impact and actionable recommendations.
• Ability to independently manage multiple priorities, stakeholder requests, and security initiatives.
• Knowledge of cybersecurity frameworks and standards such as NIST CSF, ISO 27001, CIS Controls, or similar.
• Understanding of regulatory, compliance, and technology risk management requirements.
• Relevant certifications such as CISSP, CISM, CRISC, CCSP, or equivalent are advantageous.