Business Information Security Officer

  • Full-time

Company Description

Working at Allegis Global Solutions (AGS) is more than just a job. It’s a career. It’s a community of people who invest in your development and empower you to blaze your own trail. Each of us is here to create real, measurable impact that moves needles. We operate beyond "roles" or "jobs" to realize the opportunity to make meaningful contributions to a bigger idea. Because we believe that when you build a workforce that’s designed to harness human enterprise, you design a workforce that’s built for impact.

At AGS, we help companies all over the world transform their people into a competitive advantage. It’s not about filling seats. It’s about designing workforces to meet missions and unleash the most transformative power in business today: The power of human enterprise.

With services around the globe, we have a point of view on the future of work that enables us to be a transformative partner in the way work gets done for our clients’ organizations. Meeting clients where they are, we design a plan and guide them along a transformational journey, applying bold actions and diverse minds to solve the most complex challenges – from permanent and extended workforce management to services procurement, consulting, direct sourcing and our Universal Workforce Model™.

We also represent over 100 countries and speak dozens of languages. So as you’re building relationships and doing your job, you’ll be exposed to other cultures and advancement opportunities while expanding your knowledge of global markets and strategies.

See what it’s like to work at AGS by searching #LifeAtAGS on any social network.

Job Description

The BISO’s primary responsibility is to ensure that Allegis Global Solutions, Inc.’s (AGS) information security and data privacy initiatives support the global business strategy while complying with industry best practices, cybersecurity frameworks, such as NIST Cybersecurity (CSF) and Privacy Frameworks and ISO27001, and in alignment with the parent company’s policies and standards. In conjunction with the Head of Global Information Security of Allegis Group, Inc., the parent company, the AGS BISO will provide vision and leadership for developing and supporting information security and data privacy initiatives in a ‘federated’ environment (at an operating company level in concert with a shared services corporate model) and  will oversee and direct the implementation of controls designed to protect the confidentiality, integrity and availability of the data that AGS processes internally and on behalf of its customers. This individual is also responsible for evaluating, auditing and making recommendations regarding existing business operations and systems, protecting against security and privacy breaches and vulnerabilities, while directing the administration and education of security policies, activities and standards. Information security and data privacy functions align to the Risk Team managed by the AGS Global Director of Risk and Compliance.

Key Responsibilities:

Strategy & Planning

  • On an ongoing basis, evaluate the information security and data privacy posture for AGS and provide a regular update to the Global Director of Risk and Compliance as well as make recommendations for future state to address evolving business needs and minimize risk to the organization.
  • Participate as a member of the global enterprise risk team in governance processes of the organization’s security and privacy strategies.
  • Recommend and implement changes in security and data privacy policies and practices in accordance with changes in local, federal or international regulation.
  • Develop and communicate security and privacy strategies and plans to executive team, staff, partners, customers and stakeholders.
  • Remain informed on trends and issues in the security industry, including current and emerging technologies. Advise, counsel and educate executive and leadership teams on their relative importance and financial impact.

Operational Management

  • Act as advocate and primary liaison for AGS’ security vision via regular written and in-person communications with executives, leadership and end users.
  • Participate in customer and vendor contract review/negotiations on information security and data privacy. Provide training and guidance in conjunction with the legal department on these topics periodically.
  • Supervise recruitment, development, retention and organization of security and privacy staff in accordance with AGS budgetary objectives and personnel policies.
  • Oversee responses to customer security questionnaires and liaise with AGS program teams and customers, as needed.
  • Oversee the AGS Security Incident Response Process (SIRP) and ensure alignment with the Allegis Group Information Security team.
  • In coordination with a third-party auditor, oversee security certification audits such as SOC1/SOC2 Type II and ensure controls are working effectively.
  • Work closely with Allegis Group IS and Information Security on corporate technology development to fully secure information, computer, network and processing systems.
  • Review, educate and enforce information security policies.
  • Ensure that facilities, premises and equipment of the corporate headquarters as well as local and global remote offices adhere to all applicable laws and regulations.
  • In conjunction with Allegis Group IS, Information Security and independently as needed, providing resolution to security problems in a cost-effective manner.
  • Promote and oversee strategic security relationships between internal resources and external entities including government, vendors and partner organizations.
  • Coordinate associated activities with employee/contractor end of assignment/de-provisioning project solutions.

Qualifications

  • University degree in the field of cybersecurity, information services or business administration, Master’s in one these fields preferred.
  • Certifications such as CISSP, CISM, Security +, CySA+, ITIL v3 and other information security or data privacy-related preferred, but not required.
  • 3- 5 years’ experience involved in or managing an IS team and/or security operations team.
  • 7-10 years’ experience working in the IS industry or business operations.
  • Experience in planning and executing security policies and standards development.
  • Considerable knowledge of business theory, business processes, management, budgeting and business office operations.
  • Detailed knowledge of technology efforts regarding IS internal controls, risk management, information security, legal, contractual and litigation concerns.
  • Good understanding of computer systems characteristics, features and integration capabilities.
  • Experience with common security certifications and frameworks such as SOC2 Type II, ISO27001, CMMC and NIST.
  • Knowledge of applicable global data privacy and security regulations.
  • Ability to provide coaching and mentoring to team members in the areas of technical skills & competencies.
  • In-depth knowledge of applicable laws and regulations as they relate to security and privacy.
  • Proven leadership ability. 
  • Ability to set and manage priorities judiciously and independently.
  • Excellent written and oral communication skills.
  • Excellent interpersonal skills.
  • Strong negotiating skills.
  • Ability to present ideas in business-friendly and user-friendly language.
  • Exceptionally self-motivated and directed.
  • Superior analytical, evaluative and problem-solving abilities.
  • Exceptional service orientation.
  • Ability to motivate in a team-oriented, collaborative environment.

 

Employee Attributes

  • Alignment with AGS Core Values:
    • Commitment to Excellence
    • Open Communication
    • Relationships
    • Serving Others
  • Customer Service
  • Building Relationships
  • Business Knowledge / Organizational Acumen
  • Initiative and Drive
  • Leading Self and Others

Additional Information

Per Pay Transparency Acts: The range for this position is $112,500 + bonus potential of up to $20,000. 

Benefits are subject to change and may be subject to specific elections, plan, or program terms. This role is eligible for the following:

  • Medical, dental, & vision
  • 401(k)/Roth
  • Insurance (Basic/Supplemental Life & AD&D)
  • Short and long term disability
  • Health & Dependent Care Spending Accounts (HSA & DCFSA)
  • Transportation benefits
  • Employee Assistance Program
  • Tuition assistance
  • Time off/Leave (PTO, primary caregiver/parental leave)

The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law. If you would like to request a reasonable accommodation, such as the modification or adjustment of the job application process or interviewing process due to a disability, please email [email protected] for other accommodation options.

*Location disclaimer:  this position is open to North America locations outside of California, Colorado, New Jersey, New York and Washington.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy Notice