Delan Associates, Inc

Senior BISO Engineer (Cybersecurity)

Delan Associates, Inc Houston, Texas, United States

51-200 employees

Yesterday
security Senior (5-10 yrs) Contractor United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The BISO Engineer acts as an embedded cybersecurity liaison to bridge enterprise security strategy with operational technology environments. They are responsible for conducting risk assessments, managing security initiatives, and ensuring compliance across business unit infrastructure.

What they look for

Cybersecurity Engineering Risk Management WAF NGFW Palo Alto SIEM Vulnerability Management NIST CSF CMMC Identity & Access Management Cloud Security OT/ICS Network Segmentation Incident Response Security Governance M&A Integration

Requirements

Candidates must have at least 5 years of experience in cybersecurity engineering, architecture, or risk management. Proficiency with security platforms like WAF, SIEM, and NGFW, along with knowledge of frameworks like NIST CSF or CMMC, is required.

Full description

The BISO (Business Information Security Officer) Engineer serves as an embedded cybersecurity practitioner within a assigned business unit, bridging the gap between enterprise security strategy and day-to-day operational technology environments. This role partners closely with IT, OT, and business stakeholders to identify risk, drive remediation, and translate security requirements into actionable programs.

Key Responsibilities Serve as the primary cybersecurity liaison for assigned business unit(s), translating enterprise security policies into unit-specific controls and procedures Conduct and support risk assessments, vulnerability management reviews, and security posture evaluations across applications, infrastructure, and OT environments Lead or support security initiatives including WAF/firewall configurations, identity & access management reviews, endpoint protection, and cloud security posture Represent the business unit in change management and security governance forums Coordinate with enterprise SIEM (Splunk), network security (Palo Alto/Panorama), and application security platforms (e.g., Imperva Cloud WAF) to ensure appropriate monitoring and enforcement Support M&A integration activities including network segmentation, firewall onboarding, and security baseline validation Develop and maintain security documentation: policies, runbooks, risk acceptance memos, and remediation plans Engage stakeholders across technical and leadership levels; present risk posture and program status to senior management.

Required: 5+ years in cybersecurity engineering, architecture, or risk management Hands-on experience with WAF, NGFW (Palo Alto preferred), SIEM, or vulnerability management platforms Strong understanding of NIST CSF, CMMC, or equivalent frameworks Proven ability to manage cross-functional security programs with minimal oversight

Preferred: Experience in energy, utilities, or OT/ICS environments Familiarity with Imperva Cloud WAF, Illumio, Splunk, or Panorama CISSP, CISM, or equivalent certification Experience supporting M&A cybersecurity integration

Similar roles