Senior BISO Engineer (Cybersecurity)
Delan Associates, Inc Houston, Texas, United States
51-200 employees
About the role
The BISO Engineer acts as an embedded cybersecurity liaison to bridge enterprise security strategy with operational technology environments. They are responsible for conducting risk assessments, managing security initiatives, and ensuring compliance across business unit infrastructure.
What they look for
Requirements
Candidates must have at least 5 years of experience in cybersecurity engineering, architecture, or risk management. Proficiency with security platforms like WAF, SIEM, and NGFW, along with knowledge of frameworks like NIST CSF or CMMC, is required.
Full description
The BISO (Business Information Security Officer) Engineer serves as an embedded cybersecurity practitioner within a assigned business unit, bridging the gap between enterprise security strategy and day-to-day operational technology environments. This role partners closely with IT, OT, and business stakeholders to identify risk, drive remediation, and translate security requirements into actionable programs.
Key Responsibilities Serve as the primary cybersecurity liaison for assigned business unit(s), translating enterprise security policies into unit-specific controls and procedures Conduct and support risk assessments, vulnerability management reviews, and security posture evaluations across applications, infrastructure, and OT environments Lead or support security initiatives including WAF/firewall configurations, identity & access management reviews, endpoint protection, and cloud security posture Represent the business unit in change management and security governance forums Coordinate with enterprise SIEM (Splunk), network security (Palo Alto/Panorama), and application security platforms (e.g., Imperva Cloud WAF) to ensure appropriate monitoring and enforcement Support M&A integration activities including network segmentation, firewall onboarding, and security baseline validation Develop and maintain security documentation: policies, runbooks, risk acceptance memos, and remediation plans Engage stakeholders across technical and leadership levels; present risk posture and program status to senior management.
Required: 5+ years in cybersecurity engineering, architecture, or risk management Hands-on experience with WAF, NGFW (Palo Alto preferred), SIEM, or vulnerability management platforms Strong understanding of NIST CSF, CMMC, or equivalent frameworks Proven ability to manage cross-functional security programs with minimal oversight
Preferred: Experience in energy, utilities, or OT/ICS environments Familiarity with Imperva Cloud WAF, Illumio, Splunk, or Panorama CISSP, CISM, or equivalent certification Experience supporting M&A cybersecurity integration
Similar roles
-
Senior Cybersecurity Engineer
Votaw Precision Technologies LLC Santa Fe Springs, California, United States · $125K–$175K/yr
-
Sr. Application Security Engineer
SentinelOne United States · $132K–$160K/yr
-
Cloud Security Engineer - Public Sector, IT Operations
BDO USA, P.C. Mclean, Virginia, United States · $105K–$120K/yr
-
Senior Software Security Engineer
Valar Atomics Torrance, California, United States · $175K–$200K/yr
-
Staff Security Engineer, Product & Platform Security
Nscale San Francisco, California, United States · $190K–$240K/yr
-
Staff Cyber Security Engineer
NBCUniversal New York, New York, United States · $125K–$155K/yr