Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI
Audit
Communication @ 3
Compliance
Dashboarding
Microsoft 365 @ 6
Python @ 6
Reporting @ 6
SQL @ 6
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
As a Business Information Security Officer (BISO) for Finance, you will protect the confidentiality, integrity, and availability of the Finance department’s information assets. You will identify and assess security risks and vulnerabilities, enforce security policies and controls, and partner with Finance leadership to ensure a secure posture that supports business needs and critical activities while aligning with the organization’s risk appetite and regulatory obligations.
This role extends beyond a traditional advisory BISO model, with end-to-end ownership of DLP and surveillance controls, including active monitoring, investigation of data events, and escalation of policy violations and high-risk activity within the Finance environment. You will serve as the accountable security control lead for Finance, ensuring controls are effective and continuously enhancing and scaling these capabilities as business risk, workflows, and technology evolve.
Responsibilities
- Serve as the Business Information Security Officer representative for the Finance organization, aligning information security strategy with business objectives, risk tolerance, and regulatory requirements.
- Partner with Finance leadership to identify, assess, and prioritize information security risks, translating technical findings into business impact and actionable mitigation strategies.
- Provide security oversight for secure configuration and governance across collaboration platforms, including Microsoft 365 in single-tenant and multi-tenant environments.
- Advise on secure data-sharing practices for sensitive financial, regulatory, and strategic data shared across internal teams and third parties.
- Lead and support risk assessments and security reviews for Finance systems, workflows, and third-party vendors. Communicate identified risks, recommended mitigation strategies, and formal risk acceptance requirements to business leadership.
- Oversee and administer Data Loss Prevention (DLP) and surveillance controls, including policy tuning and alert review to reduce data-exfiltration risks and policy violations.
- Investigate data events and potential incidents, escalate high-risk findings to appropriate leadership, and drive remediation to closure.
- Review and interpret security monitoring logs, alerts, and metrics to identify trends, emerging risks, and control gaps.
- Collaborate with Security, Technology, Legal and Compliance, Risk, and Finance stakeholders to provide cohesive security support.
- Synthesize complex datasets, including metrics, event trends, and audit findings, into actionable insights using Excel, Qlik, or similar dashboarding tools.
- Create tailored cybersecurity training and tabletop sessions for the Finance population.
- Deliver executive-ready reporting and presentations that articulate risk exposure, control effectiveness, and recommended remediation strategies.
- Provide security oversight for new business workflows, SaaS applications, and AI tools, ensuring appropriate risk assessment and control implementation before deployment.
Requirements
- Experience in information security, technology risk, or cyber risk management, preferably in financial services or another highly regulated environment.
- Strong understanding of Microsoft 365 architecture, including identity and access management, tenant configurations, single-tenant and multi-tenant models, and secure collaboration controls.
- Experience implementing or governing secure cloud collaboration environments at scale.
- Hands-on experience with DLP technologies, surveillance programs, data classification frameworks, and secure data-handling practices.
- Experience conducting and documenting risk assessments, control testing, and gap analyses.
- Familiarity with security monitoring, log analysis, and incident response processes.
- Ability to work across business, technology, and security stakeholders to influence risk-based decisions.
- Strong analytical skills, including the ability to synthesize large datasets using Excel, Qlik, or similar reporting tools.
- Excellent written and verbal communication skills, with the ability to present complex risk concepts clearly to senior business leaders.
- Ability to manage multiple projects, prioritize work, and develop and communicate timelines.
- Ability to work independently and collaboratively in a fast-paced environment.
- Strong analytical and creative problem-solving skills, with the ability to develop innovative, data-driven solutions.
- Strong attention to detail.
Preferred Qualifications
- Professional certifications such as CISSP, CISM, or similar.
- Experience supporting Finance, Treasury, or Regulatory Reporting functions.
- Knowledge of financial regulations affecting data protection and recordkeeping, such as SOX, SEC, FINRA, DORA, or global equivalents.
- Background in surveillance monitoring programs or insider-threat risk management.
- A proactive, solutions-oriented mindset with a strong sense of ownership and accountability.
- Advanced systems experience with SQL databases and Python.
Compensation And Benefits
The salary range is $215,000–$290,000 USD annually, plus benefits and bonus. Actual compensation may vary based on geographic location, work experience, market conditions, education, training, and skill level.
Benefits may include merit increases, incentive compensation for exempt roles, paid holidays, paid time off, medical, dental, vision, short- and long-term disability benefits, a 401(k) match, life insurance, and wellness programs.