×
Register Here to Apply for Jobs or Post Jobs. X

Business Information Security Officer; BISO

Job in Chandler, Maricopa County, Arizona, 85249, USA
Listing for: Avnet US
Full Time position
Listed on 2026-06-02
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, Data Security
Salary/Wage Range or Industry Benchmark: 80000 - 100000 USD Yearly USD 80000.00 100000.00 YEAR
Job Description & How to Apply Below
Position: Business Information Security Officer (BISO)

The Business Information Security Officer (BISO) serves as a strategic partner to Avnet’s global business operations - enabling the business to operate securely, grow confidently, and deliver value to customers.

Acting as a trusted advisor and embedded security leader, the BISO works across business, technology, and cybersecurity teams to ensure security is seamlessly integrated into business processes, decision‑making, and innovation. This role focuses on reducing friction, clarifying risk, and accelerating secure outcomes while aligning to enterprise cybersecurity strategy.

The BISO partners with the business to balance risk, speed, and opportunity, helping teams move forward with revenue growth opportunities.

Business Unit Alignment & Intake
  • Serve as the primary cybersecurity advisor to assigned business units, building strong, trust‑based relationships.
  • Actively engage with business leaders to understand priorities, challenges, and growth initiatives.
  • Ensure security is embedded early in planning to enable faster, more informed decision‑making.
  • Provide consistent, responsive, and business‑aligned security support.
System Assessments, Categorization & Control Selection
  • Apply practical, risk‑based assessment methodologies aligned to business context.
  • Recommend right‑sized security controls based on operational context and regulatory requirements.
  • Prevent over‑ or under‑engineering of controls, reducing friction for business teams.
Risk Translation, Prioritization & Action Planning
  • Translate complex technical risks into clear business‑impact language (financial, operational, customer trust, and compliance) for executives.
  • Enable business leaders to make informed, risk‑based decisions with confidence.
  • Partner with teams to define actionable remediation strategies, compensating controls, and acceptable risk positions.
  • Promote transparency so risks are clearly understood.
Local Governance & Risk Visibility
  • Establish recurring governance touchpoints within each business unit.
  • Provide transparency into security posture, risk hot spots, and upcoming compliance obligations.
  • Support clear ownership and drive accountability for managing risk.
Escalation of Business‑Specific Risks & Project Needs
  • Represent business priorities within enterprise cybersecurity discussions.
  • Surface business‑unit‑specific risks and needs to enterprise cybersecurity leadership.
  • Advocate for solutions that align security expectations with business realities.
  • Help ensure enterprise priorities are informed by emerging risk and business needs.
Vulnerability Management & Secure Baseline Adoption
  • Support business units in meeting vulnerability remediation SLAs.
  • Help teams understand the business impact of exposures and coordinate remediation with IT Ops and Engineering.
  • Promote and monitor adoption of secure configuration baselines across all systems.
Representation of Business Interests in Security, Sales & Revenue Activities
  • Provide security expertise for customer‑facing functions such as supply chain solutions, design services, and digital platforms.
  • Support sales cycles, customer trust discussions, and contract/audit responses.
  • Position cybersecurity investments as competitive differentiators for revenue‑critical offerings.
Certification & Regulatory Compliance Support
  • Support business units in obtaining, maintaining, and preparing for security and compliance certifications—including CMMC, ISO 27001, UK Cyber Essentials, and NIS2—by guiding control implementation, evidence collection, readiness assessments, and audit interactions.
  • Assist the business in meeting ongoing regulatory and compliance requirements such as SOX, PCI, HIPAA, GDPR, and other regional or industry‑specific mandates.
  • Ensure that certification and regulatory obligations are translated into clear, actionable business tasks, and that gaps are tracked and remediated.
Strategic Impact
  • Embedding security into business operations to support growth and innovation.
  • Reducing friction between security requirements and business delivery.
  • Improving clarity and ownership of risk across the organization.
  • Strengthening customer trust and regulatory confidence.
  • Aligning security investments with business…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary