Business Info Security Officer
Listed on 2026-06-04
-
IT/Tech
Information Security, Cybersecurity, IT Consultant, Data Security
What You’ll Do
We’re looking for a Business Info Security Officer to join our team. In this role, you’ll be responsible for managing and leading information security objectives and processes in partnership with BISO II, with a significant focus on articulating and presenting our security strategy, controls, and risk posture to clients, advisors, and other external stakeholders.
Our BISO’s play a key role in governance of our information security program at Principal; your voice makes an impact!
Key responsibilities include:
- Advise business area management and corporate information security on industry developments in information security, technology, security issues and legislation that impacts our business, and translate those developments into clear, audience-appropriate messaging for clients and advisors.
- Develop and maintain working relationships with RIS compliance, risk management, audit, privacy, fraud areas.
- Identify risks and issues and participate in risk assessments with corporate information security, bringing an information security lens to complex business unit initiatives.
- Review policies, standards and guidance and other key documents associated with our information security program and actively participate in information security governance as part of the Information Security Steering Group.
- Provide input on information security reporting and metrics, as well as to the business function, including project status, issues or funding issues, and synthesize this information into compelling presentations and talking points for client and advisor discussions.
- Represent on incident response processes which may include incident response planning and management of security incidents and events to protect IT assets.
- Responsible for oversight of business area compliance with information security policies and procedures, including but not limited to identity and access management, education and awareness, software security, patch management, data loss protection and overall business unit assessment of IT risk.
- Partner with business unit subsidiaries, joint ventures, partnerships, and other external relationships to communicate security expectations, explain our security program, and build confidence in secure communications and transactions with clients and advisors.
- Serve as a visible security spokesperson for the business by presenting our security strategy, control environment, and risk management approach to clients, advisors, and key external customers in a clear, credible, and business-relevant manner.
- Travel is expected in this role, including periodic travel for internal meetings and external client or advisor-facing engagements.
Operating at the intersection of financial services and technology, Principal builds financial tools that help our customers live better lives. We take pride in being a purpose‑led firm, motivated by our mission to make financial security accessible to all. Our mission, integrity, and customer focus have made us a trusted leader for more than 140 years.
Who You Are- You have a Bachelor’s degree in a computer related field or equivalent experience plus at least 8 years of experience as an IT professional.
- You have a strong understanding of business principles and business language, with the ability to tailor security messaging for clients, advisors, and executive audiences.
- You are able to effectively communicate information security principles, strategy, and control effectiveness with all levels of employees, as well as present confidently to clients, advisors, and senior external stakeholders.
- You have the ability to align security strategy with business strategy and convert complex security concepts into concise, trust‑building narratives and presentation materials for non‑technical audiences.
- You understand multiple info security domains and have depth in a few of those domains (examples could include data protection, governance, cyber defense, application security, or others).
- You have strong leadership & decision‑making ability.
- CISSP or CISM preferred.
- Demonstrated executive presence, strong presentation skills, and experience…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).