Senior Business Unit Security Officer
We are seeking a talented Senior Business Unit Security Officer (BUSO) to join the Cybersecurity, Resilience & Governance (CRG) team. As a BUSO, you will enable business and IT partners to recognize and manage their cyber and information risk in a dynamic business environment. You will participate in critical projects and initiatives to ensure information risk is always considered and managed.
A successful BUSO will serve as a trusted partner and subject matter expert to the business and empower them to protect their information assets and intellectual property. You will help securely implement new technologies and tools, foster consistency through common methodologies and stay fully aligned with cybersecurity issues and efforts.
Office location:
Boston - USA (primarily) or Toronto
- Canada or Waterloo
- Canada or Halifax
- Canada
Work arrangement:
Hybrid - 3 days in office, 2 days from Home
Position Responsibilities:
Perform application risk assessments from a technical security and information risk management perspective, this includes risk identification based on information criticality through to control implementation and management of risk acceptance by business areas
Provide application and operational security consulting services to IT, partners and clients
Provide hands‑on guidance on secure architecture design, including application, cloud, and infrastructure security patterns
Act as an escalation point for complex security issues, including authentication, authorization, secrets management, and data protection
Guide teams on modern identity and access patterns (OAuth2, OIDC, SAML, service‑to‑service authentication, workload identity, etc.)
Provide technical oversight on cloud security (Azure/AWS) including IAM, network segmentation, and workload protection
Translate security requirements into practical, implementable solutions aligned with business and engineering constraints
Drive adoption of secure‑by‑design principles across new initiatives and onboarding efforts
Maintain, among all levels of business line staff, a high level of awareness about security issues and control objectives
Identify and communicate known information security control issues to business area teams providing guidance (as necessary) and oversight to ensure timely remediation of the issues
Provide support to other risk teams as necessary to address high‑priority risks
Support adherence to global information security policies and standards; work with business units and technical teams to implement solutions that comply with security policies and processes
Actively participate in your team’s plans to achieve their goals, this includes goals that originate from CRG and the business. Participate in frameworks used to measure and report on progress towards the achievement of goals
Stay current on emerging technologies, key business drivers, evolving threats and opportunities from both the business and CRG
Collaborate with other CRG professionals within the US segment and across the company
Participate in divisional and global CRG projects and initiatives as requested. Ensure business requirements and needs are considered in initiatives, projects and services.
Required Qualifications:
7/8+ Years of experience
Fewer years of experience in security is acceptable if you have systems development experience with a proven ability to implement secure applications
Professional certification for information security (or willingness to begin acquiring) - CISSP, CISA, CRISC, GIAC or similar credentials
Preferred Qualifications:
General operating knowledge of security for applications and infrastructure, security threat/risk/data classification
Solid understanding of Generative AI foundations, principles and tools
Proven ability to build relationships, engage and influence others, and work with diverse internal and international user communities as well as vendors
The ability to work both independently and as part of a team, managing multiple priorities and deadlines
The ability to work within agile development teams
Strong communicator and active listener with the ability to effectively articulate risk from both a business and technical standpoint to…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: