Business Information Security Officer- Digital and Industrial Solutions
Listed on 2026-08-10
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, Cloud Computing: Infrastructure & Operations
Job Description
What if you could redefine what's possible? With us, you can. You want Purpose. Growth. Opportunity. People who get it.
We are the home of ambitious, passionate, and innovative world shapers. With an unmatched breadth and depth of engineering, advisory and science-based expertise, our global minds unite to power local solutions. We are pathfinders and impact makers. We are Visioneers. We are WSP.
The OpportunityWSP's Information Security Office is responsible for deploying and governing the information security framework across both the IT organization and the wider business community. This includes the governance mechanisms, policies, processes, technologies, and training required to protect WSP information and that of our clients.
As the Business Information Security Officer, Digital & Industrial Solutions; you will play a critical role in securing the digital and industrial solutions that WSP designs, develops, and brings to market. Working at the intersection of technology, security, innovation, and commercial strategy, you will help embed security, privacy, and trust into products, platforms, and services from concept through launch and ongoing operation.
Partnering closely with Digital Solutions, engineering, architecture, product leadership, and customer-facing teams, you will enable innovation while ensuring solutions meet customer, industry, and regulatory security expectations.
Your Impact- Serve as the primary security leader for WSP's externally facing digital and industrial products, platforms, and services.
- Embed security-by-design and privacy-by-design principles throughout the entire product and solution lifecycle, from concept and development through deployment and operation.
- Govern secure software development and Dev Sec Ops practices, including threat modeling, secure coding standards, code scanning, CI/CD security controls, vulnerability management, and penetration testing.
- Provide security architecture guidance for cloud-native, AI/ML, data-driven, and connected IoT/OT solutions.
- Identify, assess, track, and communicate security risks while driving remediation efforts with delivery and engineering teams.
- Support client engagements, proposals, due diligence activities, and security questionnaires to help position security as a business differentiator.
- Establish and maintain security certifications, attestations, and compliance requirements such as ISO/IEC 27001 and SOC 2.
- Oversee software supply-chain security, third-party risk assessments, and secure adoption of external technologies and services.
- Monitor emerging technologies including AI, generative AI, connected infrastructure, digital twins, and operational technology, providing practical security guidance to support innovation.
- Partner with the CISO and Information Security Office to ensure alignment with the Global Information Security Framework and contribute to ongoing security governance and reporting.
- Champion a strong security culture by building awareness and capabilities across product, engineering, and solution teams.
- 8+ years of senior-level experience in information security, including product, application, cloud, or solution security.
- Demonstrated experience securing customer-facing products, SaaS platforms, cloud services, or commercial digital solutions.
- Strong knowledge of secure software development and Dev Sec Ops practices, including threat modeling, SAST, DAST, SCA, CI/CD security, and vulnerability management.
- Experience with cloud security across Azure, AWS, and/or Google Cloud platforms.
- Working knowledge of application security, API security, encryption, authentication, authorization, PKI, and secure integration patterns.
- Professional security certification such as CISSP, CISM, CCSP, CSSLP, or an equivalent credential.
- Experience applying governance and security frameworks such as ISO/IEC 2700x, NIST, SOC 2, COBIT, and ITIL.
- Strong understanding of risk management principles and their application within engineering and delivery environments.
- Knowledge of privacy and cybersecurity regulations applicable to global organizations and commercial technology solutions.
- Ability…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: