Business Information Security Officer - AMERICAS

IngenicoAlpharetta, GA
Remote

About The Position

The Business Information Security Officer (BISO) will serve as the primary point of contact between the cybersecurity function and their assigned business unit(s)/region. The BISO is responsible for maintaining a strategic relationship with the specific business unit or function that they are aligned to. This role is in place to ensure that cybersecurity is incorporated into the culture of the organization/business unit in question.

Requirements

  • Bachelor’s degree in business, Technology, Cybersecurity, or a related field.
  • 8+ years of experience in cybersecurity risk management, governance, and regulatory compliance, with a focus on business outcomes and service delivery.
  • Experience leading and collaborating with global, cross-functional teams.
  • Strong knowledge of risk assessments, incident response, and security audits.
  • Experience working within regulated environments, including PCI DSS, ISO 27001, and/or NIST Cybersecurity Framework.
  • Understanding of cloud security governance, DevOps, and enterprise IT control environments.
  • Familiarity with identity and access management (IAM), privileged access management (PAM), vulnerability management, and SOC operating models.
  • Proven ability to partner with business leaders and support enterprise-wide initiatives.
  • Excellent stakeholder management and communication skills.
  • Experience managing and/or partnering with Managed Service Providers (MSPs).
  • Comfortable travelling – Regional based role, requiring occasional visits to regional offices.
  • Fluency in written and oral English required.

Nice To Haves

  • Certifications: CISSP, CISM or CRISC.
  • MBAs are an added benefit but not required.

Responsibilities

  • Serve as the cybersecurity SME for regional business stakeholders, translating security policies, standards, and frameworks into business-relevant guidance.
  • Build trusted relationships, influence decision-making through risk-based consultation, and align cybersecurity priorities with business objectives.
  • Promote cybersecurity awareness and foster a strong security culture in partnership with global awareness and training teams.
  • Conduct security risk assessments for new initiatives, projects, and material technology changes.
  • Advise stakeholders on risks, controls, mitigations, and trade-offs before key decisions.
  • Establish clear risk ownership and accountability, ensuring risks, remediation plans, and exceptions are properly documented, governed, and tracked within enterprise GRC processes.
  • Monitor and escalate emerging regional and business-specific cyber risk.
  • Act as the regional liaison between business teams and Security Centers of Excellence (Cyber Defense, Security Architecture, Security Risk Management, etc.).
  • Ensure enterprise security standards, operating models, and controls are applied consistently and pragmatically across the region.
  • Validate that regional changes do not introduce compliance, regulatory, or security boundary risks and escalate control deviations as required.
  • Align security funding requirements and risk treatment plans with business and IT priorities.
  • Participate in governance forums, councils, and working groups to represent regional security interests.
  • Ensure security considerations are embedded in regional initiatives, transformations, and technology programs.
  • Serve as the regional security escalation point during major incidents, coordinating with incident response teams and stakeholders.
  • Support internal, external, customer, and regulatory audits, including evidence collection and remediation tracking.
  • Contribute to accurate communication of the organization's security posture during customer and regulatory engagements.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service