Jobs and Careers
PN

Security Director - Business Information Security Officer (BISO)

PNC
Pittsburgh, United Statesfull_timeVerifiedPosted 15 Nov 2024

About the role

Position Overview

At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company’s success.

As a Security Director - BISO within PNC’s Technology organization, you will be based in Pittsburgh, PA as the preferred location, or Strongsville, OH. The position is primarily based in a PNC location. Responsibilities require time in the office or in the field on a regular basis. Some responsibilities may be performed remotely, at the manager’s discretion.

The Business Information Security Officer (BISO) will serve as the primary point of contact between the cybersecurity function and business lines and shared services. Here, the BISO collaboratively works with the business lines and shared services to create alignment with the information security strategy and ensure that information security risk priorities are addressed. In this strategic function, the BISO must also align the security objectives to the business objectives, helping the businesses mitigating potential information security risks that could adversely affect business operations. The BISO plays a vital role in stakeholder engagement, effectively communicating with various internal and external parties to establish and maintain a culture of security awareness.

Responsibilities:
1. Stakeholder Engagement:
• Act as the primary point of contact between the business units and the information security team.
• Advises business leaders on risk issues related to information security and recommends actions in support of the divisions wider risk management and compliance programs.
• Translate business requirements into security solutions and policies.
• Provides guidance and advocacy regarding the prioritization of business investments that impact information security.
• Develop an understanding of business goals and reframe risk discussion in business terms.
• Ensures compliance with policies, regulations and information security tools and services.
• Participate in cybersecurity and business-related committees or working groups as necessary.

2. Risk Management:
• Identify, assess, and prioritize security risks within business units.
• Develop and implement risk mitigation strategies in collaboration with the business units.
• Educate stakeholders on cybersecurity-related matters in an effort to increase awareness and improve culture.
• Inform business partners of the risk implications of critical decision by combining empirical analysis with expert judgment to assess business decisions.
• Challenge business partners’ assumptions about value drivers and present an alternate perspective.
• Reshape business partners’ preconceived notions of success where appropriate.
• Follow all risk remediation protocols to ensure issues are mitigated, risks are accounted for and exceptions are tracked in accordance with frameworks, policies and standards set by the organization.

3. Security Policy Enforcement:
• Ensure that business units adhere to information security policies, standards, and procedures.
• Collaborate with the information security team to update policies and procedures as needed.

4. Security Awareness and Training:
• Promote security awareness and best practices within business units.

5. Project Management:
• Oversee and manage security-related projects within business units.
• Ensure that security considerations are integrated into the project lifecycle from initiation to completion.

6. Metrics and Reporting:
• Develop and maintain security metrics to measure the effectiveness of the delivery of security capabilities into business initiatives.
• Provide regular reports on the security posture of business units to senior management.

Qualifications:
• Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related field. Advanced degree preferred.
• Professional certifications such as CISSP, CISM, CRISC, or similar.
• Minimum of 10-15 years of experience in information security, with at least 3 years in

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

PNC

View company profile →