Jobs and Careers
WS

Business Information Security Officer- Digital and Industrial Solutions

WSP
United States, United Statesfull_timeVerifiedPosted 10 Aug 2026

About the role

Position Summary


WSP’s Information Security Office (ISO) is responsible for the deployment of the information security framework across both the IT organisation and the wider business community. This includes the governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our clients.


The Business Information Security Officer (BISO) – Digital & Industrial Solutions is a business-facing role dedicated to securing the digital and industrial solutions that WSP’s business lines design, build and bring to market for external customers and for general consumption. This role focuses on the security of the products, platforms and services WSP sells, ensuring that security, privacy and trust are engineered into every solution from concept through go-to-market and ongoing operation.


This is a role at the intersection of technology, security, innovation and commercial strategy. The BISO works hand-in-hand with the Digital Solutions team, product managers, engineering and architecture, and go-to-market functions to embed security-by-design, meet customer and regulatory security expectations, and position security as a competitive differentiator that accelerates sales rather than slowing them.


This position requires a senior professional who combines strong information and product security expertise with genuine commercial and product acumen — comfortable in engineering and DevOps environments, fluent in cloud-native, application, data and operational-technology (OT/IoT) security, and equally capable of engaging engineers, executives and customers. 
 

Responsibilities

  • Product security ownership — serve as the single point of security accountability for WSP’s externally-facing digital and industrial solutions — the products, platforms and services built by the business lines for customers and for commercial sale.
  • Security-by-design partnership — partner directly with the Digital Solutions team, product owners, engineering and architecture leaders to embed security-by-design and privacy-by-design across the full solution lifecycle, from ideation and business case through development, launch and ongoing operation.
  • Secure development lifecycle — Govern a Secure SDLC / DevSecOps model for solution teams, including threat modelling, secure-coding standards, code and dependency scanning (SAST/DAST/SCA), CI/CD pipeline security, vulnerability management and pre-release penetration testing.
  • Solution security architecture — provide security architecture guidance for cloud-native, data-intensive, AI/ML and connected (IoT/OT) solutions, ensuring appropriate controls for multi-tenant platforms, customer-data protection, identity and access, and secure integration with third-party and client systems.
  • Product risk management — identify, assess, document and track security risks in each solution; drive remediation with delivery teams; and provide clear, risk-based reporting to business and CISO leadership.
  • Go-to-market and sales enablement — act as security authority for bids, proposals and customer engagements — responding to customer security questionnaires and due-diligence requests, articulating each solution’s security posture, and helping win and retain business by giving customers confidence in WSP’s solutions.
  • Compliance and certification — establish and evidence the security certifications, attestations and compliance the market expects of commercial solutions (e.g., ISO/IEC 27001, SOC 2, and industry-, region- and contract-specific obligations), and maintain the artefacts needed to demonstrate them to customers and auditors.
  • Supply-chain and third-party security — manage third-party, open-source and supply-chain security for solution components, including software bill of materials (SBOM), vendor security assessment, and secure use of external 
  • Innovation and emerging technology — track emerging technology (AI and generative AI, digital twins, edge/OT, connected infrastructure) and translate new threats and opportunities into practical guidance so the business can innovate safely and at speed.
  • Global framework alignment — work with the CISO and ISO on the Global Information Security Framework — adapting corporate policies and standards for the product/solutions context, feeding product-security requirements back into the framework, and providing regular reporting on solution-security posture and metrics.
  • Security culture — build security awareness and capability within solution and engineering teams, championing a culture in which product and engineering teams own security as part of quality.
     

Leadership and People Responsibilities
 

  • Displays leadership and independence in performing the role, with the ability to make complex, busin

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

WSP

View company profile →