Chief Information Security Officer
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 1d ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 1d ago
The date the source published, not the day we noticed it (2026-10-09). Last seen at its source 2h ago.
We have tracked this listing since 9 Oct 2026 (1 days). The employer's own board has carried it every time we have read it, most recently 2 hours ago.
Is it remote?
Marked remote on the employer's board
Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.
Who may apply?
United States
The description states no restriction of its own. This is the source's own tag.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
Lever employer's own board first seen 1d ago · last seen 2h ago
The listing
BPM – where caring and community is in our company DNA; we are always striving to be our best selves; and we’re compelled to ask the questions that lead to innovation.
Working with BPM means using your experiences, broadening your skills, and reaching your full potential in work and life—while also making a positive difference for your clients, colleagues, and communities. Our shared entrepreneurial spirit drives us to see and do things differently. Our passion for people makes BPM a place where everyone feels welcome, valued, and part of something bigger. Because People Matter.
What you get:
-
Total rewards package: from flexible work arrangements to personalized benefit structures and financial compensation options that give you choice and flexibility
-
Well-being resources: interactive wellness platform and incentives, an employee assistance program and mental health resources, and Colleague Resource Groups (CRGs)
-
Balance & flexibility: 14 Firm Holidays including 2 floating, Flex PTO, paid family leave, winter break, summer hours, and remote work options, so you can balance challenging yourself with taking care of yourself
-
Professional development opportunities: A learning culture with CPA exam resources and bonuses, a coach program, and live classes, workshops, and seminars through BPM University
Who is successful at BPM:
-
Caring people who put others first
-
Self-starters who embody the BPM entrepreneurial spirit
-
Authentic individuals with a diverse point of view
-
Lifelong learners with a drive to excel
-
Resilient people who rise to the occasion
The Chief Information Security Officer (CISO) provides vision, leadership, and strategic direction for BPM's enterprise information security, cyber risk, privacy, and trust programs. The CISO partners closely with the CIO and technology organization while maintaining independent responsibility for information security risk, governance, compliance, and assurance across the firm. The role partners with firm leadership, business units, legal, risk management, and technology teams to ensure security is integrated into business strategy, client service delivery, and emerging technologies, including artificial intelligence (AI).
Strategy & Planning:
-
Participate as a member of the senior management team in governance processes of the organization’s security strategies.
-
Lead strategic security planning to achieve business goals by prioritizing defense initiatives and coordinating the evaluation, deployment, and management of current and future security technologies using a risk-based assessment methodology.
-
Develop and communicate security strategies and plans to executive team, staff, partners, customers, and stakeholders.
-
Assist with the design and implementation of disaster recovery and business continuity plans, procedures, audits, and enhancements.
-
Develop, implement, maintain, and oversee enforcement of policies, procedures, and associated plans for system security administration and user system access based on industry-standard best practices.
Acquisition & Deployment:
-
Establish security architecture, governance, and risk management standards for the evaluation, acquisition, implementation, and operation of technology solutions across the firm.
-
Ensure security, privacy, compliance, and resiliency requirements are incorporated into the selection and deployment of enterprise applications, cloud services, infrastructure, and emerging technologies.
-
Provide security oversight and risk assessment for major technology initiatives, vendor relationships, and strategic business investments.
-
Define security requirements and approval processes for new technologies to ensure alignment with BPM's risk appetite, client commitments, and regulatory obligations.
Operational Management:
-
Partner with technology leadership to ensure security, privacy, and risk management requirements are integrated into enterprise architecture, applications, infrastructure, and business processes.
-
Establish and oversee enterprise physical security, access control, and facility protection standards to safeguard BPM personnel, facilities, and information assets.
-
Develop and manage the information security operating and capital budgets.
-
Assess and advise on information security, privacy, and technology risks associated with strategic initiatives, technology investments, and third-party relationships.
-
Lead the development and performance of the information security team.
-
Develop and maintain strategic relationships with clients, regulators, vendors, and industry partners.
-
Advise executive leadership on cybersecurity, privacy, AI, and emerging technology risks and opportunities.
Requirements/Qualifications:
-
Bachelor's degree in Computer Science, Information Security, Business Administration, or related field.
-
CISSP, CISM, CRISC, CCSP, or similar certifications preferred.
-
10+ years leading information security and cyber risk programs.
-
Experience in professional services, public accounting, financial services, legal, healthcare, or other highly regulated industries preferred.
-
Deep knowledge of cybersecurity, risk management, cloud security, privacy, identity, and regulatory compliance.
-
Experience presenting to executive leadership and boards.