Business Information Security Officer- Digital and Industrial Solutions

WSP
United States
Workplace: OnsiteFull timeUSD 153,400 - 257,800 annuallyFunction: CybersecurityEducation: bachelorsSkills: ["Leadership","Stakeholder management","Problem-solving","Risk management","Written and verbal communication"]

Own security for WSP’s externally facing digital and industrial products, from ideation and business cases through development, launch, and ongoing operations. Embed security-by-design and privacy-by-design with Digital Solutions, product, engineering, and architecture teams. Govern a Secure SDLC/DevSecOps model (threat modeling, SAST/DAST/SCA, CI/CD security, vulnerabilities, and pre-release testing) and provide security architecture and risk reporting to business and CISO leadership, enabling bids and customer due diligence.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
WSP
WSP
1 day ago

Business Information Security Officer- Digital and Industrial Solutions

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Own security for WSP’s externally facing digital and industrial products, from ideation and business cases through development, launch, and ongoing operations. Embed security-by-design and privacy-by-design with Digital Solutions, product, engineering, and architecture teams. Govern a Secure SDLC/DevSecOps model (threat modeling, SAST/DAST/SCA, CI/CD security, vulnerabilities, and pre-release testing) and provide security architecture and risk reporting to business and CISO leadership, enabling bids and customer due diligence.
Location: United States
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Serve as single point of security accountability for WSP’s externally facing digital and industrial solutions.
  • •Partner with Digital Solutions, product owners, engineering, and architecture to embed security-by-design and privacy-by-design across the solution lifecycle.
  • •Govern a Secure SDLC/DevSecOps model including threat modeling, secure-coding standards, SAST/DAST/SCA, CI/CD pipeline security, vulnerability management, and pre-release penetration testing.
  • •Provide security architecture guidance for cloud-native, data-intensive, AI/ML, and connected (IoT/OT) solutions, including controls for multi-tenant platforms and secure integrations.
  • •Act as security authority for bids and customer engagements, responding to questionnaires and due-diligence requests with risk-based reporting and posture articulation.

Pay and Benefits

Salary: USD 153,400 - 257,800 annually
Perks:Health InsuranceDentalVisionDisabilityLife InsuranceRetirement SavingsPaid LeaveParental LeaveTime Off

Key Requirements

  • •Bachelor’s degree (or equivalent) and 12+ years senior-level information security experience with product, application, or cloud security and software/solution delivery exposure.
  • •Experience securing customer-facing products, SaaS/cloud platforms, or digital services.
  • •Working knowledge of secure software development and DevSecOps practices (threat modeling, secure coding, SAST/DAST/SCA, CI/CD security, vulnerability and patch management).
  • •Working knowledge of cloud-native security across major providers (Azure, AWS, GCP), including identity, network, data protection, and workload security.
  • •Professional security certifications (e.g., CISSP, CISM, CCSP, CSSLP) and experience with governance frameworks (ISO/IEC 2700x, NIST, SOC 2, COBIT, ITIL).
Experience:SaaSCloudDevSecOpsOT/IoTAI/MLSecurity governance
Education:Bachelor's
Skills:LeadershipStakeholder managementProblem-solvingRisk managementWritten and verbal communication
Certifications:CISSPCISMCCSPCSSLPCGEITCISA
Tech Stack:DevSecOpsSecure SDLCThreat modellingSASTDASTSCACI/CDVulnerability managementPenetration testingCloud-native securityAzureAWSGCPPKIEncryptionAuthenticationAuthorizationSBOMISO/IEC 2700xISO/IEC 27001

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

WSP
Global professional services firm providing engineering, consulting, and technical services across infrastructure, environment, buildings, transportation, and energy sectors for public- and private-sector clients worldwide.
Industry: Professional Services
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Montreal, Canada
Founded: 1959
WebsiteLinkedIn