Job Description: 1
BISO Engineer
Houston, TX
Contract: 12 Months
Position Overview
The BISO (Business Information Security Officer) Engineer serves as an embedded cybersecurity practitioner within a assigned business unit, bridging the gap between enterprise security strategy and day-to-day operational technology environments. This role partners closely with IT, OT, and business stakeholders to identify risk, drive remediation, and translate security requirements into actionable programs.
Key Responsibilities
· Serve as the primary cybersecurity liaison for assigned business unit(s), translating enterprise security policies into unit-specific controls and procedures
· Conduct and support risk assessments, vulnerability management reviews, and security posture evaluations across applications, infrastructure, and OT environments
· Lead or support security initiatives including WAF/firewall configurations, identity & access management reviews, endpoint protection, and cloud security posture
· Represent the business unit in change management and security governance forums
· Coordinate with enterprise SIEM (Splunk), network security (Palo Alto/Panorama), and application security platforms (e.g., Imperva Cloud WAF) to ensure appropriate monitoring and enforcement
· Support M&A integration activities including network segmentation, firewall onboarding, and security baseline validation
· Develop and maintain security documentation: policies, runbooks, risk acceptance memos, and remediation plans
· Engage stakeholders across technical and leadership levels; present risk posture and program status to senior management
Qualifications Required:
· 5+ years in cybersecurity engineering, architecture, or risk management
· Hands-on experience with WAF, NGFW (Palo Alto preferred), SIEM, or vulnerability management platforms
· Strong understanding of NIST CSF, CMMC, or equivalent frameworks
· Proven ability to manage cross-functional security programs with minimal oversight
· Preferred:
· Experience in energy, utilities, or OT/ICS environments
· Familiarity with Imperva Cloud WAF, Illumio, Splunk, or Panorama
· CISSP, CISM, or equivalent certification
· Experience supporting M&A cybersecurity integration
Job Description: 2
BISO Analyst
Houston, TX
Contract: 12 Months
This role is designed for someone who enjoys working at the intersection of people, technology, and operations — helping teams understand risk, make informed decisions, and move work forward securely, efficiently and confidently.
In this role, you will partner closely with the business, infrastructure, and OT teams to understand how systems are used in the real world and how cybersecurity can best support reliability, security, and business outcomes. You will help translate vulnerabilities, security findings, and technical risks into clear, actionable insights that leaders and operators can use — not just reports that sit on a shelf. Your work will focus on enablement and clarity, not gatekeeping.
What you will do:
· Act as a trusted partner to the various business
· Translate cybersecurity risks (e.g., vulnerabilities, OT exposures) into business‑relevant impact and options
· Support decision‑making by framing risk, tradeoffs, and remediation paths, not just control gaps
· Assist with security reviews for OT environments, and hybrid IT/OT architectures
· Partner with engineering and operations teams to understand how systems are actually used, not just how they’re designed
· Support secure integration of new assets, vendors, or acquisitions into existing environments
· Helping prioritize remediation based on operational impact and risk
· Tracking remediation commitments and timelines
· Identifying recurring patterns or systemic issues
· Contribute to risk assessments, exception reviews, and documentation in collaboration with Cyber teams
· Gather, document, and clarify security requirements in a way that is usable by non‑security teams
· Create clear summaries, risk narratives, and visuals for leadership and stakeholders
· Help standardize repeatable processes and templates to reduce friction and rework
What we are looking for:
Experience in one or more of the following:
· OT, ICS, or industrial environments
· Gas, energy, utilities, or critical infrastructure operations
· IT infrastructure, networking, or systems administration
· Cybersecurity, risk management, or vulnerability management
· Strong ability to analyze complex problems and communicate clearly
· Comfort working across technical and non‑technical audiences
· Curiosity, learning mindset, and willingness to ask “why”
· Self-starter with little to no guidance to work with various teams
· Ability to create reports, metrics and analyses that convey the message succinctly and accurately