Padmi
Brown & Brown logo
Brown & Brown

insurance brokerage · risk management

Business Information Security Officer

Remote · United States$180k–$200k/yrPosted 6 days ago
SecuritySeniorFull Time
Apply at Brown & Brown

Opens the source posting on bbinsurance.wd1.myworkdayjobs.com

Source description

About the role

View original

Built on meritocracy, our unique company culture rewards self-starters and those who are committed to doing what is best for our customers. Brown & Brown is seeking a Business Information Security Officer (BISO) to join our growing team remotely in Georgia, Texas, Illinois, and DC! The Business Information Security Officer (BISO) serves as the primary liaison between the security function and divisional profit centers and corporate teams. Reporting directly to the Chief Security Officer (CSO), the BISO works closely with divisional IT leaders, and business executives to align business operations with both information and physical security strategies. The BISO also represents the Chief Information Security Officer (CISO) and the VP of Global Physical Security in local information security and physical security matters. Serving as the single conduit into the information security/physical security organization, this role ensures security is embedded in divisional culture, focuses on key risks, and provides guidance on security policies and controls. How You Will Contribute: Support the implementation, maintenance, and continuous improvement of information and physical security programs in alignment with corporate policies, standards, and frameworks. Contribute as a key member in shaping both the Brown & Brown security roadmap and divisional technology roadmap. Serve as a subject matter expert for information and physical security, supporting strategy development and execution. Provide guidance on prioritizing divisional investments that impact security. Allocate security resources (architecture, engineering, operations, risk management) to meet divisional needs. Support merger and acquisition activities, including pre-deal due diligence and post-deal 90-day security integration. Advise divisional leaders on security-related risk and assist in meeting broader risk management and compliance objectives. Monitor emerging security trends and assess potential impacts to divisions or profit centers. Ensure risk remediation processes are followed, issues are mitigated, and exceptions are tracked according to organizational standards Manage IT certification and accreditation processes in collaboration with auditors and certification bodies. Oversee regulatory compliance for data privacy and protection across the division. Align divisional funding requirements with strategic security initiatives. Participate in relevant security and business councils or working groups. Educate stakeholders to strengthen awareness and security culture. Understand business objectives and translate risk discussions into business-focused terms. Drive security risk assessments across the division. Engage business partners constructively on security issues. Establish clear risk ownership and accountability. Ensure compliance with security policies, regulations, and tools. Perform other duties as assigned. Skills & Experience to be Successful: CISSP, CISM, or equivalent certifications (preferred) BA/BS in business, security, or technology. 8–10+ years of experience in information security, cybersecurity, risk management, governance, physical security, or regulatory compliance, with a focus on business-aligned service delivery. Experience working with cross-functional teams. Working knowledge of ISO27001, NIST, Cyber Essentials and other security standards Deep experience of security architecture and the tooling required to instantiate. Knowledge of Property & Casualty insurance is a plus. Experience running a SOC and working cyber incidents. Experience leading teams responsible for security across mid-to-large organizations (55+ people). Strong understanding of organizational environments and their connection to external business drivers. Ability to understand business operations, evaluate risk in context, and connect business initiatives to value and risk. Pay Range $180k - $200k Annual The pay range provided above is made in good faith and based on our lowest and highest annual salary or hourly rate paid for the role and takes into account years of experience required, geography, and/or budget for the role. Teammate Benefits & Total Well-Being We go beyond standard benefits, focusing on the total well-being of our teammates, including: Health Benefits: Medical/Rx, Dental, Vision, Life Insurance, Disability Insurance Financial Benefits: ESPP; 401k; Student Loan Assistance; Tuition Reimbursement Mental Health & Wellness: Free Mental Health & Enhanced Advocacy Services Beyond Benefits: Paid Time Off, Holidays, Preferred Partner Discounts and more. Not reflective of all benefits. Enrollment waiting periods or eligibility criteria may apply to certain benefits. Benefit details and offerings may vary for subsidiary entities or in specific geographic locations. Recruiting Vendor Disclosure Statement Brown & Brown does not accept unsolicited resumes from external recruiters, recruitment vendors or employment agencies ("Recruiting Vendors"). Recruiting Vendors must have a valid written agreement and received prior written authorization from an authorized Brown & Brown representative before submitting candidates for any publicly posted role. Any unsolicited resumes submitted to Brown & Brown or its employees become the property of Brown & Brown, and no fees will be paid for such submissions. Additional information regarding this policy can be found on our careers page. The Power To Be Yourself As an Equal Opportunity Employer, we are committed to fostering an inclusive environment comprised of people from all backgrounds, with a variety of experiences and perspectives, guided by our Diversity, Inclusion & Belonging (DIB) motto, “The Power to Be Yourself”. We think of ourselves as a team, so we have teammates - not employees. We strive to attract people who are competitive, driven, and disciplined. Built on meritocracy, our unique company culture rewards self-starters and those who are committed to doing what is best for our customers. Founded in 1939 as a small, two-partner firm, Brown & Brown (NYSE: BRO) and our team of companies have grown into one of the world’s largest insurance brokerages while staying true to our foundation of trust, resilience, and delivering results. With a team that is as connected locally as it is globally, our high-performing, highly collaborative team delivers innovative risk and insurance solutions. We look for individuals who embrace our culture, thrive in a collaborative environment, are driven to grow and succeed, and are committed to always doing what is right. With a unique culture built on integrity, superior capabilities and grit, we value teamwork, trust and courage. We think of ourselves as a team, so we have teammates—not employees, and leaders—not managers. Everything we do is about the greater “WE”—never “me.” While diverse in abilities and experience, we are all connected through our core values, a commitment to our local communities and a shared mission—always doing what is best for our customers. Brown & Brown and its affiliates maintain an internal recruiting team responsible for filling open roles posted to the public. In certain situations, Brown & Brown may supplement its internal capabilities by engaging external recruiting vendors and employment agencies (“Recruiting Vendors”). Recruiting Vendors are not authorized to submit resumes, share candidate data, or directly or indirectly contact Brown & Brown employees to present candidates for employment opportunities. The only exception applies to Recruiting Vendors with an active Valid Agreement (as defined below) that has been approved by Brown & Brown. In accordance with this policy, and to ensure appropriate authorization for sharing candidate personal information, Brown & Brown will not accept unsolicited resumes from any source other than Authorized Recruiting Vendors with a Valid Agreement in place who have been expressly invited to support a specific role. Any unsolicited resumes, incomplete submissions, or candidate data received through any means (including email or otherwise) will be considered the property of Brown & Brown. Brown & Brown will not pay any placement or related fees for unsolicited submissions or candidate data provided in violation of this policy. Such submissions may be used by Brown & Brown without any obligation to pay fees of any kind to Recruiting Vendors. A Valid Agreement is defined as a written contract signed by an authorized representative of Brown & Brown. In the absence of a Valid Agreement, Brown & Brown assumes no liability under any legal theory, including but not limited to breach of contract, breach of implied contract, tortious interference, quantum meruit, any/or any other contractual or equitable claims in connection with candidates identified through unsolicited submissions made in violation of this policy. If you are an existing Brown & Brown teammate, please click here to apply to a job on our internal career site.

More at Brown & Brown

Related open roles

View all roles