Skip to main content

Business Information Security Officer

Primary Location Corona, California Worker Location Remote Job Number 1260129 Date posted 03/05/2024
Submit Interest

Navigating the Hiring Process

We're here to support you!

Having trouble with your account or have questions on the hiring process?

Please visit the FAQ page on our website for assistance.

Need help with your computer and browser settings?

Please visit the Technical Information page for assistance or reach out to the web manager at kp-hires@kp.org.

Do you need a reasonable accommodation due to a disability?

A reasonable accommodation is any modification or adjustment that enables you to fully participate in completing the following:

  • Online Submissions
  • Pre-Hire Assessments
  • Interview Process

Please submit your accommodation request and an HR Representative will contact you.

Description:
Technical Summary

This remote BISO role will support our department with their security architecturecloud computing and technology risk assessment skillset. Strong candidates should have experience guiding teams with the correct principles required for cloud environment. Additional valuable experience may include Cyber Security Consulting experience in multiple areas of IT Security disciplines (Application Security, Red Team, vendor risk, policy and compliance controls), executive level communications and reporting required  to drive IT Security Risk Management  (GRC) and risk reduction.



*Candidates must reside or be willing to relocate at their own expense to: CA, CO, DC, GA, HI, MD, NY, OR, VA, WA. The finalist in this role will be permitted to work remotely from approved KP states. 



Job Summary:

In addition to the responsibilities listed below, this position will serve as an IT risk portfolio advisor for a large or complex technology portfolio by ensuring an ongoing awareness of the potential risks, providing guidance related to the assignment and understanding of risk factors related to the use of technology in a given IT functional area or line of business, and driving the management of technology risk in this area. This position will also collaborate with key stakeholders to obtain consensus on roadmaps to jointly mitigate security risks; determine the frequency and depth of assessment processes for assigned technology portfolio(s); establish, enforce, and manage future assessment criteria based on information risk, business criticality and compliance requirements; and facilitate ongoing security assessment activities to validate the control environment.



Essential Responsibilities:


  • Drives the execution of multiple work streams by identifying customer and operational needs; developing and updating new procedures and policies; gaining cross-functional support for objectives and priorities; translating business strategy into actionable business requirements; obtaining and distributing resources; setting standards and measuring progress; removing obstacles that impact performance; guiding performance and developing contingency plans accordingly; solving highly complex issues; and influencing the completion of project tasks by others.

  • Practices self-leadership and promotes learning in others by soliciting and acting on performance feedback; building collaborative, cross-functional relationships; communicating information and providing advice to drive projects forward; adapting to competing demands and new responsibilities; providing feedback to others, including upward feedback to leadership; influencing, mentoring, and coaching team members; fostering open dialogue amongst team members; evaluating and responding to the strengths and weaknesses of self and unit members; and adapting to and learning from change, difficulties, and feedback.

  • Leads a team of IT consultants in the development of requirements, for process or system solutions which may span multiple business domains by leveraging partnerships with stakeholders and appropriate IT teams (for example, Solutions Delivery, Infrastructure, Enterprise Architecture).

  • Leverages multiple business requirements gathering methodologies to identify business, functional, and non-functional requirements (for example, SMART) across the enterprise.

  • Leads and oversees the development and documentation of comprehensive business cases to assess the costs, benefits, ROI, and Total Cost of Ownership (TCO) of highly unique or complex solution proposals.

  • Leads the evolution of applications, systems, and/or processes to a desired future state by translating how current processes impact business operations across the enterprise.

  • Leads teams of IT Consultants in the mapping of current state against future state processes.

  • Defines the impact of requirements on upstream and downstream solution components.

  • Provides insight and influence to executive management and business leaders on how to integrate requirements with current systems and business processes across the enterprise.

  • Reviews, evaluates, and prioritizes value gaps and opportunities for process enhancements or efficiencies.

  • Leads solution design by translating requirements into workable business solutions and leading in design sessions with IT teams.

  • Recommends and advocates for additional data and/or services needed to address key business issues related to process or solutions design.

  • Leads the evaluation of third-party vendors as directed.

  • Drives continuous process improvement by leading the development, implementation, and maintenance of standardized tools, templates, and processes across the enterprise.

  • Recommends and advocates for regional and national process improvements which align with sustainable best practices, and the strategic and tactical goals of the business.

Minimum Qualifications:


  • Minimum eight (8) years experience in IT risk management, governance, compliance, or security, including Minimum one (1) year in risk portfolio management.

  • Bachelors degree in Business Administration, Computer Science, CIS or related field and Minimum ten (10) years experience in IT consulting, business analysis, or a related field. Additional equivalent work experience may be substituted for the degree requirement.


Additional Requirements:

Preferred Qualifications:
  • Five (5) years experience working for an IT organization
  • Four (4) years experience working on projects or programs requiring the integration of cross-functional technology and/or business solutions.
  • Five (5) years in a leadership role working with project or technical teams.
  • Five (5) years experience working on cross-functional project teams
  • Four (4) years of work experience in a role requiring interaction with executive leadership (e.g., Vice President level and above)
  • CISSP certification.
  • CISM certification.
Primary Location: California,Corona,Corona Data Center Admin Scheduled Weekly Hours: 40 Shift: Day Workdays: Mon, Tue, Wed, Thu, Fri Working Hours Start: 08:00 AM Working Hours End: 05:00 PM Job Schedule: Full-time Job Type: Standard Worker Location: Remote Employee Status: Regular Employee Group/Union Affiliation: NUE-IT-01|NUE|Non Union Employee Job Level: Individual Contributor Specialty: IT Consulting Department: KPIT ADMIN - Tech Risk Mgmt Ops - 9601 Pay Range: $168800 - $218350 / year The ranges posted above reflect the location in the job posting. The salary range may vary if you reside in a different location or state than the location posted. Travel: No Remote: Work location is the remote workplace (from home) within KP authorized states. Worker location must align with Kaiser Permanente's Authorized States policy. At Kaiser Permanente, equity, inclusion and diversity are inextricably linked to our mission, and we aim to make it a part of everything we do. We know that having a diverse and inclusive workforce makes Kaiser Permanente a better place to receive health care, a more supportive partner in our communities we serve, and a more fulfilling place to work. Working at Kaiser Permanente means that you agree to and abide by our commitment to equity and our expectation that we all work together to create an inclusive work environment focused on a sense of belonging and wellbeing.

Kaiser Permanente is an equal opportunity employer committed to a diverse and inclusive workforce. Applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy), age, sexual orientation, national origin, marital status, parental status, ancestry, disability, gender identity, veteran status, genetic information, other distinguishing characteristics of diversity and inclusion, or any other protected status. Submit Interest