BPM – where caring and community is in our company DNA; we are always striving to be our best selves; and we’re compelled to ask the questions that lead to innovation.
Working with BPM means using your experiences, broadening your skills, and reaching your full potential in work and life—while also making a positive difference for your clients, colleagues, and communities. Our shared entrepreneurial spirit drives us to see and do things differently. Our passion for people makes BPM a place where everyone feels welcome, valued, and part of something bigger. Because People Matter.
What you get:
Total rewards package: from flexible work arrangements to personalized benefit structures and financial compensation options that give you choice and flexibility
Well-being resources: interactive wellness platform and incentives, an employee assistance program and mental health resources, and Colleague Resource Groups (CRGs)
Balance & flexibility: 14 Firm Holidays including 2 floating, Flex PTO, paid family leave, winter break, summer hours, and remote work options, so you can balance challenging yourself with taking care of yourself
Professional development opportunities: A learning culture with CPA exam resources and bonuses, a coach program, and live classes, workshops, and seminars through BPM University
Who is successful at BPM:
Caring people who put others first
Self-starters who embody the BPM entrepreneurial spirit
Authentic individuals with a diverse point of view
Lifelong learners with a drive to excel
Resilient people who rise to the occasion
The Chief Information Security Officer (CISO) provides vision, leadership, and strategic direction for BPM's enterprise information security, cyber risk, privacy, and trust programs. The CISO partners closely with the CIO and technology organization while maintaining independent responsibility for information security risk, governance, compliance, and assurance across the firm. The role partners with firm leadership, business units, legal, risk management, and technology teams to ensure security is integrated into business strategy, client service delivery, and emerging technologies, including artificial intelligence (AI).
Strategy & Planning:
Participate as a member of the senior management team in governance processes of the organization’s security strategies.
Lead strategic security planning to achieve business goals by prioritizing defense initiatives and coordinating the evaluation, deployment, and management of current and future security technologies using a risk-based assessment methodology.
Develop and communicate security strategies and plans to executive team, staff, partners, customers, and stakeholders.
Assist with the design and implementation of disaster recovery and business continuity plans, procedures, audits, and enhancements.
Develop, implement, maintain, and oversee enforcement of policies, procedures, and associated plans for system security administration and user system access based on industry-standard best practices.
Acquisition & Deployment:
Establish security architecture, governance, and risk management standards for the evaluation, acquisition, implementation, and operation of technology solutions across the firm.
Ensure security, privacy, compliance, and resiliency requirements are incorporated into the selection and deployment of enterprise applications, cloud services, infrastructure, and emerging technologies.
Provide security oversight and risk assessment for major technology initiatives, vendor relationships, and strategic business investments.
Define security requirements and approval processes for new technologies to ensure alignment with BPM's risk appetite, client commitments, and regulatory obligations.
Operational Management:
Partner with technology leadership to ensure security, privacy, and risk management requirements are integrated into enterprise architecture, applications, infrastructure, and business processes.
Establish and oversee enterprise physical security, access control, and facility protection standards to safeguard BPM personnel, facilities, and information assets.
Develop and manage the information security operating and capital budgets.
Assess and advise on information security, privacy, and technology risks associated with strategic initiatives, technology investments, and third-party relationships.
Lead the development and performance of the information security team.
Develop and maintain strategic relationships with clients, regulators, vendors, and industry partners.
Advise executive leadership on cybersecurity, privacy, AI, and emerging technology risks and opportunities.
Requirements/Qualifications:
Bachelor's degree in Computer Science, Information Security, Business Administration, or related field.
CISSP, CISM, CRISC, CCSP, or similar certifications preferred.
10+ years leading information security and cyber risk programs.
Experience in professional services, public accounting, financial services, legal, healthcare, or other highly regulated industries preferred.
Deep knowledge of cybersecurity, risk management, cloud security, privacy, identity, and regulatory compliance.
Experience presenting to executive leadership and boards.
Experience leading incident response and crisis management.
Experience with ISO 27001, SOC 2, privacy regulations, and client security assessments.
Experience securing cloud, SaaS, ERP, and other business-critical platforms.
Experience with AI governance and emerging technology risk management.
Incident Response and Resilience
Serve as executive leader for cybersecurity incident response and crisis management activities.
Ensure BPM maintains and regularly tests incident response, cyber recovery, disaster recovery, and business continuity plans.
Lead executive communications and stakeholder engagement during significant security events.
Conduct post-incident reviews and drive continuous improvement of security capabilities.
Executive and Board Engagement
Serve as BPM's principal advisor on cybersecurity, information risk, privacy, and emerging technology risks.
Provide regular security and risk reporting to executive leadership, firm committees, and the Board of Directors.
Translate technical risks into business impact, decision-making guidance, and measurable security outcomes.
Client Trust and Regulatory Assurance
Serve as executive sponsor for BPM's client trust and security assurance programs.
Oversee security responses, attestations, and trust-center content for prospective and existing clients.
Partner with legal, risk, and business development teams to support client requirements and revenue opportunities impacted by cybersecurity.
AI and Emerging Technology Governance
Establish governance frameworks for artificial intelligence, automation, and emerging technologies.
Ensure security, privacy, and compliance requirements are integrated into AI-enabled business processes.
Assess emerging technology risks and enable responsible innovation across the firm.
Third-Party and Vendor Risk Management
Oversee BPM's third-party risk management program.
Establish security requirements and risk review processes for vendors, cloud providers, and outsourced services.
Partner with procurement and legal teams to evaluate contractual security obligations and technology risks.
Personal Attributes:
Ability to set and manage priorities judiciously.
Excellent written and oral communication skills.
Excellent interpersonal skills.
Strong negotiating skills.
Ability to present ideas in business-friendly and user-friendly language.
Exceptionally self-motivated and directed.
Keen attention to detail.
Superior analytical, evaluative, and problem-solving abilities.
Exceptional service orientation.
Ability to motivate in a team-oriented, collaborative environment.
Physical Demands and Work Environment:
General office assignments-(typing), which lends itself to repetitive motion.
Sitting in a stationary position for several hours within the day.
On-call availability and periodic overtime.
Dexterity of hands and fingers to operate a computer keyboard, mouse, and other computing equipment.
We hope you find this opportunity to be in line with your background and interests, and look forward to receiving your application!
Wondering if you should apply?
At BPM we are people who value people. We are progressive and purposeful. We are a firm with flexibility. Our shared entrepreneurial spirit drives us to see and do things differently. And our passion for people makes BPM a place where everyone feels welcome, valued, and part of something bigger.
***************
BPM provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. BPM welcomes and encourages applications from people with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process.
For positions based in San Francisco, consideration of qualified candidates with arrest and conviction records will be in a manner consistent with the San Francisco Fair Chance Ordinance.
Please note - this posting is for prospective candidates only. Unsolicited third-party resume submissions will be considered property of BPM and will not be acknowledged or returned.
Skills Required
- Bachelor’s degree in Computer Science, Information Security, Business Administration, or a related field
- 10+ years leading information security and cyber risk programs
- Deep knowledge of cybersecurity, risk management, cloud security, privacy, identity, and regulatory compliance
- Experience presenting to executive leadership and boards
- Experience leading incident response and crisis management
- Experience with ISO 27001, SOC 2, privacy regulations, and client security assessments
- Experience securing cloud, SaaS, ERP, and other business-critical platforms
- Experience with AI governance and emerging technology risk management
- CISSP, CISM, CRISC, CCSP, or similar certification
- Experience in professional services, public accounting, financial services, legal, healthcare, or another highly regulated industry
BPM LLP Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about BPM LLP and has not been reviewed or approved by BPM LLP.
-
Leave & Time Off Breadth — Policies include generous PTO, multiple firm holidays, and seasonal breaks, with unlimited PTO available for certain roles. Feedback suggests these options enhance overall value even in a demanding industry.
-
Healthcare Strength — Multiple medical, dental, and vision plan choices are offered with a strong employer-paid share, alongside HSA options and mental-health resources. Feedback suggests the breadth and depth of coverage are a core strength of the package.
-
Flexible Benefits — Flexible and remote/hybrid work options are emphasized, along with alternative schedules. Feedback suggests this flexibility is a meaningful component of total rewards.
BPM LLP Insights
What We Do
BPM LLP is one of the 50 largest public accounting and advisory firms in the country. With more than 800 professionals along the West Coast – as well as offices abroad – we help clients succeed around the world. We offer a cross-functional team approach that gives clients direct access to the best and most qualified resources. With full-service capabilities in audit, tax and advisory services, we possess in-depth knowledge of the transactional industry—its key processes, challenges surrounding growth and performance, regulatory compliance and governance—and the many other complex accounting and reporting issues you face. Our collective knowledge representing a diverse client base allows us to serve as experts in over a dozen industries. In 2021, we are proud to be named by Forbes “Best Tax and Accounting Firms” and #22 on Vault’s “Accounting 50” ranking! We invite you to learn more about us, visit bpmcpa.com









