Portfolio Information Security Officer

Posted 6 Days Ago
Be an Early Applicant
2 Locations
In-Office
Expert/Leader
Insurance
In a world made up of devices, screens, and power buttons, when something breaks, Asurion steps in to help.
The Role
Senior director-level security advisor owning security for assigned portfolios: advise on cyber risk, prioritize remediation, review application and cloud architecture, drive security program adoption, produce risk reporting, support incidents and regulatory/audit activities, and influence senior stakeholders to remediate material risks.
Summary Generated by Built In
Position Overview

The Portfolio Information Security Officer (PISO) is a senior, director-level leader serving as the primary security advisor for assigned lines of business. Reporting to the Deputy Chief Information Security Officer, the PISO aligns business objectives with enterprise security requirements, advises on cyber and technology risk, and ensures application, architecture, and engineering initiatives incorporate appropriate security controls. This role influences senior stakeholders across technology, product, engineering, operations, risk, compliance, and business leadership, translating complex technical issues into actionable business risk decisions and driving remediation aligned to regulatory expectations, operational resilience, and enterprise security strategy.

Key Responsibilities
  • Business Unit Security Leadership: Own the security relationship for assigned portfolios; participate in business planning and governance; ensure leaders understand current and emerging risks, control gaps, remediation obligations, and risk acceptance decisions; connect enterprise security functions with business and technology teams to align priorities to outcomes.
  • Cyber Risk Advisory and Prioritization: Advise on remediation prioritization, compensating controls, exceptions, and formal risk acceptance; assess findings based on likelihood, impact, exploitability, regulatory exposure, operational criticality, and customer impact; develop practical risk treatment plans; present time-bound risk acceptance recommendations with accountable ownership; escalate material risks to appropriate governance forums.
  • Application Architecture and Engineering Reviews: Provide technical security advisory for application architecture, cloud deployments, integrations, APIs, identity patterns, and third-party connectivity; partner with enterprise architecture, engineering, DevOps, cloud, and infrastructure teams to identify risk early; evaluate authentication, authorization, data protection, encryption, logging, segmentation, resilience, secrets management, secure configuration, and vulnerability exposure; ensure alignment to enterprise standards, secure SDLC, and regulatory requirements.
  • Risk Reporting and Governance: Produce business-unit-specific cyber risk reporting covering key risks, control gaps, remediation progress, exceptions, vulnerabilities, audit/regulatory issues, and emerging threats; deliver regular updates to business leaders and contribute to consolidated executive reporting; translate technical issues into clear business impact statements and decision materials; track commitments, risk acceptances, and issue closure.
  • Security Program Alignment: Drive adoption of enterprise capabilities and standards (e.g., vulnerability management, third-party risk, IAM, data protection, cloud security, incident response, threat management, awareness, secure development); identify gaps between policy and implementation; provide feedback to central security teams; support regulatory, audit, and compliance activities; partner with security architecture, GRC, risk, privacy, legal, compliance, and technology teams.
  • Incident, Threat, and Emerging Risk Support: Provide business context during incidents and investigations; advise leaders on exposure, remediation urgency, operational impact, and communications; lead post-incident risk reviews and ensure lessons learned inform sustainable control improvements.
Education and Experience
  • Bachelor’s degree in Information Security, Computer Science, Information Technology, Engineering, Risk Management, or related field, or equivalent practical experience.
  • 10+ years across information security, technology risk, application security, infrastructure, cloud security, security architecture, engineering, or related disciplines.
  • 5+ years influencing senior technology, engineering, risk, or business stakeholders.
  • Demonstrated experience advising on cyber risk, control gaps, risk acceptance, remediation prioritization, and executive-level risk reporting.
  • Experience reviewing application, system, or platform designs for security risk and translating technical issues into business risk language for executives.
  • Preferred: Experience as a PISO/BISO or in security architecture, technology risk, or senior security advisory roles; regulated industry experience (e.g., financial services, healthcare, insurance, technology, critical infrastructure); familiarity with frameworks such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, COBIT, FAIR; relevant certifications (e.g., CISSP, CISM, CRISC, CCSP, CISA, SABSA, AWS/Azure security credentials); experience presenting to executive and board-level forums.
Knowledge, Skills, and Abilities
  • Broad technical fluency across application security and secure SDLC, cloud security architecture, IAM, infrastructure and network security, data protection and encryption, API and integration security, vulnerability management, DevSecOps and CI/CD, logging/monitoring/detection controls, third-party risk, resilience and continuity.
  • Strong risk judgment; ability to distinguish theoretical risk from material business risk and compliance exposure, and to recommend pragmatic treatments aligned to risk appetite.
  • Executive communication skills with the ability to prepare concise, decision-oriented materials and influence without direct authority.
  • Business acumen to connect security posture to strategy, revenue, operations, and customer impact.
  • Relationship management and prioritization skills to focus teams on the most impactful risks under resource constraints.
  • Ownership mindset to drive issues to closure, maintain accountability, and ensure transparent, time-bound risk decisions.
Travel Requirements

N/A

Physical Demands
  • Stationary Position: Frequently
  • Vision: 20/20 corrected vision
  • Hearing: Receive detailed information if spoken to
Working Conditions

N/A

Skills Required

  • Bachelor's degree in Information Security, Computer Science, IT, Engineering, Risk Management, or equivalent experience
  • 10+ years in information security, technology risk, application security, cloud security, security architecture, or related disciplines
  • 5+ years influencing senior technology, engineering, risk, or business stakeholders
  • Experience advising on cyber risk, remediation prioritization, risk acceptance, and executive-level risk reporting
  • Experience reviewing application, system, or platform designs for security risk and translating technical issues to business risk
  • Broad technical fluency across application security, cloud security, IAM, data protection, encryption, APIs, vulnerability management, DevSecOps, CI/CD, and logging/monitoring
  • Preferred: prior PISO/BISO, security architecture, technology risk, or senior security advisory experience
  • Preferred: regulated industry experience (financial services, healthcare, insurance, critical infrastructure) and familiarity with NIST CSF, NIST 800-53, ISO 27001, CIS Controls, COBIT, FAIR
  • Preferred: relevant certifications (CISSP, CISM, CRISC, CCSP, CISA) and cloud security credentials (AWS/Azure)

Asurion Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Asurion and has not been reviewed or approved by Asurion.

  • Fair & Transparent Compensation Pay is often described as solid or competitive in certain corporate and technical tracks, with some roles viewed as aligned to market ranges.
  • Strong & Reliable Incentives Short-term incentives and bonus structures are described as a meaningful layer on top of base pay, increasing total compensation when targets are met.
  • Healthcare Strength Medical, dental, and vision offerings are described as inclusive and broad, with additional protections like life/AD&D and disability coverage available.

Asurion Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Nashville, Tennessee
18,000 Employees
Year Founded: 1994

What We Do

We're a global tech care company keeping nearly every device and appliance in your home running smoothly. Trusted by more than 100 leading brands and serving over 230M customers worldwide, we deliver tech support, repair, protection, and replacements at a massive scale. From your neighborhood uBreakiFix by Asurion repair store, to in-home tech support, to global protection plans, we’re the people keeping your tech connected when it matters most.

Why Work With Us

As Asurion, you will work with people who care about you and the work we do together. You can depend on us to care about the work you do.

Gallery

Gallery

Similar Jobs

Boeing Logo Boeing

Senior Manager - Sustainable Operations

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Hybrid
Arlington, VA, USA
170000 Employees
162K-235K Annually

Byrd's House Detective DBA BHD Home and Mold Inspections Logo Byrd's House Detective DBA BHD Home and Mold Inspections

Virtual Assistant

Agency • Logistics • Real Estate • Virtual Reality • Consulting • Hospitality • Data Privacy
Remote or Hybrid
United States
100 Employees
35-45 Annually

Boeing Logo Boeing

Senior Industrial Security Specialist

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Herndon, VA, USA
170000 Employees
119K-161K Annually

Capital One Logo Capital One

Lead Software Engineer

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
2 Locations
55000 Employees
197K-246K Annually

Similar Companies Hiring

Globe Life Thumbnail
Insurance • Financial Services
McKinney, TX
3000 Employees
MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account