This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
At Boeing, we innovate and collaborate to make the world a better place. We’re committed to fostering an environment for every teammate that’s welcoming, respectful and inclusive, with great opportunity for professional growth. Find your future with us. Boeing Enterprise Security (BES) is on the lookout for a highly motivated East Asia region Business Information Security Officer (BISO) to join the Global Cybersecurity team. The Global Cybersecurity program is dedicated to the assurance of cybersecurity regulatory framework compliance, in-region security GRC advice and oversight, and strategic cybersecurity solutions to enable global business operations. The BISO will serve as the primary point of contact between the BES organizational functions and Boeing entities, business programs, and other stakeholders across the East Asia region. The BISO is the region's trusted cybersecurity partner and is responsible for maintaining strategic relationships with various organizational leaders/stakeholders from IT, Legal, and Security departments.
Job Responsibility:
Facilitate the authority to operate (ATO) in a region
Manage regulatory compliance and assurance activities (e.g., audits, assessments, attestations)
Registration with East Asia regulatory authorities as an appointment Cybersecurity Focal/officer, as needed
Serve as a conduit between Enterprise Security Leaders/SMEs, Cyber Legal Counsel, regional partners, and stakeholders
Champion Governance, Risk and Compliance (GRC) responsibilities in East Asia region
Assess cybersecurity risk and overall health that may impact business operations in the region
Ensure regional compliance and alignment with Boeing Enterprise Security policy
Identify/safeguard regional IT assets, ensure effective governance, minimum defensive controls and IT Preparedness Plans
Provide cybersecurity advisory, project support, and promote cybersecurity awareness
Serve as the regional point person for cybersecurity requests and inquiries from internal / external customers
Provide expert cybersecurity advisory to enable regional business initiatives and imperatives
Promote awareness of BES directives, cybersecurity policies and security best practices
Partner with regional stakeholders to deliver comprehensive security planning and solutions
Requirements:
An expert translator with the ability to convert complex, technical security concepts into clear, concise business language for non-technical stakeholders, executives and regional Boards
Strong 'influencer leadership' skills to gain buy-in from business leaders and partners without having direct authority over them
An ability to act as a 'business enabler' that can align Enterprise security initiatives to regional business objectives and imperatives
A technical fluency and strong understanding of the entire security domain (network/cloud, data protection, application, identity/access management, vulnerability, incident response)
In-depth knowledge of the security regulatory landscape across East Asia (China MLPS 2.0, various AI Laws/Acts, PDP Acts) and familiarity with other global regulatory standards (ISO/IEC 27000, NIST SP 800-171, CSF)
Proven ability to lead/conduct IT security risk assessments, support internal security audits, and prepare for regulatory assessments
Ability to operate within a large, complex, global, multicultural environment
Proactive, innovative, observant, detail-oriented and tolerant of ambiguity with the flexibility to thrive in a dynamic environment
Operates with a sense of urgency while maintaining a high standard of quality delivery
Professional, collaborative, respectful, with a strong sense of accountability, ethics, and business integrity
Nice to have:
10+ years IT/Security related work experience, ideally with 5+ years in a management/leadership role
CISSP, CISM, CISA, Security+ or other cybersecurity certifications
5+ years presenting complex security risks, strategies, and concepts in business terms to executive leadership
5+ years leading or conducting IT/cybersecurity risk assessment
5+ years of experience with East Asia security regulatory assessments and pertinent compliance activities
5+ years proven experience working in a Security GRC related role
Strong executive presence and business acumen, excellent written and oral communication skills, and the ability to translate technically complex issues into simple, easy to understand concepts
Experience working in an IT/Security role across multiple East Asia / APAC countries
Multi-lingual with strong verbal, comprehension and written English competence
Advanced degree (e.g. Bachelor, Master, etc.) preferred but not required
What we offer:
Competitive base pay and incentive programs
Industry-leading tuition assistance program pays your institution directly
Resources and opportunities to grow your career
Up to $10,000 match when you support your favorite nonprofit organizations