This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Business Information Security Officer (BISO) is a subject matter professional (SMP) within the Technology Risk & Cybersecurity Compliance (TRACC) team under the Cybersecurity Services organization. The Digital Assets BISO acts as the primary cybersecurity risk liaison and advisor for business units engaged in cryptocurrency- and digital asset–related products, services, and vendor partnerships. This role ensures that all digital asset initiatives adhere to enterprise cybersecurity policies and procedures, while enabling innovation in a secure and compliant manner.
Job Responsibility:
Serve as the embedded security partner for Digital Assets business teams, aligning security requirements with product and operational objectives
Translate enterprise cybersecurity policies and procedures into practical, actionable expectations for digital asset initiatives
Participate in project planning, architecture reviews, and roadmap discussions to ensure secure design and regulatory alignment
Support risk exception, risk acceptance, and mitigation processes
Lead end-to-end cybersecurity risk assessments for digital asset products, crypto custody models, wallet operations, blockchain integrations, and supporting vendors
Evaluate risks related to private key management, wallet operations, smart contract risks, node infrastructure, and transaction processes
Document risks, recommend compensating controls, and track remediation to closure
Own the security risk lifecycle for digital asset vendors—from due diligence and contract negotiation to ongoing monitoring