CBRE Group, Inc

Divisional Business Information Security Officer

CBRE Group, Inc$110K — $130K *
Business Services
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or Business Administration.
  • 3+ years in technology or closely related field.
  • 3-5 years of experience in one or more cybersecurity domains (security operations, engineering, etc.).
  • 1-3 years in risk management domain (technology risk, enterprise risk).
  • Strong understanding of cybersecurity, risk management, and business operations.

Responsibilities

  • Execute corporate cybersecurity strategy aligned with business needs and regulations.
  • Facilitate communication between cybersecurity, business, and technology teams.
  • Provide briefings to divisional leadership on security risks and mitigation efforts.
  • Assist with risk analysis and develop tailored cybersecurity strategies.
  • Promote security awareness and train division staff on best practices.

Benefits

  • Opportunity to impact business operations positively through cybersecurity alignment.
  • Recognition as a trusted advisor within the organization.
  • Access to ongoing training and professional development resources.
  • Chance to collaborate with high-level stakeholders and technical experts.
  • Contribution to a culture valuing cybersecurity as a business enabler.
Full Job Description
About the role

CBRE is seeking a Divisional Business Information Security Officer (BISO), to join CBRE's Global

Business Information Security team, and serve as a trusted advisor between cybersecurity and business operations. The individual will serve as a catalyst for aligning security with business goals, contributing to the overall success of CBRE. At a high level, the BISO plays a valuable and pivotal role in the following key objectives:

  • Execution of corporate cybersecurity strategy within the assigned division, in alignment with the business needs and regulatory environment,
  • Reduction of cybersecurity risk,
  • Facilitation of cyber risk-based decision-making,
  • Enablement of the business, through alignment of security products and services with business objectives.
  • Addressing security-related business challenges,
  • Promoting the security culture.

What you'll do

Communication & Collaboration: BISOs serve as a liaison between cybersecurity and the business as well as between cybersecurity and technology teams that support the business. In that role, BISOs facilitate effective communication between the various teams while also communicating with other critical partners (i.e. legal, risk teams, internal audit, etc.) including the following:

  • Provide regular briefings to divisional leadership on security posture, risks, and risk reduction/mitigation efforts.
  • Bring 'voice of the business' insights to the CISO, Global BISO and the broader Global
  • Cybersecurity Office to drive business awareness with cyber teams and partner on improvements.
  • Collaborate with Global BISO, Cyber Incident Response, Security Operations Center and
  • Client Assurance teams, in response to division-specific security incidents, coordinating with broader security, technology, legal, compliance and corporate communication teams, as needed.
  • Drive cyber control adoption, as well as remediation of cybersecurity issues (including audit findings, regulatory compliance items, contractual compliance issues, regulatory compliance requirements) and cybersecurity control gaps through coordination of and communication of remediation plans.
  • Assist the CBRE Client Assurance team with division-related client requests by providing business insights and leveraging your knowledge of the business to connect the team with appropriate stakeholders.

Risk Management: A key focus of BISOs is to assist with cybersecurity risk management. BISOs, in partnership with Cybersecurity Governance, Risk & Compliance teams as well as Enterprise Risk Management, assist with identification, assessment, mitigation and overall reduction of cybersecurity risk.

  • Assist with risk analysis and assessment, identifying potential security threats, and developing mitigation strategies tailored to the business risk profile and specific business needs.
  • Translate corporate security policies, standards and cyber-related regulatory requirements into actionable plans for the assigned division, ensuring awareness within the business and assisting to drive adherence to policies, standards and compliance requirements.
  • Assist with development, implementation, and evolution of cybersecurity-related processes, including but not limited to application registration, cyber risk evaluation, cybersecurity control self-assessment processes while partnering with product and technology teams to drive successful and timely execution of these processes.
  • Serve in a consulting/advising function to effectively identify relevant cybersecurity requirements (example - MFA, WAF, etc.) for new and existing projects/initiatives, in partnership with appropriate product teams and subject-matter experts, ultimately driving the implementation of security into the division's products and services, balancing business needs with security requirements.
  • Monitor the assigned division's cybersecurity objectives and measures and assist the division's business and technology teams with prioritization of cybersecurity-related efforts needed to address control adoption and/or operational control deficiencies.

Training & Awareness: BISOs promote a security culture where cybersecurity is valued as an enabler of the business. They serve as advocates for security best practices, cybersecurity strategy and programs with an understanding that cybersecurity policies and standards are purpose-built and not simply compliance requirements.

  • Educate division staff on cybersecurity best practices, integration of cybersecurity controls, and importance of meeting targets for cybersecurity-related operational measures.
  • Ensure training is relevant, impactful and aligned with the specific needs of the assigned division.
  • Facilitate and assist with creation, delivery and evaluation of security awareness training for employees, to reduce human-centric security risks.
  • Monitor effectiveness of training programs and assist with tailoring of training as needed.
  • Provide division-level actionable insights to leadership.

What you'll need

  • Strong and broad understanding of cybersecurity, risk management and technology with ability to deep dive into specific technology domains, as needed.
  • Excellent business acumen with ability to understand business operations and priorities within the division to effectively align security strategies.
  • Excellent communication skills, with proven ability to translate and explain complex security concepts to non-technical stakeholders, influence decision-making and articulate vision across both technical and business teams.
  • Must be a self-starter who takes initiative, can work independently, is eager to learn and has a passion for cybersecurity and technology.
  • Demonstrated ability to build and maintain strong relationships with key stakeholders, including at the executive level, as well as with technical subject-matter experts.
  • Demonstrated executive presence and emotional intelligence.
  • Ability to assess and prioritize security risks based on their potential impact on the business.
  • Must be proficient with MS Office suite of productivity tools as well as collaboration tools.

Education and Experience

  • Bachelor's Degree, from an accredited four-year college or university, in Cybersecurity,
  • Computer Science, Information Technology, Business Administration.
  • Prior experience serving as a BISO or ISO is preferred.
  • 3+ years working in technology or technology-adjacent field.
  • 3-5 years working in, or closely with, one or more cyber domains (i.e. security operations, security engineering, network security, identity and access management, etc.)
  • 1-3 years working in or with a risk management domain (i.e. technology risk, cybersecurity risk, enterprise risk, etc.); prior experience within cybersecurity risk management is preferred.
  • Certifications are a plus, including ITIL, CISSP, CISM, CRISC, CISA, Cloud Security Practitioner.
  • Familiarity with key cybersecurity compliance standards (i.e. ISO27001, etc.), frameworks (i.e.
  • NIST CSF, NIST 800-171, etc.) and regulations relevant to cybersecurity (i.e. DORA, GDPR, etc.)

About CBRE Group, Inc

CBRE is a vertically integrated global commercial real estate services and investment firm. The company was established in 1992 and is headquartered in Chicago, Illinois, United States.

CBRE Group, Inc Careers

Join the world-class team at CBRE Group, Inc, the global leader in real estate services and investment. At CBRE, we are committed to fostering a culture of innovation, diversity, and professional growth. Our team is composed of industry-leading experts who are passionate about shaping the future of real estate.

Work You’ll Do

At CBRE, you will have the opportunity to engage in transformative projects that reshape the landscape of modern real estate. Our professionals lead with expertise and a deep understanding of industry needs, making CBRE the epitome of excellence in the real estate sector.

Explore Job Opportunities and Internships

Whether you're starting your career or looking to make a significant impact in the real estate industry, CBRE offers a range of job opportunities and internships that will harness your skills and expand your horizons. From positions in management to roles in research and analytics, your perfect job awaits.

Innovate and Lead

Join a team where innovation and leadership go hand in hand. CBRE empowers its employees to take the lead on projects, encouraging a culture of leadership that permeates every level of the company. With CBRE, you can transform your career trajectory through meaningful work that drives the real estate market forward.

Professional Growth and Development

CBRE is dedicated to the professional growth of its employees. With comprehensive diversity training and leadership development programs, we ensure that every team member has the resources to succeed. Our commitment to professional development is unmatched, offering continuous learning opportunities and career advancement.

Benefits and Culture

At CBRE, we understand that our employees are our greatest asset. That’s why we offer competitive benefits that support both your professional and personal life. Our inclusive culture champions diversity, encouraging a workplace where every voice is heard and valued.

Networking and Career Advancement

Enhance your career through CBRE’s vast networking opportunities. Connect with industry leaders, participate in global conferences, and engage in groundbreaking projects. Our robust networking channels foster connections that lead to dynamic career opportunities and lasting professional relationships.

Join Our Team

Ready to advance your career at CBRE Group, Inc? Explore our current job openings and find out how your skills and interests align with our needs. We are always on the lookout for passionate, creative, and solution-driven team players.

Stay Connected

Keep up to date with the latest from CBRE careers by subscribing to our job alert emails. Tailor your subscription to receive updates that match your career preferences and discover the exciting opportunities that await.

Apply Now

Start your journey with CBRE today. Submit your resume, prepare for your interview, and get ready to join a company where your career will flourish. Let’s build a better future together.

SEARCH CBRE JOBS

READ CAREERS BLOG

At CBRE Group, Inc, we don’t just offer jobs—we offer careers that make a difference. Join us and be a part of our journey to shape the world of real estate.
Learn more about CBRE Group, Inc
Size
105,000 employees
Market Cap
$23.8 billion
Industry
Net Income
$751.9 million
Founded
1906
5 Year Trend
+9.8%
Revenue
$23.8 billion
NASDAQ

Similar Jobs

More Jobs at CBRE Group, Inc

More Business Services Jobs

  • Branch Vice President
    $150K — $250K + $30K bonus + equity, medical, dental, vision, life, std/ltd, auto allowance, *
    Just Rite Equipment / DuraServ
    South Windsor, CT 06074 (Capitol County)
  • Branch Vice President
    $200K — $500K++ $30K bonus + equity, medical, dental, vision, life, std/ltd, auto allowance, *
    Casco Dock & Door / DuraServ
    West Sacramento, CA 95691 (Yolo County)
  • Branch Vice President
    $150K — $250K + $30K bonus + equity, medical, dental, vision, life, std/ltd, etc. *
    Southern Dock Products / DuraServ
    Oklahoma City, OK 73111 (Oklahoma County)
  • Director of Business Development
    $130K — $150K *
    Warren Whitney
    Richmond, VA 23226 (Henrico County)
  • Risk Manager
    $130K — $140K *
    Cal State Long Beach
    Long Beach, CA 90802 (Los Angeles County)

Find similar Divisional Business Information Security Officer jobs: