About the Role
As a Senior Business Unit Security Officer (BUSO), you will enable business and IT partners to recognize and manage their cyber and information risk in a dynamic business environment. You will participate in critical projects and initiatives to ensure information risk is always considered and managed. A successful BUSO will serve as a trusted partner and subject matter expert to the business and empower them to protect their information assets and intellectual property.
Responsibilities
- Perform application risk assessments from a technical security and information risk management perspective, including risk identification, control implementation, and risk acceptance management.
- Provide application and operational security consulting services to IT, partners, and clients.
- Offer hands-on guidance on secure architecture design for applications, cloud, and infrastructure.
- Act as an escalation point for complex security issues like authentication, authorization, secrets management, and data protection.
- Guide teams on modern identity and access patterns (OAuth2, OIDC, SAML, service-to-service authentication, workload identity, etc.).
- Provide technical oversight on cloud security (Azure/AWS), including IAM, network segmentation, and workload protection.
- Translate security requirements into practical, implementable solutions aligned with business and engineering constraints.
- Drive adoption of secure-by-design principles across new initiatives and onboarding efforts.
- Maintain a high level of security awareness among business line staff.
- Identify and communicate information security control issues to business area teams, providing guidance and oversight for remediation.
- Support other risk teams in addressing high-priority risks.
- Support adherence to global information security policies and standards by working with business and technical teams to implement compliant solutions.
- Actively participate in team goals, including those originating from CRG and the business, and contribute to frameworks for measuring progress.
- Stay current on emerging technologies, business drivers, evolving threats, and opportunities.
- Collaborate with other CRG professionals within the US segment and across the company.
- Participate in divisional and global CRG projects and initiatives, ensuring business requirements are considered.
Requirements
- 7/8+ Years of experience
- Fewer years of experience in security is acceptable if you have systems development experience with a proven ability to implement secure applications
- Professional certification for information security (or willingness to begin acquiring) - CISSP, CISA, CRISC, GIAC or similar credentials
- General operating knowledge of security for applications and infrastructure, security threat/risk/data classification
- Solid understanding of Generative AI foundations, principles and tools
- Proven ability to build relationships, engage and influence others, and work with diverse internal and international user communities as well as vendors
- The ability to work both independently and as part of a team, managing multiple priorities and deadlines
- The ability to work within agile development teams
- Strong communicator and active listener with the ability to effectively articulate risk from both a business and technical standpoint to personnel with varying degrees of technical knowledge
Skills
- Cybersecurity
- Information Risk Management
- Application Security
- Cloud Security (Azure/AWS)
- Identity and Access Management (IAM)
- OAuth2
- OIDC
- SAML
- Service-to-service authentication
- Workload identity
- Network segmentation
- Workload protection
- Secure architecture design
- Generative AI
Location
- Boston - USA
- Toronto - Canada
- Waterloo - Canada
- Halifax - Canada
Work Type
- Hybrid
- 3 days in office, 2 days from Home
Experience Level
- Senior
Education Level
- Professional certification for information security (or willingness to begin acquiring) - CISSP, CISA, CRISC, GIAC or similar credentials
Salary/Compensations
- $107,450.00 USD - $199,550.00 USD
Benefits
- Opportunity to learn and grow career
- Flexible environment
- Well-being and inclusion support
- Shaping the future
- Health, dental, mental health, vision, short- and long-term disability, life and AD&D insurance coverage
- Adoption/surrogacy and wellness benefits
- Employee/family assistance plans
- Retirement savings plans (pension/401(k) savings plans and a global share ownership plan with employer matching contributions)
- Financial education and counseling resources
- Paid time off program (up to 11 paid holidays, 3 personal days, 150 hours of vacation, and 40 hours of sick time)
- Statutory leaves of absence
About the Company
- Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better.
- Company: John Hancock Life Insurance Company (U.S.A.)
Equal Opportunity
- Manulife is an Equal Opportunity Employer
- At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals.
- We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.
- It is our priority to remove barriers to provide equal access to employment.
- A Human Resources representative will work with applicants who request a reasonable accommodation during the application process.
- All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies.
- To request a reasonable accommodation in the application process, contact hr@manulife.com.
