Skip to content

Open nowPosted today

Senior Business Unit Security Officer

manulife12 open roles

Where
Boston Massachusetts
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Business Unit Security Officermanulife · Boston Massachusetts
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on manulife's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. manulife postings stay open a median of 3 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted today

manulife median: 3 days open

The posting

We are seeking a talented Senior Business Unit Security Officer (BUSO) also termed as "BISO" (Business Information Security Officer) in some Org's.

The selected finalist will join the Cybersecurity, Resilience & Governance (CRG) team. As a BUSO (or BISO) you will enable business and IT partners to recognize and manage their cyber and information risk in a dynamic business environment. You will participate in critical projects and initiatives to ensure information risk is always considered and managed.

A successful BUSO will serve as a trusted partner and subject matter expert to the business and empower them to protect their information assets and intellectual property. You will help securely implement new technologies and tools, foster consistency through common methodologies and stay fully aligned with cybersecurity issues and efforts.

Office location: Boston - USA (primarily) or Toronto - Canada or Waterloo - Canada or Halifax - Canada

Work arrangement: Hybrid - 3 days in office, 2 days from Home

Position Responsibilities:

  • Perform application risk assessments from a technical security and information risk management perspective, this includes risk identification based on information criticality through to control implementation and management of risk acceptance by business areas
  • Provide application and operational security consulting services to IT, partners and clients
  • Provide hands-on guidance on secure architecture design, including application, cloud, and infrastructure security patterns
  • Act as an escalation point for complex security issues, including authentication, authorization, secrets management, and data protection
  • Guide teams on modern identity and access patterns (OAuth2, OIDC, SAML, service-to-service authentication, workload identity, etc.)
  • Provide technical oversight on cloud security (Azure/AWS) including IAM, network segmentation, and workload protection
  • Translate security requirements into practical, implementable solutions aligned with business and engineering constraints
  • Drive adoption of secure-by-design principles across new initiatives and onboarding efforts
  • Maintain, among all levels of business line staff, a high level of awareness about security issues and control objectives
  • Identify and communicate known information security control issues to business area teams providing guidance (as necessary) and oversight to ensure timely remediation of the issues
  • Provide support to other risk teams as necessary to address high-priority risks
  • Support adherence to global information security policies and standards; work with business units and technical teams to implement solutions that comply with security policies and processes
  • Actively participate in your team’s plans to achieve their goals, this includes goals that originate from CRG and the business. Participate in frameworks used to measure and report on progress towards the achievement of goals
  • Stay current on emerging technologies, key business drivers, evolving threats and opportunities from both the business and CRG
  • Collaborate with other CRG professionals within the US segment and across the company
  • Participate in divisional and global CRG projects and initiatives as requested. Ensure business requirements and needs are considered in initiatives, projects and services.

Required Qualifications:

  • 7/8+ Years of experience
  • Fewer years of experience in security is acceptable if you have systems development experience with a proven ability to implement secure applications
  • Professional certification for information security (or willingness to begin acquiring) - CISSP, CISA, CRISC, GIAC or similar credentials

Preferred Qualifications:

  • General operating knowledge of security for applications and infrastructure, security threat/risk/data classification
  • Solid understanding of Generative AI foundations, principles and tools
  • Proven ability to build relationships, engage and influence others, and work with diverse internal and international user communities as well as vendors
  • The ability to work both independently and as part of a team, managing multiple priorities and deadlines
  • The ability to work within agile development teams
  • Strong communicator and active listener with the ability to effectively articulate risk from both a business and technical standpoint to personnel with varying degrees of technical knowledge

When you join our team:

  • We’ll empower you to learn and grow the career you want.
  • We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
  • As part of our global team, we’ll support you in shaping the future you want to see.

#LI-JH

The role being advertised is an existing vacancy.

About Manulife and John Hancock

Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.

Manulife is an Equal Opportunity Employer

At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact [email protected].

Referenced Salary Location

Boston, Massachusetts

Working Arrangement

Hybrid

Salary range is expected to be between

$107,450.00 USD - $199,550.00 USD

Employees also have the opportunity to participate in incentive programs and earn incentive compensation tied to business and individual performance. The actual salary will vary depending on local market conditions, geography and relevant job-related factors such as knowledge, skills, qualifications, experience, and education/training. If you are applying for this role outside of the primary location, please contact [email protected] for the salary range for your location.

Manulife/John Hancock offers eligible employees a wide array of customizable benefits, including health, dental, mental health, vision, short- and long-term disability, life and AD&D insurance coverage, adoption/surrogacy and wellness benefits, and employee/family assistance plans. We also offer eligible employees various retirement savings plans (including pension/401(k) savings plans and a global share ownership plan with employer matching contributions) and financial education and counseling resources. Our generous paid time off program in the U.S. includes up to 11 paid holidays, 3 personal days, 150 hours of vacation, and 40 hours of sick time (or more where required by law) each year, and we offer the full range of statutory leaves of absence.

We use data and analytics technologies, such as artificial intelligence (AI), and automated processing tools, to analyze and process the information you provide to us or third parties in the application process. For more information, please refer to our personal information collection statement.

Know Your Rights I Family & Medical Leave I Employee Polygraph Protection I Right to Work I E-Verify

Company: John Hancock Life Insurance Company (U.S.A.)

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against manulife's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on manulife's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    manulife's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.