Job Overview
Who's the hiring manager?
Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Job Description
Job Summary
Note: Hybrid - Mondays - Thursdays on site / Fridays remote.
Preferred Location: Southlake, TX; Lonetree, CO; South Mountain, Phoenix, AZ
The Business Information Security Officer (BISO) is a subject matter professional (SMP) within the Technology Risk & Cybersecurity Compliance (TRACC) team under the client Cybersecurity Services (SCS) organization. The Digital Assets BISO acts as the primary cybersecurity risk liaison and advisor for client business units engaged in cryptocurrency and digital asset-related products, services, and vendor partnerships. This role ensures that all digital asset initiatives adhere to client's cybersecurity policies and procedures, while enabling innovation in a secure and compliant manner.
The Digital Assets BISO will oversee vendor cybersecurity controls, conduct comprehensive risk assessments, guide business and technology teams on policy and standards, and support compliance and audit activities. The role requires robust domain knowledge of crypto ecosystems, custody/security models, and third-party risk management, along with effective communication skills to bridge cybersecurity, engineering, and business functions.
Key Responsibilities
Cybersecurity Governance & Business Alignment
- Serve as the embedded security partner for Digital Assets business teams, aligning security requirements with product and operational objectives.
- Translate enterprise cybersecurity policies and procedures into practical, actionable expectations for digital asset initiatives.
- Participate in project planning, architecture reviews, and roadmap discussions to ensure secure design and regulatory alignment.
- Support risk exception, risk acceptance, and mitigation processes.
Digital Asset & Cryptocurrency Risk Assessments
- Lead end-to-end cybersecurity risk assessments for digital asset products, crypto custody models, wallet operations, blockchain integrations, and supporting vendors.
- Evaluate risks related to private key management, wallet operations, smart contract risks, node infrastructure, and transaction processes.
- Document risks, recommend compensating controls, and track remediation to closure.
Vendor Cybersecurity Oversight
- Own the security risk lifecycle for digital asset vendors-from due diligence and contract negotiation to ongoing monitoring.
- Review vendor cybersecurity evidence (SOC 2, pen tests, questionnaires, cloud posture).
- Ensure contractual controls for data protection, breach notification, crypto asset handling, and regulatory adherence.
- Track and drive remediation of vendor findings.
Education, Policy, and Standards Enablement
- Educate business, engineering, and operations teams on client's cybersecurity policies and secure practices.
- Develop crypto-specific security training and guidance.
- Promote a culture of security awareness.
Compliance, Audit, and Regulatory Support
- Prepare and coordinate internal/external audit activities.
- Ensure controls operate effectively and evidence is complete.
- Support alignment with SEC, FINRA, OCC, FFIEC, and other regulatory expectations.
Cyber Incident Preparedness & Response
- Collaborate with Cyber Operations and IR teams for crypto-specific incident preparedness.
- Contribute to playbooks for key compromise, vendor breaches, on-chain exploits, and blockchain outages.
Risk Reporting & Executive Communication
- Produce business-focused reporting on residual risk, vendor posture, assessment outcomes, KRIs, and audit findings.
- Present risks and recommendations to leadership.
Qualifications
- Bachelor's degree in Information Security, Computer Science, Engineering, or related field.
- 7+ years in cybersecurity or technology risk.
- Experience with digital assets, blockchain, or crypto custody/security.
- Familiarity with cybersecurity frameworks: NIST CSF, NIST 800-53, SOC 2, FFIEC.
- Robust communication and risk articulation skills.
Preferred Qualifications
- Cybersecurity related certification such as: CISSP, CISM, CRISC, CCSP, CISA or similar.
- Crypto-focused credentials or blockchain training.
- Knowledge of key management systems, smart contract risks, and cloud security.
- Experience with GRC (Governance Risk & Compliance) platforms.
Equal Opportunity Employer
Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status.
At Randstad Digital, we welcome people of all abilities and want to ensure that our hiring and interview process meets the needs of all applicants. If you require a reasonable accommodation to make your application or interview experience a great one, please contact HRsupport@randstadusa.com.
Pay offered to a successful candidate will be based on several factors including the candidate's education, work experience, work location, specific job duties, certifications, etc. In addition, Randstad Digital offers a comprehensive benefits package, including: medical, prescription, dental, vision, AD&D, and life insurance offerings, short-term disability, and a 401K plan (all benefits are based on eligibility).
This posting is open for thirty (30) days.
Key skills/competency
- Info Security Analyst
- Cybersecurity Risk Management
- Digital Assets Security
- Cryptocurrency Security
- Vendor Risk Management
- Compliance and Audit
- NIST CSF
- NIST 800-53
- SOC 2
- GRC Platforms
How to Get Hired at Randstad Digital Americas
- Tailor your resume: Highlight experience with digital assets, crypto security, and risk assessment. Use keywords from the job description like 'cybersecurity', 'digital assets', and 'risk management'.
- Craft a compelling cover letter: Emphasize your understanding of cryptocurrency ecosystems, NIST frameworks, and your ability to translate technical risks for business stakeholders.
- Prepare for technical questions: Be ready to discuss specific cybersecurity frameworks (NIST CSF, SOC 2), risk assessment methodologies, and your experience with crypto custody and blockchain technologies.
- Showcase communication skills: Provide examples of how you've effectively communicated complex security risks and recommendations to both technical and non-technical audiences.
- Research Randstad Digital: Understand their commitment to talent, innovation, and their role in the digital transformation landscape.
Frequently Asked Questions
Find answers to common questions about this job opportunity
Explore similar opportunities that match your background