Levi Strauss & Co. · 7 hours ago
Business Information Security Officer
Levi Strauss & Co. is a company that encourages individuality and positive impact. The Business Information Security Officer (BISO) will act as the primary liaison between cybersecurity and business units, focusing on integrating security into operations and strategy while driving risk reduction and compliance readiness.
ApparelFashionLifestyleRetail
Responsibilities
Be a subject matter expert (SME) between cybersecurity and the lines of business in the development of appropriate policies, standards, and frameworks
Recommend resources (e.g., security architects, engineers) to achieve outcomes
Monitor trends to anticipate and plan for future impact of cyber risk on a specific business unit (BU) or function
Follow all risk remediation protocols to ensure issues are reduced, risks are accounted for and exceptions are tracked following frameworks, policies and standards set by our organization
Work with BUs to align funding requirements with strategic projects
Participate in cybersecurity and business-related councils or working groups
Oversee vendor onboarding and monitoring; enforce third‑party security requirements, issue remediation plans, and track residual risk
Collaborate with Procurement, Legal, and Business Owners to embed security in contracts and due diligence
Partner with Audit, Legal, Privacy, and Compliance on controls testing, obligations, and readiness
Educate partners on cybersecurity-related matters to increase awareness and improve culture
Develop an understanding of business goals and reframe risk discussions in business terms
Constructively engage business partners regarding cybersecurity issues
Inform business partners of the risk implications of critical decisions by combining empirical analysis with expert judgment to assess business decisions
Challenge business partners' assumptions about value drivers and present an alternate perspective
Investigate security incidents and develop remediation plans in collaboration with CSIRT or other partners responsible for incident response
Establish standard operating procedures for business engagement, risk management, exception handling, and escalation
Qualification
Required
A BA/BS in a Business or Computer Science, Information Security, Engineering, or related field
7+ years of progressive experience in cybersecurity, risk management, or technology governance; experience influencing senior business leaders
Expertise in security programs in complex global, matrixed organizations
Experience with risk assessment, incident response, and security audits
Experience with GRC platforms, cloud security, and DevSecOps
Experience with many security technologies, including firewalls, artificial intelligence, intrusion detection systems, access control systems, and encryption
Experience with security frameworks, methodologies, and regulations such as NIST Cybersecurity Framework (CSF) and ISO/IEC 27001, FAIR, PCI-DSS, GDPR, SOC 2, HIPAA
Deep understanding of business operations and how initiatives create value and risk
Demonstrated strength in coaching and developing teams to improve outcomes
Preferred
MBA or MS in Cybersecurity or Information Security desirable but not required
Certifications Preferred: CRISC, CISSP, and CISM
Benefits
401(k) matching
Paid leave
Health insurance
Product discounts
Company
Levi Strauss & Co.
Levi Strauss & Co. is a brand-name apparel company designs, markets, and sells jeans, casual and dress pants, jackets, skirts, and more.
H1B Sponsorship
Levi Strauss & Co. has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (37)
2024 (46)
2023 (52)
2022 (76)
2021 (59)
2020 (39)
Funding
Current Stage
Public CompanyTotal Funding
$554.96M2025-07-15Post Ipo Debt· $554.96M
2019-03-20IPO
Recent News
Global Cosmetics News
2026-01-03
2025-12-30
Retail Dive
2025-12-24
Company data provided by crunchbase