Apply now »

Business Information Security Officer


Berre l'Etang, Bouches-du-Rhône, FR, 13131

Req ID:  74520
Facility:  Berre Cpb-521
Department:  Business Systems Security
Division:  Global Business Services

Business Information Security Officer

Basic Function

The BISO will provide tactical direction to the regional and local sites. This role is a hands-on role that will ensure the subject matter expertise, and processes for the effective execution of global cybersecurity program, support the computing systems of site’s business and process control systems to coordinate changes and provide security and to ensure optimum integrity, confidentiality, reliability, and availability.  The role acts as the main local point of contact with the business and manufacturing in supporting the center led business systems security in the region.  This role will be a security evangelist and drive company-wide focus to prevent, detect, and remediate cyber security threats. Work life balance is offered consistent with LyondellBasell’s Global Remote Working Policies.

Roles & Responsibilities

  • Oversee the operation of regional and local preventative systems and business / manufacturing computing systems (firewall, versions, patches, protection, certificate management, etc.)
  • Ensure that all regional sites’ networks and systems comply with corporate standards; communicate threats appropriately
  • Coordinate IT and manufacturing changes, etc. with site management
  • Participate in Level 2 monitoring, support, and SVA (site vulnerability assessments)
  • Assist in Operational Excellence assessment support and facilitate forensics investigations
  • Support project design and implementation
  • Ensure effective regional security awareness program implementation
  • Effectively facilitate center-led (located on-site or regional) support model; security responsibilities for site’s manufacturing computing equipment
  • Assist in setting technical direction and strategy for ICS systems architecture and security
  • Support the management, planning and execution of budget activities
  • Support for LyondellBasell’s Diversity, Equity, and Inclusion (DEI) strategy and values

Roles & Responsibilities (2)

  • Improve overall cyber resilience to the next level of maturity and effectiveness
  • Regularly analyze LyondellBasell’s intrusion resistance and lead efforts to improve it through automation, integration, and aggregation.
  • Provide information protection expertise to IT operational teams to ensure systems are properly protected and monitored by design.
  • Evangelize security within LyondellBasell and drive changes needed to response to emerging threats
  • Profile new and emerging threats to the IT landscape
  • Serve as a member to the event response team, providing mentoring to other team members as needed, while performing Level 2 support.
  • Contribute ideas to the future state technology roadmap ensuring effective investments are made to enable scale, quality, and maintenance and overall cost effectiveness.
  • Understand security vulnerability management and the process
  • Be able to conduct vulnerability assessments for the IT infrastructure


  • Bachelor’s degree in an appropriate field, or equivalent professional experience
  • Exceptional communication and advocacy skills, both verbal and written, with the ability to express complex and technical issues in clear and concise language
  • Ability to collaborate and communicate effectively with both business-oriented and technology-oriented personnel
  • Ability to work with minimal supervision
  • Working knowledge of one or more of these technologies: Microsoft Windows, Active Directory, domain architecture & management, group policies, network topology and components, antivirus, SQL server, and database management


Preferred Qualifications


  • Experience in information security, information technology (IT), or operational technology (OT)
  • Experience developing and refining risk based, defense-in-depth security architectures based on established frameworks such as NIST or ISO
  • Working knowledge of plant ICS systems (i.e. Modbus, OPC communications, Aspentech, PAS, Honeywell, DeltaV etc.)
  • Practical knowledge of different message distribution techniques to ensure end user’s understand and apply the behavioral changes necessary to reduce the ‘human factors’ risk
  • Detailed understanding of manufacturing and business systems
  • Ability to work with minimal supervision
  • Ability to travel as required, up to 10%
  • Experience with security incident and event analytics and monitoring technology including regular maintenance and tuning, correlation rules, filters, lists, views, and reports
  • CISSP, CCNA, or other security recognition desirable
  • Intercultural competence


Builds effective teams
Cultivates innovation
Customer focus
Demonstrates courage
Drives results
Ensures accountability
Instills trust and exemplifies integrity

Apply now »