1

Vice President Biso Jobs (NOW HIRING)

Showing results 21-28

Vice President Biso information

See salary details

$43.5K

$157.5K

$277.5K

How much do vice president biso jobs pay per year?

As of Sep 6, 2026, the average yearly pay for vice president biso in the United States is $157,532.00, according to ZipRecruiter salary data. Most workers in this role earn between $115,000.00 and $190,000.00 per year, depending on experience, location, and employer.

What is a vice president BISO?

A Vice President BISO (Business Information Security Officer) is responsible for aligning information security strategies with the business goals of an organization. They act as a bridge between the cybersecurity team and business units, ensuring that security policies support business operations while mitigating risks. Their duties often include developing security programs, overseeing compliance, managing risk assessments, and communicating security priorities to senior management. Additionally, they collaborate with stakeholders to drive security awareness and integrate best practices across the company.

How does a vice president BISO collaborate with IT and business units to enhance cybersecurity posture?

A Vice President BISO (Business Information Security Officer) acts as a bridge between business units and the IT security team, ensuring that cybersecurity strategies align with business objectives. This role involves regular meetings with business leaders to understand their needs and risks, translating them into actionable security initiatives with IT. Collaboration often includes risk assessments, policy development, and incident response planning, ensuring both compliance and operational efficiency. Effective BISOs foster a culture of security awareness across departments and help prioritize investments that mitigate real business risks.

What are the key skills and qualifications needed to thrive as a vice president BISO?

To thrive as a Vice President, BISO, you need deep expertise in information security management, risk assessment, and business operations, typically supported by a bachelor’s or master’s degree in information security or a related field. Familiarity with security frameworks (such as NIST, ISO 27001), regulatory compliance standards, and certifications like CISSP or CISM are commonly required. Strategic leadership, strong communication, and the ability to influence stakeholders are crucial soft skills in this role. These skills and qualities are important because they enable effective alignment of security initiatives with business goals, ensuring both protection and growth.

What is the difference between Vice President Biso vs Director of Business Operations?

AspectVice President BisoDirector of Business Operations
CredentialsTypically requires extensive experience in business management, leadership, and industry-specific knowledge; often holds a bachelor's or master's degree.Usually requires a bachelor's degree in business or related field; some roles prefer advanced degrees or certifications.
Work EnvironmentStrategic leadership role, often involved in executive decision-making, high-level meetings, and cross-departmental oversight.Operational focus, managing daily business functions, process improvements, and team management.
Employer & Industry UsageCommonly used in large corporations, finance, and industry sectors requiring strategic oversight.Widely used across industries for overseeing business operations and ensuring efficiency.

The Vice President Biso is a senior leadership role focused on strategic initiatives and executive decision-making, while the Director of Business Operations handles daily operational management and process improvements. Both roles require strong business acumen but differ in scope and level of responsibility.

What cities are hiring for Vice President Biso jobs?

Cities with the most Vice President Biso job openings:

What are the most commonly searched types of Biso jobs?

The most popular types of Biso jobs are:

What states have the most Vice President Biso jobs?

States with the most job openings for Vice President Biso jobs include:

Infographic showing various Vice President Biso job openings in the United States as of August 2026, with employment types broken down into 94% Full Time, and 6% Part Time. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution, with an average salary of $157,532 per year, or $75.7 per hour.

BISO - Enterprise Technology Services (ETS)

AstraZeneca

Gaithersburg, MD

Full-time

Posted 9 days ago


AstraZeneca rating

8.4

Company rating: 8.4 out of 10

Based on 45 frontline employees who took The Breakroom Quiz

23rd of 86 rated pharmaceutical


Job description

The BISO will serve as the primary strategic cybersecurity partner to the IT Enterprise Technology Services (ETS) organization and its associated technology domains, representing the CISO by leading cybersecurity engagement, alignment, and delivery of cybersecurity risk and resilience outcomes across AstraZeneca's foundational technology estate. ETS is the enterprise technology backbone of AstraZeneca - delivering sustainable and globally scaled enterprise technology services that enable the company's scientific, manufacturing, and commercial activities. As AstraZeneca's global technology operations organization, ETS focuses on the reliable delivery and operation of enterprise technology services, while cybersecurity and IT risk accountability is owned within the CISO Cybersecurity organization that this role represents.

This customer-facing role is closely coupled with the ETS leadership team and operates as a dotted-line function to the ETS VP-level leadership, supporting the cloud and infrastructure, network and connectivity, digital workplace, identity and access, service operations, and technology governance capabilities on which the enterprise depends. Accountabilities Strategic partnership and governance: Act as the primary strategic partner and security consultant to ETS leadership, driving alignment between enterprise technology priorities, operational service commitments, and the enterprise cybersecurity strategy. Chair or participate in relevant governance forums, ensuring risk-based decision-making, clear accountability, and visibility of cybersecurity outcomes across cloud, infrastructure, network, workplace, and service management portfolios.

Cloud and infrastructure security: Provide cybersecurity leadership across ETS cloud environments and on-premises infrastructure, including hosting, cloud subscriptions, compute, storage, and operating systems supporting both ETS platforms and applications owned by other business technology groups. Drive cloud security posture management, infrastructure-as-code hardening, secure configuration baselines, workload protection, privileged access management for infrastructure, and consistent controls across AWS and on-premises platforms and Windows and Linux server estates. Network security and connectivity: Partner with network engineering teams to ensure robust network security architecture across AstraZeneca's global networks, including segmentation and micro-segmentation, firewall governance, internet and proxy connectivity, DNS security, intrusion detection and prevention, traffic inspection, secure remote access, and secure integration with third-party networks, sites, data centres, and cloud service providers.

Advance network reliability and resilience objectives alongside security outcomes. Digital workplace and Site IT security: Guide the security of end-user devices, workplace engineering, and endpoint management, together with productivity and collaboration services such as Microsoft 365, Teams, SharePoint, OneDrive, Viva, and the Power Platform. Champion protection against phishing, business email compromise, malware delivery, data exfiltration, unauthorized sharing, and account compromise, and balance controls with employee technology experience so security enables rather than hinders workforce productivity across the global device estate and local technology support functions.

Service operations security: Ensure cybersecurity principles are embedded within ETS service operations, including monitoring, incident and problem management, patching, release coordination, change management, service continuity, and operational automation. Integrate security into ITSM processes and the CMDB, drive timely patching and vulnerability remediation, and ensure change and release practices preserve a strong, auditable security posture across the estate. Technology governance and standards: Embed cybersecurity into ETS technology governance disciplines, including the service catalogue and demand management, configuration data, technology standards, lifecycle management, supplier coordination, and operational performance reporting.

Ensure security requirements are built into technology standards, platform guardrails, reusable controls, and lifecycle and decommissioning processes, reducing risk from unsupported and end-of-life technology. Risk management and assurance: Carry out cyber risk assessments and make recommendations to ETS leadership on cybersecurity best practices, control improvements, and appropriate technology solutions. Support security assessments, threat modeling, and design reviews for complex enterprise platforms, infrastructure services, and reusable capabilities.

Partner with control owners to ensure security requirements are built into engineering standards, infrastructure baselines, and operational workflows. Vulnerability management and continuous improvement: Facilitate vulnerability management, audit and penetration test finding remediation, and implementation of cybersecurity control maturity improvements across the ETS technology estate. Deliver ETS leadership actionable information regarding identity, service account, infrastructure, network, endpoint, and platform vulnerability management priorities.

Identify and lead improvements in cyber processes, engagement models, and operational effectiveness; establish KPIs, OKRs, and feedback loops to measure and optimize outcomes. Third-party and supplier security: Lead a practical approach to third-party cybersecurity risk for the ETS ecosystem of cloud providers, infrastructure and network vendors, managed service providers, and technology suppliers. Govern vendor security assessments, contractual controls, ongoing assurance, and secure integration patterns that enable reliable enterprise service delivery without compromising confidentiality, integrity, or availability.

Risk reporting and metrics: Create an ETS-focused risk dashboard and cybersecurity metrics that translate complex security data into clear, actionable insight for technology and service leaders. Coordinate risk profile development and distribution to ETS stakeholder audiences, and use data to drive risk-reduction outcomes and informed prioritization across the estate. Incident preparedness and response: Partner with enterprise security operations, infrastructure teams, network teams, and service management leaders to enhance readiness, playbooks, and crisis alignment for incidents that could affect enterprise infrastructure, connectivity, workplace services, identity, or IT service continuity.

Support cybersecurity assessments and penetration tests, and contribute to post-incident reviews and business-centric improvements. Threat awareness: Maintain significant knowledge of threats relevant to enterprise IT infrastructure and operations, including ransomware, cloud infrastructure breach, network intrusion, identity and credential compromise, endpoint compromise, email account takeover, supply chain compromise, and disruption to critical IT services. Routinely share insights and practical implications with stakeholders.

Stakeholder management: Build trusted relationships with senior leaders across ETS and the broader IT and Cybersecurity communities, including infrastructure, network, workplace, identity, and service operations leaders, and represent ETS cybersecurity needs within enterprise governance bodies. Essential Skills & Experience Information security leadership: 10+ years of experience in information security positions, with 5+ years' experience overseeing an information security function and influencing senior business and IT stakeholders. Enterprise infrastructure and operations domain familiarity: Demonstrated experience supporting enterprise technology operations - cloud and on-premises infrastructure, networks, digital workplace, identity, and IT service management - with the ability to translate technical and operational priorities into effective cybersecurity controls and risk decisions.

Infrastructure and cloud security expertise: Extensive experience with enterprise IT infrastructure security, including cloud platforms (IaaS, PaaS, SaaS), compute and storage, operating system hardening, infrastructure-as-code, and secure configuration across hybrid and multi-cloud environments (for example AWS and on-premises). Network security and architecture: Understanding of enterprise network security principles, including segmentation and micro-segmentation, firewall governance, zero-trust network access, secure remote connectivity, DNS security, intrusion detection/prevention, proxy/internet connectivity, and secure integration with cloud providers and third-party networks. Digital workplace and endpoint security: Familiarity with endpoint detection and response, device and mobile device management, patch management, data loss prevention, encryption, and secure configuration across diverse user device estates, together with security of productivity and collaboration platforms such as Microsoft 365, Teams, SharePoint, and OneDrive.

IT service management security: Understanding of ITSM frameworks and processes (ITIL or equivalent) and how cybersecurity integrates with monitoring, incident management, change management, problem management, request fulfillment, and configuration management (including the CMDB, for example in ServiceNow) in enterprise environments. Frameworks and control implementation: Experience implementing and operationalizing controls defined by NIST CSF, CIS-18, ISO 27001/27002, and related cybersecurity control frameworks, and applying them pragmatically to infrastructure, network, workplace, identity, and operational ecosystems. Vulnerability and security testing management: Experience managing vulnerability management and recurring hygiene efforts across cloud infrastructure, servers, network devices, endpoints, and identities; familiarity with penetration testing, infrastructure and application security testing, and risk-based remediation approaches.

Risk dashboarding and data analysis: Familiarity with risk dashboarding, data analysis, and leveraging actionable data to achieve risk reduction outcomes, including the ability to translate complex security telemetry into clear business and technology insight. Incident response collaboration: Understanding of global security operations and incident response processes, including scenarios such as cloud infrastructure breach, network intrusion, ransomware, endpoint compromise, identity and account takeover, and disruption to enterprise IT services. Stakeholder communication: Strong written and verbal communication skills, with proven ability to present complex technical information to both technical and non-technical audiences, including enterprise technology leadership, infrastructure and network leaders, service delivery managers, and governance bodies.

Execution under pressure: Proven ability to manage competing priorities and operate under time constraints tied to infrastructure changes, releases, service commitments, and enterprise delivery timelines, and drive outcomes through influence across matrixed teams. Cross-functional collaboration: Experience working collaboratively across IT, infrastructure, network, workplace, identity, service management, legal, and sourcing disciplines, and the ability to integrate cybersecurity considerations into multi-disciplinary decision-making. Problem solving and autonomy: Excellent problem-solving and troubleshooting skills, with a proven autonomous working style, clear direction-setting, and the ability to establish and pursue meaningful goals in ambiguous environments.

Bachelor's degree in science or relevant technical field of study; Master's preferred. Desirable Skills & Experience Pharmaceutical or life sciences industry experience: Prior experience in a regulated pharmaceutical, biotechnology, or life sciences environment, with understanding of GxP systems, regulatory expectations (e.g., FDA, EMA, MHRA), and the interplay between cybersecurity, data integrity, and patient safety as they relate to enterprise infrastructure and services. Zero-trust architecture expertise: Familiarity with designing or implementing zero-trust security models across enterprise environments, including identity-centric access controls, continuous verification, least-privilege enforcement, micro-segmentation, and context-aware policy engines spanning infrastructure, network, and workplace services

Cloud-native security tooling and automation: Practical experience with cloud-native security tools such as cloud security posture management (CSPM), cloud workload protection platforms (CWPP), cloud infrastructure entitlement management (CIEM), and container security solutions across major cloud providers (AWS, Azure, GCP). Third-party and supply chain risk management: Experience leading or contributing to third-party cybersecurity risk assessments, vendor security governance programs, and supply chain risk frameworks covering both technology suppliers and managed service providers. Security metrics, reporting, and executive communication: Demonstrated ability to develop and present meaningful cybersecurity metrics, risk dashboards, and executive-level reporting that drives informed decision-making and demonstrates return on security investment to business and technology leadership.

Automation and AI for cybersecurity: Demonstrated ability to apply automation, and where appropriate LLMs and agentic tooling, to improve cybersecurity and operational outcomes - for example faster risk triage, better control evidence, and improved detection and response - while protecting sensitive data. Certifications: Relevant industry certifications are valued, such as CISSP, CISM, CISA, CCSP, CRISC, SABSA, TOGAF (Security Architecture), AWS/Azure/GCP Security Specialty, or equivalent professional qualifications demonstrating breadth across security leadership, infrastructure, cloud, and risk management disciplines. Business continuity and disaster recovery: Experience contributing to or overseeing business continuity planning and disaster recovery strategies for critical IT infrastructure, enterprise services, and operational platforms, including tabletop exercises, recovery testing, and resilience architecture.

When we put unexpected teams in the same room, we unleash bold thinking with the power to encourage life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office.

But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.

The annual base pay for t...


What AstraZeneca employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


AstraZeneca logo

About AstraZeneca

Sourced by ZipRecruiter

AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery, development and commercialization of prescription medicines for some of the world's most serious diseases. But we're more than one of the world's leading pharmaceutical companies. A place built on courage, curiosity and collaboration - we make bold decisions driven by patient outcomes. Empowered to lead at every level, free to ask questions and take smart risks that write the next chapter for our pipeline and Oncology team. Make a meaningful impact that brings real benefits to society. By applying your knowledge of data, you will help to redefine our industry and ultimately save lives. Work with experts who share a common goal: to accelerate the potential of medicines and the science of tomorrow.

Industry

Pharmaceutical product wholesalers and pharmaceutical and medicine manufacturing

Company size

10,000+ Employees

Headquarters location

Cambridge, Cambridgeshire, GB