ForgeApply
Try it free

ForgeApply · Job listing

BISO - Commercial IT

AstraZeneca

MD, Gaithersburg, US$191k – $286konsite

See all 308 open roles at AstraZeneca

Tailor your resume for this AstraZeneca job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for AstraZeneca's site. Free trial, no card required.

About this role

The Commercial IT Cybersecurity Business Information Security Officer (BISO) acts as the main cybersecurity partner to Commercial IT and related business areas. This role represents the CISO to lower cyber risk and improve resilience across platforms dedicated to clients and revenue generation. This role leads security for a SaaS-heavy, data-centric Commercial ecosystem spanning CRM, omnichannel engagement, digital experience, analytics and personalization, data and AI platforms, pricing and revenue, integration and API fabric, BI, and MDM. Key platforms include Veeva (CRM/Vault/OCE), Salesforce (Service/Health/Life Sciences/Marketing Cloud, Data 360), Adobe Experience Cloud (AEM/Analytics/Target), Tealium, Databricks on AWS, Model N, MuleSoft/SnapLogic, Power BI, and Reltio, supporting both global operations and localized implementation alongside agency and third-party delivery models.

Ready to shape how these critical capabilities stay secure while enabling bold Commercial ambitions?

Accountabilities   • Act as the Commercial IT security lead and CISO representative. Serve as the primary cybersecurity liaison for the commercial IT division and associated business units worldwide. Coordinate the security strategy with business objectives and customer-centered, revenue-enhancing outcomes.

• Lead governance and risk-based decision-making by chairing or participating in key forums, ensuring risk visibility, documented risk acceptance and ownership, and translating enterprise security policy into Commercial-ready standards, guardrails, and roadmaps.  

• Provide continuous risk advisory and posture management by maintaining awareness of threat trends and regulatory drivers relevant to Commercial operations, proactively advising on priorities, architecture decisions, and long-term security posture.  

• Establish SaaS security governance across core Commercial platforms by defining and implementing secure configuration baselines, environment and tenant management, identity, SSO and MFA patterns, logging and monitoring, and continuous control monitoring for Veeva, Salesforce, Adobe Experience Cloud, Tealium, and connected tooling.

• Strengthen digital channel and web experience security by partnering with digital teams to embed secure SDLC and release practices for externally hosted web content and experiences, aligning protections such as WAF, CDN and DDoS where applicable, and mitigating web-layer and brand-abuse risks including impersonation, account takeover, credential stuffing, web skimming and scraping.  

• Drive security controls aligned with privacy in marketing and data collection. Ensure consent, tracking governance, and secure handling of healthcare professional and consumer information across digital marketing operations. Follow GDPR and other global privacy rules.  

• Improve control maturity for commercial content, records and revenue interfaces by maturing controls for content lifecycle and records (including audit trail and e-signature expectations where applicable) and for financial and ordering interfaces where Commercial platforms touch revenue processes, including SOX-relevant controls.  

• Run vulnerability, audit, and testing remediation to closure. Facilitate risk assessment and ongoing maintenance across SaaS tenants, web properties, and integrations. Drive timely remediation of audit and penetration test findings while reducing repeat issues.

• Enhance incident readiness and response coordination by partnering with enterprise SecOps to build Commercial-relevant playbooks, align crisis and BCP activities, support post-incident reviews, and drive business-centric improvements for scenarios such as SaaS compromise, third-party or agency incidents, data exposure and digital channel compromise.  

• Advance third-party and agency risk management by defining onboarding patterns, minimum control requirements and ongoing monitoring for Commercial vendors and agencies (creative, media/AdTech partners, event hosts, SaaS providers), ensuring clear remediation paths and exit strategies.  

• Measure and communicate outcomes through KPIs, OKRs, dashboards and reporting that demonstrate risk ownership, remediation throughput, control coverage and resilience improvements over time.  

• Champion security culture and targeted awareness by tailoring training and communications for Commercial roles and partner ecosystems on phishing and social engineering, safe SaaS usage, HCP and customer data handling, and reporting obligations.  

• Plan and oversee security initiatives and investment by shaping multi-year roadmaps, business cases and resource plans; overseeing delivery of security improvements aligned to Commercial programs including platform changes, integrations and data initiatives.  

• Lead and develop the BISO team by directing a group spanning risk reporting and analytics, risk management and remediation, and security consulting tailored to SaaS-heavy international Commercial operating models; setting clear goals tied to measurable risk reduction and resilience outcomes; coaching for high performance.  

Essential Skills/Experience   • Information security leadership: 10+ years of experience in information security positions, with 5+ years’ experience overseeing an information security functionand influencing senior business/IT stakeholders.  

• Commercial pharma domain familiarity: Experience supporting Commercial/Go-to-Market functions in a regulated life sciences environment (marketing operations, sales operations, customer/HCP engagement, digital channels, and in-country execution models).  

• SaaS/CRM security depth: Hands-on experience securing Veeva CRM, Veeva Vault, Veeva OCE, and/or Salesforce ecosystems (Service Cloud, Health Cloud, Life Sciences Cloud, Marketing Cloud, Data 360), including identity/access models, connected apps, environment strategy, secure configuration, and operational monitoring.  

• Digital experience and marketing technology secur

Tailor your resume for this AstraZeneca role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)