Director, Security Consulting — Business Information Security Officer (BISO) Commercial IT
At AstraZeneca, we pride ourselves on crafting a collaborative culture that champions knowledge-sharing, ambitious thinking and innovation – ultimately providing employees with the opportunity to work across teams, functions and even the globe.
Recognizing the importance of individualized flexibility, our ways of working allow employees to balance personal and work commitments while ensuring we continue to create a strong culture of collaboration and teamwork by engaging face-to-face in our offices 3 days a week. Our head office and BlueSky Hub in downtown Toronto are purposely designed with collaboration in mind, providing space where teams can come together to strategize, brainstorm and connect on key projects.
Our dedication to sustainability is also central to our culture and part of what makes AstraZeneca a great place to work. We know the health of people, the planet and our business are interconnected which is why we’re taking ambitious action to tackle some of the biggest challenges of our time, from climate change to access to healthcare and disease prevention.
Introduction to role:
Are you ready to shape enterprise security strategy where it matters most—protecting innovation and enabling life-changing medicines to reach patients faster? Do you want to influence VP and executive stakeholders while embedding secure-by-design practices into transformative platforms, AI/ML programs, M&A, and regulated digital products?
As Director, Security Consulting, you will serve as a senior, trusted advisor embedded with product, platform, and business leaders. You will own the strategy, standards, and delivery of security consulting for a complex, global portfolio, translating business goals, threat intelligence, and regulatory obligations into scalable patterns and policy-aligned architectures. Your work will accelerate risk-informed decisions, reduce systemic risk, and improve control effectiveness without slowing innovation.
Based in Gaithersburg and reporting into the Commercial IT BISO, you will operate across a highly matrixed environment to set the guardrails that enable speed with confidence. You will partner closely with architects, engineers, data and AI leaders, and security operations to drive measurable improvements in resilience, audit readiness, and time-to-value.
Accountabilities:
Strategy and Function Ownership: Own the strategy, operating model, standards, and roadmap for security consulting across the assigned portfolio; align with CISO priorities, product and platform roadmaps, and enterprise architecture, and represent the function in executive governance to drive risk reduction at scale.
Executive Engagement and Influence: Advise VP/SVP business and technology leaders; translate threat intelligence, regulatory drivers, and commercial strategy into clear, defensible priorities and investment decisions that balance risk, cost, and speed.
Governance Integration: Embed security into program and product lifecycles with traceable requirements, clear ownership, escalation paths, and measurable outcomes, minimizing friction while maintaining strong control health.
Secure-by-Design Standards: Define and enforce secure patterns, guardrails, threat models, and reference architectures; champion shift-left practices and continuous security testing integrated into CI/CD.
Security Consulting and Major Assessments: Lead high-impact assessments across transformative platforms, M&A, AI/ML, major SaaS adoptions, and regulated digital products; document risks, exceptions, and treatments aligned to risk appetite and business objectives.
Orchestration: Direct deep architecture reviews, red/blue team consultations, and threat modeling accelerators; convert findings into prioritized, funded remediation and durable architectural uplift.
Program and Portfolio Leadership: Sponsor multi-team security initiatives such as cloud control baselines, AppSec uplift, identity modernization, and third-party assurance; define success metrics and change management to land adoption that lasts.
Control Assurance and Compliance: Provide executive oversight of control health, testing, and audit readiness across ISO 27001, SOC 2, SOx ITGC, and GxP/GMP where applicable; ensure durable remediation and continuous improvement.
Third-Party and Supply Chain Security: Set the standard for supplier risk management, security clauses, due diligence, and continuous monitoring; manage concentration and systemic risks and own executive escalations.
Data, AI, and Privacy Enablement: Partner with data, AI, and privacy leaders to safeguard sensitive and regulated data; enable compliant analytics and AI/ML through classification, encryption, DLP, monitoring, and model-risk controls.
Incident Preparedness and Response Leadership: Partner with security operations and crisis management to enhance readiness, playbooks, and BCP alignment; sponsor post-incident corrective actions and drive durable control improvements.
Metrics, Reporting, and Executive Communication: Define and own KPIs, KRIs, and business-centric dashboards; communicate posture and priorities to executives, governance bodies, and where required to Audit Committee and Board-level forums.
People Leadership and Talent: Lead and develop a team of senior security consultants; build succession, drive performance, and foster a culture of accountability, inclusion, and continuous learning across virtual and matrixed teams.
Innovation and Emerging Technology: Drive secure adoption of AI/ML including LLMs and agentic systems, IoT/OT, SaaS, and data-centric initiatives; shape enterprise standards for data protection, identity, and zero-trust across hybrid environments.
Essential Skills/Experience:
Bachelor’s degree in Information Security, Computer Science, Risk Management, or related field
12-15 years of progressive experience in information security, including 8+ years leading security consulting, architecture, or BISO functions and influencing senior business and IT executives at VP/SVP level.
Demonstrated track record of setting enterprise security strategy, standards, and reference architectures in complex, global organizations, and measuring the maturity and business impact of those standards over time.
Demonstrated ability to apply LLMs and agentic automation to improve cybersecurity and business outcomes, translating use cases into measurable gains (for example faster risk triage, better control evidence, improved detection and response) while protecting sensitive data.
Deep experience implementing and operationalizing controls defined by NIST CSF, ISO 27001/27002, CIS Controls, and related cybersecurity control frameworks, and demonstrating measurable maturity improvement at enterprise scale.
Proven ability to design and govern meaningful risk dashboards and metrics (for example in Power BI or equivalent), using actionable data to prioritize remediation, defend investment decisions, and demonstrate risk reduction and resilience improvements.
Strong understanding of global security operations, incident response, and crisis management; experience as a senior security partner during high-severity events and post-incident reviews.
Exceptional written and verbal communication skills, with proven ability to present complex technical and risk information to executive, regulatory, and Board-level audiences as well as in-country and business stakeholders.
Proven ability to manage competing executive-level priorities, operate under time constraints tied to launches, regulatory commitments, and business campaigns, and drive outcomes through influence across a highly matrixed, global organization.
Demonstrated success building and retaining high-performing security consulting and architecture teams, including senior practitioners, in a global, multicultural environment.
Proven track record of owning enterprise-wide security consulting, architecture, or risk programs in complex, regulated environments — pharmaceutical, healthcare, life sciences, financial services, or comparable.
Demonstrated experience setting standards, patterns, and governance that have been adopted enterprise-wide and have produced measurable business and risk outcomes.
Deep experience with risk assessment methodologies, control frameworks (NIST CSF, ISO 27001, CIS Controls), and global regulatory regimes; experience leading audit and regulator interactions.
Demonstrated ability to engage, influence, and advise senior executives (VP/SVP and above), translating technical risks into business and strategic language.
Experience leading and developing cross-functional, geographically distributed teams of senior security professionals; accountable for talent, performance, and succession.
Skills & Competencies:
Ability to set a multi-year vision, connect security to enterprise strategy, and make defensible trade-offs across risk, cost, speed, and customer experience.
Deep understanding of cyber risk assessment, risk treatment, and risk monitoring practices; ability to quantify, prioritize, and communicate risk in business and financial terms.
Strong grounding in cybersecurity architecture, cloud and data security, identity, application security, and zero-trust; ability to set and enforce enterprise-wide patterns.
Strong program and portfolio management capability, including milestone tracking, RAID management, benefits realization, and executive-level stakeholder reporting.
Ability to analyze complex security landscapes, identify systemic patterns, and develop strategic mitigation approaches grounded in data.
Exceptional written and verbal communication; ability to present to executive audiences, governance bodies, regulators, and Board-level forums, and to drive decision-making through influence.
Proven ability to build trusted, durable relationships with senior business, technology, audit, legal, and regulatory leaders, and to foster a collaborative, inclusive security culture.
Strong familiarity with pharmaceutical and life-sciences regulations (GxP, FDA 21 CFR Part 11) and global data protection regimes (GDPR, NIS2, HIPAA), and experience translating these into actionable controls.
Track record of leading, coaching, and retaining senior security talent in a global, matrixed environment; commitment to inclusion, development, and high performance.
Desirable Skills/Experience:
Master’s degree strongly preferred
Professional certifications such as CISSP, CISM, or CRISC.
Additional certifications (CCSP, CGEIT, ISO 27001 Lead Auditor/Implementer, CISA, TOGAF, SABSA).
Experience working in a global, matrix organization with distributed teams and significant operations in multiple regions, including the US, UK, Sweden, China, Japan, India, and Latin America.
Direct experience as a BISO, Senior Security Architect Lead, or Head of Security Consulting in a regulated industry.
Hands-on knowledge of emerging technologies and associated security risks (multi-cloud, AI/ML and agentic systems, IoT/OT, quantum-safe cryptography).
Understanding of business continuity, disaster recovery, and crisis management at enterprise scale.
Experience leading security input into M&A due diligence, integration, and divestitures.
Track record of representing security at Audit Committee or Board-level forums.
Why AstraZeneca:
Join a technology-forward environment where security enables bold science to move faster, safely. Here, unexpected combinations of experts come together to solve hard problems—architects with data scientists, engineers with product strategists—unleashing ideas that translate directly into better outcomes for patients and the business. You will operate with the investment, scale, and executive sponsorship to modernize controls across hybrid cloud, data, and AI, while working in an inclusive culture that values kindness alongside ambition. Your leadership will simplify complex landscapes, build trusted partnerships, and turn cutting-edge concepts into scalable guardrails that raise resilience across a global enterprise.
Call to Action:
If you are ready to lead secure-by-design at enterprise scale and turn strategy into measurable, business-aligned risk reduction, step forward and show us the impact you will deliver!
Great People want to Work with us! Find out why:
Are you interested in working at AZ, apply today!
AstraZeneca is an equal opportunity employer that is committed to diversity and inclusion and providing a workplace that is free from discrimination. AstraZeneca is committed to accommodating persons with disabilities. Such accommodation is available on request in respect of all aspects of the recruitment, assessment and selection process and may be requested by emailing View email address on careers.astrazeneca.com .
#LI-Hybrid
Date Posted
17-Jun-2026Closing Date
01-Jul-2026Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.
- A leading consulting firm is seeking a Program Assistant for an on-site position in Rockville, MD. The role involves consolidating weekly inputs... ...an Associate’s degree, 3 years of experience in a federal IT services environment, and proficiency in Microsoft 365 tools. The...Suggested
$107.9k - $195.05k
...seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This... ...solutions with business objectives, deliver technical... ...with collaboration/IT systems (e.g., ticketing... ...serving government and commercial customers with smarter,...CommercialLocal areaImmediate startNight shiftDay shift- A national security firm in Gaithersburg, MD is seeking a Senior SCRM Analyst to support critical data and analytics programs. The role involves risk assessments, policy compliance, and continuous improvement of supply chain risk management processes. Candidates must have...Suggested
$100k - $120k
...relationships and support mission-critical small business initiatives within the government? ROCIMG is a consulting firm serving federal and commercial clients with a focus on strategy,... ...Experience supporting acquisition offices within DoD or other federal agencies....CommercialFull timeContract workPart time$70k - $82k
...Department of Defense? ROCIMG is a consulting firm serving federal and commercial clients with a focus on strategy,... ...KPIs) to assess effectiveness and inform strategy adjustments. Develop... ...Journalism, Marketing, Public Policy, Business, Data Analytics, or related field....CommercialFull timePart time$75k - $85k
...problems? We are ROCIMG, a consulting firm serving the federal government and commercial clients with a focus... ...continue to grow our business, we are looking for a... ...Gather and analyze information, formulate and test hypotheses... ...Program Management Office (PMO) services and...CommercialFull timePart timeWork experience placementWork at office- Learning Without Tears in Gaithersburg, Maryland, is seeking a strategic IT leader to develop and manage their IT organization. The ideal candidate will lead the IT team, drive innovation, and ensure effective communication with the Senior Leadership Team. This role requires...
$140k - $165k
...We are a technology consulting and cloud solutions organization... ...of highly available, secure, and mission-critical... ...for government and commercial clients. Our teams... ...solutions that solve complex business and operational... ...military status, genetic information or any other basis...CommercialLocal area- ...accelerating evidence-informed decisions across... ...Enterprise AI, IT, Medical leadership... ...; ensure privacy, security, and regulatory alignment... ..., Digital/IT, or Commercial Operations; proven... ...topics into business value; outstanding... ...per week from the office. But that doesn't...CommercialHourly payContract workTemporary workWork at officeLocal areaWorldwideFlexible hours3 days per week
$70k - $90k
...Compliance Specialist in Rockville, MD. This role is responsible for performing quality control reviews and ensuring compliance of commercial loan data, supporting audits and regulatory requirements. The ideal candidate will hold an Associate’s or Bachelor’s degree with...Commercial$175k - $250k
Piper Companies is looking for a Director, Platform Technology and Operations to join a large pharma biotechnology organization. This... ...Engineering/Development with facility design exposure; late stage and commercial Pharma experience. Demonstrated experience in process scale...CommercialFull time$136.5k - $227.5k
...Vacancy Name Associate Director, TMF Operations and Clinical Operations Analytics... ...initiatives that align with organizational business objectives. • Create and generate sophisticated... ...(NASDAQ: IMCR) is a pioneering, commercial-stage T cell receptor biotechnology...CommercialFull timeContract work$17.65 - $19 per hour
Overview Join a collaborative team dedicated to delivering exceptional patient care as a Physical Therapy Aide, while gaining valuable healthcare skills that can launch your career. Work alongside leading experts in Physical and Occupational Therapy, playing a key role ...Full timeTemporary workLocal areaFlexible hours- ...plumbing department operations, coordinating field teams, and ensuring project efficiency. Candidates should have over 10 years of commercial plumbing experience and strong communication skills. The position also requires effective resource coordination and maintaining...CommercialFor contractors
- ...teams including engineering, security, and network & system... ...utilizing industry standard commercial and open-source toolsets... ...Work with the functional business areas as needed during incident... ...sexual orientation, genetic information or any other protected status...CommercialRemote workFlexible hours
- ...evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics. Pay Transparency Maximus compensation is based on various factors including...Minimum wageFull timeContract workTemporary workTraineeshipWork experience placementRemote work
$154.05k - $278.48k
...architecture, development, security, operations, and integration... ...subject to change based on business needs, Leidos reasonably anticipates... ...serving government and commercial customers with smarter, more... ...January 3, 2025. For more information, visit . Pay and Benefits...CommercialLocal areaImmediate startRemote workFlexible hours- Leidos is seeking a Senior Business Operations Specialist in Gaithersburg, Maryland. This position supports enterprise data and analytics... .... Join us to contribute to mission-critical projects combining data analytics with national security outcomes. #J-18808-Ljbffr Leidos
$92.3k - $166.85k
Leidos is seeking a Senior Resource Operations Manager in Gaithersburg, Maryland, to support resource planning for a Department of Defense data and analytics program. This role involves working with government partners and cross-functional teams to enhance operational efficiency...- A community college in Germantown, Maryland is seeking a full-time Director, Infrastructure and Network Engineering. The role involves leading IT architecture and managing complex projects to enhance the college's enterprise systems. Candidates must have a Bachelor's degree...Full time
$2,000 - $4,000 per month
...to hire an experienced B2B/Commercial Sales personnel for a Commercial... ...customers with product information. Explain credit or... ...warranties, and delivery dates. Consult with clients after sales or... ...prospective customers by using business directories, following leads...CommercialFull timeContract workFlexible hours- ...Hands-on experience of cyber security and privacy industry, including... ...availability of sensitive information. *) Hands-on experience working... .... *) Working knowledge of IT enterprise operations,... ...intelligence, and assess potential business impact. *) Hands-on...Work experience placement
$93k - $118k
...established HVAC, Plumbing, and Mechanical contractor serving commercial, residential (custom homes), industrial, and government clients... ...service delivery Safety & Compliance Partner with the Safety Director to maintain compliance with OSHA and company safety standards...CommercialFull timeFor contractors- ...Description The Director of Information Technology is... ...cybersecurity, and business systems to... ...technology leader and IT business partner... ...closely with Commercial, Finance, HR, Customer... ...CRM vendors, consultants, and technology... ...regulatory, privacy, and security requirements,...Commercial
$169.52k
...ID: 44996BR Business Unit: IND Job... ...is seeking a Director of Business Development... ...insights to inform leadership decisions... ..., management consulting, advisory services... ...solutions, cyber-security, technology, and... ...analysis • Strong commercial acumen (pricing,...CommercialFull timeH1bFlexible hours- ...company is seeking an IT Management Analyst... ...Department of Energy's Office of the Chief Information Officer. This... ...Collaborate with legal, security, and technical teams... ...Bachelor's degree in Business Administration,... ...we apply our proven commercial solutions to a deep...CommercialContract workWork at officeLocal areaFlexible hours
$270.22k - $405.33k
...stage development and commercialization, rapidly progressing... ...Commercial Executive Director, Cell Therapy Strategy... ..., including business development and competitive... ...and publicly available information at the brand and Therapeutic... ...in life sciences or consulting firm with focus in...CommercialHourly payTemporary work$95k - $105k
INNOVATIVE CONSULTING & MANAGEMENT in Gaithersburg, MD is looking for a Corporate Recruiter to lead full-life cycle recruitment for Federal and State Government contracts and commercial clients. The candidate will excel in sourcing and converting top talent, while maintaining...CommercialRemote jobFull time- ASSYST a CMMI Level 3 Company is seeking a Program Manager to lead the delivery of services under a specific program. The ideal candidate must have an active PMP certification and a proven track record in managing large-scale contracts. Responsibilities include overseeing...
$116.6k - $177.8k
...maintenance of the Information Technology (IT) Compliance Program.... ...customer's information security requirements. The... ...especially Microsoft Office applications. ~ Ability... ...to apply them to a business environment. ~... ...how they apply in the commercial environment; ~ ISO...CommercialTemporary workWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Security Consulting — Business Information Security Officer (BISO) Commercial IT. Be the first to apply!
- business opportunity manager Gaithersburg, MD
- business director Gaithersburg, MD
- director enterprise solutions Gaithersburg, MD
- new business executive Gaithersburg, MD
- director enterprise architecture Gaithersburg, MD
- business manager Gaithersburg, MD
- director of enterprise application services Gaithersburg, MD
- director business analysis Gaithersburg, MD
- director enterprise applications Gaithersburg, MD
- director of business systems Gaithersburg, MD




