Vice President, Business Information Security Office (BISO) & Security Risk
Elsevier
Vice President, Business Information Security Office (BISO) & Cyber Security RiskAbout Our TeamThe Business Information Security Office (BISO) team partners closely with business, product, and technology leaders to deliver measurable security outcomes that directly support enterprise objectives. We focus on managing complex and critical risk, embedding secure-by-design practices, and driving long-term cybersecurity maturity across the organization. This role also carries a dedicated cyber security risk management mandate, connecting business-aligned security partnership with rigorous identification, assessment, and treatment of cyber and technology risk. Our work enables trusted innovation, operational resilience, and informed risk decision-making at scale.About the RoleAs Vice President, Business Information Security & Cyber Security Risk, you lead the enterprise BISO function and own cyber security risk management for the organization, while personally serving as the senior security partner for your assigned business unit. You carry a dual mandate: you build, lead, and develop a team of BISOs supporting business units across the organization, and you act as the accountable BISO for your assigned business unit, modeling the standard of partnership, judgment, and delivery you expect from the team.Reporting into the Elsevier Information Security organization, you set the vision, operating model, and priorities for how security partners with the business at scale, and you own cyber security risk management, including risk identification, assessment, treatment, and acceptance, as a distinct, standing capability. You are accountable for the consistency, quality, and measurable risk outcomes of BISO coverage across all supported business units, and for a clear, well-understood cyber risk posture reported to executive and business leadership.Key ResponsibilitiesTeam Leadership & Function Strategy· Build, lead, and develop a team of BISOs and cyber risk professionals supporting business units across the organization, owning hiring, coaching, performance management, and career development, and setting clear standards of performance.· Define and evolve the BISO and cyber risk operating model, engagement standards, and coverage allocation, deploying resources across business units based on risk, business criticality, and strategic priorities.· Establish consistent methods, playbooks, and reusable artifacts so partnership, risk assessment, and reporting meet a common quality bar; manage the function's budget, headcount, and vendor relationships.· Serve as the senior escalation point on complex or high-severity risk decisions, providing executive judgment and air cover for the team.Executive Business Partnership & Program Governance· Serve as the senior security partner and accountable BISO for your assigned business unit, building trusted relationships with business unit presidents, product leaders, and technology executives.· Embed security early in strategy, planning, product development, and delivery for your business unit, and ensure the team does the same across their business units.· Sponsor and govern the portfolio of enterprise and business-aligned security initiatives, ensuring requirements are integrated into major technology programs and removing organizational blockers.· Represent the aggregated risk posture of your portfolio to executive leadership, balancing risk management with business objectives and delivery speed.Security Assurance & Cyber Risk Management· Own the cyber and technology risk management framework, risk taxonomy, and risk appetite and tolerance thresholds, aligned to enterprise risk management.· Oversee the portfolio's security assessments, including vulnerability scanning, penetration testing, application and infrastructure reviews, and third-party security risk assessments.· Ensure risks and findings across applications, infrastructure, cloud, data, and third parties are identified, assessed, prioritized, and documented in accurate risk registers, with visibility maintained through risk reviews and dashboards.· Translate assessments, threat modeling, and control gap analyses into prioritized, business-aligned remediation and risk treatment plans with accountable owners.· Drive remediation and risk treatment to closure, escalating blocked, overdue, or out-of-appetite issues to executive leadership, and ensure compensating controls are documented where treatment is deferred.· Facilitate formal risk acceptance, exception, and escalation processes with appropriate business ownership and executive oversight.Technical Security· Application & Product Security: secure SDLC, threat modeling, API security, and remediation of application vulnerabilities across the business unit's products and services.· Cloud & Infrastructure Security: secure configuration, hardening, and posture management (CSPM) across cloud platforms (AWS, Azure, GCP) and supporting infrastructure.· Identity & Access Management: least-privilege access, strong authentication, authorization, and privileged access controls.· Data Protection: data classification, encryption, key management, and controls that safeguard sensitive and regulated data.· Vulnerability & Threat Management: vulnerability scanning, penetration testing, and prioritized remediation informed by threat intelligence.· Detection & Response: SIEM, EDR/XDR, logging, and telemetry that enable monitoring, detection, and incident response in partnership with the SOC and IR teams.· DevSecOps & Pipeline Security: automated security testing, secrets management, and dependency and container scanning embedded into CI/CD pipelines.Customer Security & Client Assurance· Ensure timely, accurate, and risk-appropriate responses to customer-facing security inquiries, including RFPs, RFIs, questionnaires, audits, and due-diligence requests, across supported business units.· Partner with Sales, Customer Support, Legal, Privacy, and Trust teams to enable revenue and customer trust, setting the standard for how the team supports client assurance.· Reduce ad-hoc requests through proactive enablement, reusable response artifacts, and alignment with enterprise Trust Center capabilities.Metrics, Reporting & Continuous Improvement· Define and own the security and risk scorecard and metrics reflecting risk posture, control effectiveness, and risk treatment progress.· Provide clear, consistent reporting to executive leadership and risk forums through QBRs, highlighting trends, risk concentrations, and measurable improvements over time.· Use data-driven insights to inform prioritization, resource allocation, and continuous improvement across the BISO and cyber risk functions.· Promote measurable improvements in security awareness and behaviors, particularly within high-risk user and technology populations.RequirementsLeadership & Experience· Extensive experience in a Business Information Security Officer (BISO) role, security leadership, or a comparable senior security role, including direct accountability for enterprise risk outcomes.· Proven experience building, leading, and developing teams of security and risk professionals, including distributed teams supporting multiple business units, with a track record of hiring, coaching, and retaining talent.· Demonstrated experience owning a cyber security risk management function, including risk frameworks, risk assessment methodologies, and risk treatment.· Demonstrated ability to define operating models, set strategy, and manage a function's budget, headcount, and priorities at scale.· Experience partnering with and influencing executive and business-unit leadership in complex, matrixed enterprise environments.Technical & Risk Expertise· Cloud & Application Security: Working knowledge of cloud security (e.g., AWS, Azure, GCP) and application security practices, including secure SDLC, threat modeling, API security, and remediation of application vulnerabilities.· Security Tooling & Telemetry: Familiarity with core security platforms such as SIEM, SOAR, EDR/XDR, CSPM, SAST/DAST, or vulnerability scanning tools, with the ability to interpret outputs and guide remediation with engineering teams.· Cyber Risk Management: Deep experience with enterprise cyber risk management, risk registers and taxonomies, risk appetite, risk assessment and treatment, and third-party risk.· Risk Management & Threat Modeling: Proven ability to oversee technical risk assessments, threat modeling, and control gap analyses, translating technical findings into business risk and prioritized remediation plans.· Security Operations & Incident Response: Experience partnering with SOC, IR, and engineering teams on security monitoring, vulnerability management, and incident response, including real-world breach or security event handling.· Regulatory, Privacy & Security Standards: Experience implementing and mapping controls to frameworks and regulations such as NIST CSF/800-53, ISO 27001, CIS Controls, PCI DSS, SOX, HIPAA, or GDPR within complex enterprise environments.Skills & Attributes· Proven ability to influence without authority and drive outcomes through collaboration at all levels of the organization.· Excellent executive communication skills, with the ability to translate complex security and risk concepts into business-relevant language for senior audiences.· Strong analytical and problem-solving skills, including leading teams to identify issues, evaluate options, and coordinate effective solutions.· Comfortable operating in complex, matrixed environments with competing priorities and stakeholders.Qualifications· 15+ years of IT Security and/or cyber risk experience· 8+ years of management/leadership experience, including managing security and/or risk teams· BS Engineering/Computer Science or equivalent experience required; advanced degree preferred· Licensing/certification required (at least one of the following): CISSP, CISM, CRISC, SANS, GIAC (or related), ethical hacking/penetration tester certification, and/or security risk assessment certification This job is eligible for an annual incentive bonus. We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact View phone number on click.appcast.io.Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.Please read our Candidate Privacy Policy.We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.USA Job Seekers:EEO Know Your Rights.SummaryLocation: Alpharetta, GAType: Full time
- ...and we move money and information in a way that moves the... ..., reliably, and securely. Any time you swipe your... ...Security Architecture and Risk, Sr AdvisorAbout your... ...standards that let the business adopt AI quickly and... ...this role as in-person office experiences help you with...Work at officeRiskFull timeTemporary workWork experience placementH1bMonday to Friday
$95k - $165k
...Stanley is seeking a Risk professional to join... ...Cyber, Technology and Information Security (CTIS) Standards team... ...or Baltimore at the Vice-President level. The CTIS Standards... ...0 employees in 1,200 offices across 42 countries.... ...to move about the business for those who show passion...RiskTemporary workLocal area- ...payments, and we move money and information in a way that moves the world... ...day - quickly, reliably, and securely. Any time you swipe your... ...strategies using structured risk-based approaches.Collaborate... ...part of this role as in-person office experience helps you with your...Work at officeRiskFull timeTemporary workH1bMonday to Friday
$109k - $182.4k
...and we move money and information in a way that moves the... ..., reliably, and securely. Any time you swipe your... ...identification, identity risk analysis, security automation... ...technical and business requirements into scalable... ...role as in-person office experiences help you with...Work at officeRiskFull timeTemporary workH1bMonday to Friday$127.5k - $204k
...and we move money and information in a way that moves the... ..., reliably, and securely. Any time you swipe your... ..., identity and access risk analysis, security operations... ...technical and business teams to translate cybersecurity... ...role as in-person office experiences help you...Work at officeRiskFull timeTemporary workH1bMonday to Friday- ...Vice President of Cyber Security About the Company Leading provider of decorative... ...'s corporate objectives, risk appetite, and digital... ...cybersecurity is an integral part of business decisions, operational... ...Manager Title Chief Information Officer Functions ~...Risk
- ...Description Job Description Vice President, Cyber Security Location: Roswell, GA... ...) Reporting to: Chief Information Officer (CIO) Role Overview... ...strategic partner to the CIO and business leadership, ensuring... ...define and execute a risk-based cybersecurity strategy...Risk
$78.03k - $101.44k
...alternative application process. Information Technology Security Lead Full Time 8810-Clerical Office Roswell, GA, US 26 days ago... ...artificial intelligence governance, risk and vulnerability management,... ..., and balance innovation and business value against security, privacy...Work at officeRiskFull timeContract workCasual workLocal areaRemote work- ...Defines AI content guardrails, risk, controls, compliance,... ...position, 3 days per week in the office and 2 days per week from home.... ...Partnerships:Legal, compliance, and security teams for regulatory... ...to balance risk reduction with business usabilityExcellent communication...Work at officeRiskWorldwide2 days per week3 days per week
- ...hiring for a Director Risk Management to join... ...insurance management, security programs, and crisis response... ...crisis management, business continuity, and... ...~20% hybrid corporate office environment with periodic... ...sites. Additional Information Taking Care of our...Work at officeRiskWork experience placement
- ...facilities.The Senior Vice President (SVP) of Accounting is... ...investments to develop a business, product, technology,... ...of financial risk management and the ability... ...to work with sensitive information and maintain confidentialityKEY... ...REQUIREMENTSTypical office environment -...Work at officeRiskFull timeTemporary workFor contractorsWork experience placementLocum
- ...Clorox:The Sales Planning Business Manager serves as the... ...opportunities and risks across the business, developing... ...recommendations, securing cross-functional... ...individual will work in the office 3 days a week and... ...more.[U.S.]Additional Information:At Clorox, we champion...Work at officeRiskFull timeSummer workRemote workFlexible hours2 days per week3 days per week
- Job Title: Security Operations Center (SOC) Lead Location... ...to the Director of Information Security, the Security... ...outside standard business hours will be required... ...Demonstrated ability to manage risks effectively and enable... ...as well as the System Office. Our USG Statement of...Work at officeRiskFull timeTemporary workPart timeLocal area
$125k - $175k
...Strategy position at the Vice President level, which is... ...with long-term business objectives,... ...activities across the Office of the CISO. The Vice... ...initiatives, risks, metrics, and financial information into clear, actionable... ...risk, or information security concepts, with the...Work at officeRiskTemporary work$78k - $138k
...and we move money and information in a way that moves the... ..., reliably, and securely. Any time you swipe your... ...Fiserv.Job TitleManager Business Intelligence & AnalyticsAbout... ...to identify trends, risks, and opportunities.... ...role as in-person office experiences help you with...Work at officeRiskFull timeTemporary workH1bMonday to Friday- ...growing and expanding our business that is full of opportunity... ...Americans.Manager, Security PlatformsSecurity Office - Security Platforms | Alpharetta... ...technologies across Information Technology (IT) and Operational... ...performance, project status, risks, and resource needs while...Work at officeRiskFull timeLocal areaWeekday work
$75k - $100k
...Insurance is seeking a persuasive, high-energy Risk Placement Specialist/Marketing... ...You’ll Do Drive the Placement Process: Secure policy quotes through online rating systems... ...: In-person in our Alpharetta, GA office 2–3 days per week. What We Offer Comprehensive...Work at officeRiskWork from homeRelocation packageMonday to Friday2 days per week3 days per week- ...Business Risk AnalystIllumia is an industry leader in bringing the best integrated technology... ...position is hybrid if local to our office in Alpharetta, GA or Scottsdale, AZ.Alpharetta... ...Analyst to support the organization's information security compliance, GRC workflow, and risk...Work at officeRiskTemporary workLocal areaRemote workWorldwideFlexible hours
- ...30 PM. PNC is an in-office company that fosters a... ...for achieving desired business results. Acts as a point... ...transactions of varying risk and financial value in... ...able to leverage that information in creating customized... ...any registered role, the Secure and Fair Enforcement for...Work at officeRiskFull timeTemporary workPart timeWork experience placement
$40 per hour
...The Security Intern is an integral part of the Information Security team at Workiva. You will help solve... ...solutions within business constraints; good understanding... ...and not in a Workiva office Location: This internship... ...unifies finance, risk, and sustainability on a...Work at officeRiskRemote jobSummer workInternshipSummer internship- ...organized, warm, and missionally aligned Front Office Manager to support the daily operations,... ...across the organization. Monitor campus security camera feeds and respond appropriately to... ...exam for staff. Help organize and track risk‑management, safety, and compliance‑...Work at officeRiskFull timeTemporary workFor contractorsMonday to FridayFlexible hoursShift work
- ...performance across the commercial book of business. Accountable for building and scaling a... ...product mix, unit economics, concentration risk, and client profitability, ensuring... ...when you will be required to come into the office for meetings and team building activities...Work at officeRiskRemote work
$127.5k - $204k
...and we move money and information in a way that moves the... ..., reliably, and securely. Any time you swipe your... ...security domains and business functions.You will partner... ...architecture, engineering, risk, and business... ...this role as in-person office experiences help you with...Work at officeRiskFull timeTemporary workH1bMonday to Friday$152.7k - $294k
...build a better working world. The Global Information Security Strategist is a senior role responsible... ...assets and reputation but also enable business objectives. The strategist will combine... ...of evolving business demands and cyber risks. Key Responsibilities Strategic...RiskSummer holidayFlexible hoursShift work- ...1:30 PM PNC is an in-office company that fosters a... ...for achieving desired business results. Assists team members... ...of varying risk and financial value in... ...able to leverage that information in creating customized... ...any registered role, the Secure and Fair Enforcement for...Work at officeRiskFull timeTemporary workPart timeWork experience placement
$84k - $140k
...Re uses a hybrid work model requiring at least three days in the office each week. The position can be based near one of our Swiss Re... ..., IL. About the Role We are looking for an experienced Clinical Risk Manager to join our Accident & Health division. This role requires...Work at officeRiskTemporary work- ...payments, and we move money and information in a way that moves the world... ...day - quickly, reliably, and securely. Any time you swipe your... ...actionable intelligence, reduce risk at scale, and raise the bar... ...part of this role as in-person office experiences help you with...Work at officeRiskFull timeContract workTemporary workH1bMonday to Friday
- ...Entity Rokstone Construction Risk Underwriters LTD Location City Role Summary At Rokstone... ...to deliver profitable outcomes for the business. This role provides significant exposure... ...solving skills. Experience with Microsoft Office suite. Skills and Abilities Exceptional analytical...Work at officeRisk
- ...per week from an HPE office.Who We Are:Hewlett Packard... ...of Hybrid Cloud business unit in advancing the... ...may also be offered."Information about employee benefits... ...account details, Social Security numbers, or national IDs... ...the individual’s own risk, and HPE disclaims legal...Work at officeRiskFull timeWork experience placementLocal areaImmediate start2 days per week
- ...sustainable future. For more information, please visit... ...Description:ABOUT THE POSITIONThe Vice President, Program Management Office (PMO) is responsible for... ...execution across the Product Business Unit. Reporting to the... ...adherence, technical risks, and program dependencies...Work at officeRiskFull timeVisa sponsorshipWork visa
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vice President, Business Information Security Office (BISO) & Security Risk. Be the first to apply!
- vice president of digital marketing Alpharetta, GA
- vice president logistics Alpharetta, GA
- vice president security Alpharetta, GA
- vp infrastructure Alpharetta, GA
- vp support Alpharetta, GA
- vp safety Alpharetta, GA
- vice president finance Alpharetta, GA
- vice president innovation Alpharetta, GA
- vice president project management Alpharetta, GA
- vice president communications Alpharetta, GA



