AstraZeneca

BISO - Enabling Units IT Security

AstraZeneca$190K — $286K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in information security, including 5+ years in a leadership role influencing senior stakeholders.
  • Experience in securing enterprise applications and SaaS platforms, translating business needs into cybersecurity controls.
  • Strong understanding of financial controls and compliance regulations (SOX, GDPR, etc.).
  • Proven skills in designing cloud-native security patterns for SaaS applications.
  • Hands-on experience with identity and access management, data protection, and vendor risk management.
  • Familiar with enterprise security frameworks like NIST CSF and ISO 27001/27002.
  • Demonstrated ability to apply emerging technologies for cybersecurity improvements.

Responsibilities

  • Serve as the primary strategic cybersecurity partner for Enabling Units IT leadership.
  • Lead risk posture and architecture engagement for enterprise SaaS and cloud environments.
  • Manage security and risk for applications such as Workday, SAP, Coupa, and Concur.
  • Ensure compliance with financial and data privacy regulations during security controls implementation.
  • Drive improvements in security for enterprise applications and cloud services with necessary documentation and governance.
  • Create risk dashboards and KPIs to measure security posture and risk reduction across platforms.
  • Develop security consulting strategies for critical enterprise integrations involving cross-functional data flows.

Benefits

  • 401(k) retirement program with company contributions.
  • Paid vacation and holidays along with paid leaves.
  • Comprehensive health benefits including medical, dental, and vision coverage.
  • Eligibility for short-term incentive bonuses and participation in equity programs.
  • Professional development support and a collaborative work environment.
Full Job Description

The BISO Enabling Units IT Security serves as the Information Security Officer for the Enabling Units IT organization. This position reports to the AstraZeneca Global Head of Cybersecurity Business Operations. The BISO delivers risk management and security expertise to educate, enable, and empower Enabling Units IT and business stakeholders to safeguard information, platforms, and business-critical systems.

The BISO team ensures information security is understood and embedded across enterprise business functions. The team leads security consultants and risk analysts responsible for embedding the security policy framework, industry-standard controls, and secure-by-design initiatives into enterprise SaaS platforms, cloud services, and applications supporting Finance, HR, Global Corporate Affairs, Global Business Services, Legal, and M&A functions.

The BISO, is the primary strategic cybersecurity partner to Enabling Units IT, covering enterprise business functions including Finance, HR, Global Corporate Affairs, Global Business Services, Legal, and Mergers & Acquisitions. This customer-facing role represents the CISO by leading cybersecurity engagement, alignment, and delivery of cybersecurity risk and resilience outcomes across enterprise business applications and services.

The role provides strategic guidance on cybersecurity risks, priorities, and long-term security posture across enterprise SaaS platforms, cloud services, and applications such as Workday, SAP, Coupa, and Concur. A central focus is balancing business enablement with compliance, data protection, identity governance, vendor assurance, and resilience needs across enterprise functions.

This leader directs cybersecurity consulting, risk management, remediation, posture reporting, and data analysis activities tailored to the enterprise SaaS and cloud platforms that underpin financial integrity, employee data protection, legal obligations, M&A activity, and critical business operations.

Accountabilities

  • Act as the primary strategic partner and security consultant to Enabling Units IT leadership, participating in governance forums that drive risk-based decisions, clear accountability, and visible security outcomes.

  • Lead risk posture and architecture engagement for enterprise SaaS and cloud environments, supporting cybersecurity architects in defining cloud-native security patterns that fit business application needs.

  • Lead security consulting and risk management for enterprise applications such as Workday, SAP, Coupa, and Concur, including identity and access management, data protection, integration security, privileged access governance, and vendor assurance.

  • Ensure security controls support financial controls, SOX compliance, data privacy obligations including GDPR, M&A due diligence requirements, and electronic records/signatures expectations where applicable.

  • Deliver change-controlled security improvements within enterprise applications and cloud services, including documentation expectations, governance alignment, and compensating controls where needed.

  • Drive comprehensive application visibility, security posture reporting, and risk-based vulnerability or exposure management across enterprise SaaS and cloud platforms with continuous update models.

  • Provide security consulting for critical enterprise integrations, including HR-to-Finance, procurement-to-payment, and other cross-functional data flows, ensuring secure patterns, identity controls, logging, and resilience.

  • Strengthen third-party risk management for SaaS providers, cloud platforms, business service providers, and professional services partners, including contractual controls, ongoing assurance, and secure support models.

  • Partner with security operations and business teams to create environment-specific incident response playbooks, tabletop exercises, and recovery readiness for business-critical enterprise applications.

  • Maintain audit-ready security evidence for financial controls, SOX compliance, data privacy audits, Legal and M&A due diligence, and other enterprise assurance needs.

  • Build enterprise-focused risk dashboards and KPIs covering SaaS security posture, identity governance maturity, critical exposure reduction, privileged access governance, vendor assurance, and recovery readiness.

  • Tailor cybersecurity culture and training for Finance, HR, Legal, Global Corporate Affairs, Global Business Services, M&A, and related business users, emphasizing role-appropriate security practices.

  • Coach a high-performing team with clear goals tied to measurable risk reduction, resilience improvement, and business enablement across Enabling Units IT.

Essential Skills & Experience Required

  • 10+ years of experience in information security positions, including 5+ years overseeing an information security function and influencing senior business and IT stakeholders.

  • Demonstrated experience securing enterprise business applications, SaaS platforms, and cloud services, with the ability to translate business realities into effective cybersecurity controls.

  • Strong familiarity with financial controls and SOX compliance, data privacy regulations including GDPR, electronic records/signatures regulations, and M&A due diligence requirements.

  • Proven ability to design and operationalize cloud-native security patterns for enterprise SaaS platforms and business applications.

  • Hands-on experience securing enterprise SaaS and cloud platforms, including identity and access management, data protection, integration security, privileged access governance, and vendor risk management.

  • Working knowledge of enterprise security frameworks such as NIST CSF, ISO 27001/27002, and CIS Controls, with the ability to apply appropriate controls across business application environments.

  • Experience running risk-based exposure management across enterprise SaaS and cloud platforms that operate under continuous update models.

  • Understanding of global incident response processes with experience adapting containment and recovery approaches to business continuity requirements such as financial close, payroll, procurement, legal workflows, and employee data protection.

  • Experience managing cyber risk across SaaS providers, cloud platforms, business service providers, and professional services partners, including enforceable minimum controls and ongoing assurance.

  • M&A security experience, including cybersecurity due diligence, integration security planning, and post-merger technology risk management, is highly desirable.

  • Demonstrated ability to apply emerging technologies, including AI and automation, to improve cybersecurity and business outcomes while protecting sensitive data and maintaining human oversight.

  • Strong written and verbal communication skills, with the ability to present complex technical information to finance executives, HR leadership, legal counsel, business service leaders, and global IT.

  • Proven ability to manage competing priorities and drive outcomes across enterprise functions with different risk profiles, regulatory obligations, and operational constraints.

  • Executive presence and influence, with the ability to build trusted relationships and guide risk-based decision-making across Enabling Units IT and business leadership.

  • Bachelor's degree in science or relevant technical field of study; Master's preferred. 

The annual base pay for this position ranges from $190,956.80 - $286,435.20USD Annual. Hourly and salaried non-exempt employees will also be paid overtime pay when working qualifying overtime hours. Base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition, our positions offer a short-term incentive bonus opportunity; eligibility to participate in our equity-based long-term incentive program (salaried roles), to receive a retirement contribution (hourly roles), and commission payment eligibility (sales roles). Benefits offered included a qualified retirement program [401(k) plan]; paid vacation and holidays; paid leaves; and, health benefits including medical, prescription drug, dental, and vision coverage in accordance with the terms and conditions of the applicable plans. Additional details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an at-will position and the Company reserves the right to modify base pay (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.

Date Posted

26-Aug-2026

Closing Date

10-Sept-2026

About AstraZeneca

AstraZeneca is a British-Swedish multinational pharmaceutical company that specializes in the research, development, and manufacturing of prescription drugs. The company was formed in 1999 through the merger of Astra AB and Zeneca Group plc. AstraZeneca's products are used to treat a wide range of medical conditions, including cancer, cardiovascular disease, respiratory disease, and diabetes. The company has operations in over 100 countries and employs more than 76,000 people worldwide. AstraZeneca is committed to developing innovative medicines that improve the health and well-being of people around the world.
Learn more about AstraZeneca
Size
83,100 employees
Market Cap
$211.5 billion
Industry
Net Income
$3.1 billion
Founded
1999
5 Year Trend
+10.2%
Revenue
$26.6 billion
NASDAQ

Similar Jobs

More Jobs at AstraZeneca

More Information Technology Jobs

Find similar BISO - Enabling Units IT Security jobs: