Role Overview:This role is for a Senior Research Business Information Security Officer (BISO) responsible for securing an organization's scientific research assets. The BISO aligns cybersecurity strategies with research goals, manages risks, responds to incidents, and ensures compliance. This position fosters a strong security culture, enabling secure scientific innovation and minimizing cyber threats by positioning cybersecurity as a strategic enabler of scientific success and competitive advantage.
Key Responsibilities:- Develop and execute cybersecurity strategies aligning with scientific research objectives and regulatory measures.
- Identify, appraise, and reduce information security risks across research departments, using risk management best practices for scientific data.
- Collaborate in the establishment of ISRM, data protection, and privacy norms; monitor security procedures effectively.
- Act as information security liaison between research groups, the CISO, and the Information Security and Risk Management (ISRM) teams.
- Establish and lead a BISO Advisory group, promoting collaboration among IT, legal, and risk management teams in a scientific research context.
- Define, generate, and present crucial risk KPI's to business leaders.
- Act as a cyber security subject matter expert (SME), coordinating and providing multidisciplinary know-how in security architecture and security management.
- Collaborate with IT teams to formulate mitigations for system security threats and risks.
- Provide consulting services on current and upcoming projects, covering all layers of IT security architecture.
- Manage incident response efforts, assuring timely detection, classification, and resolution of security incidents in research units.
- Execute post-incident reviews and comprehensive tabletop exercises to improve preparedness.
- Ensure research compliance with regulatory measures such as GDPR, HIPAA, CCPA, and adherence to standards like ISO 27001, applicable to scientific data.
- Familiarize with annual audit scoping efforts, coordinating with BTO Compliance teams to identify security activities targeted for review.
- Design and provide security awareness programs, underlining the importance of cybersecurity in scientific research.
- Develop a cybersecurity-conscious culture throughout the scientific research community within the organization.
Required Skills:- Prior, significant experience as a senior information security executive within a scientific research or similar environment.
- Consultative experience in advising executive & key stakeholders on security issues in the context of scientific research data.
- Experience in designing and implementing global security solutions tailored to scientific data.
- Experience in global organizations, in various geographic regions and understanding requirements in those countries (e.g., China (CSL, PIPL), Brazil, UK (GDPR), etc.).
- Thorough understanding of information security management frameworks (ISO 27001, NIST CSF) and regulatory compliance relevant to scientific data.
- Proven communication skills with a diverse stakeholder range, both technical teams and executives.
- Strong project management, data analytics, problem-solving, and leadership skills.
Qualifications:- Bachelor's Degree and minimum 10 years of experience in Information Security, Cybersecurity, or a related field; or master's degree and 9 years of experience; or PhD and 5 years of experience.
- Holds the CISSP, CISM, CRISC, CISA certifications, or at least two of these credentials.
Preferred Skills:- Advanced degree in a related field.
- Experience in contract and vendor negotiations in a scientific research context.
- Expertise in cybersecurity risk management, performing assessments and recommending solutions for scientific research programs & data.
- Previous experience as a Chief Information Security Officer (CISO) within a medium or large scientific research entity.
- Cyber Security Risk Management.
- Information Security.