Business Information Security Officer
Quick Overview
Job Description
Job Title: Business Information Security Officer
Location: Chicago, Illinois (On-Site)
Job Description:
As a Research area Business Information Security Officer (BISO), you secure the organization's scientific research assets by aligning cybersecurity strategies with research goals. The BISO strengthens the security posture through comprehensive risk management, incident response, and compliance efforts, fostering a culture that enables scientific innovation while minimizing cyber threats.
Major Responsibilities
Strategic Alignment & Risk Management
- Develop and execute cybersecurity strategies that support scientific research objectives and regulatory requirements.
- Identify, evaluate, and reduce information-security risks across research departments using risk-management best practices.
- Help establish information-security, data-protection, and privacy standards and monitor adherence to ISRM policies.
Leadership & Collaboration
- Serve as the security liaison between research groups, the CISO, and ISRM teams.
- Form and lead a BISO Advisory Group to drive collaboration among IT, legal, and risk-management functions.
- Define, generate, and present key risk KPI s to business leaders.
- Act as a security subject-matter expert, providing guidance on security architecture and management.
- Partner with IT teams to recommend and implement mitigations for system security threats.
Incident Response & Crisis Management
- Oversee incident-response activities to ensure timely detection, classification, and resolution of security events.
- Conduct post-incident reviews and tabletop exercises to improve preparedness.
Compliance & Governance
- Ensure research compliance with GDPR, HIPAA, CCPA, ISO 27001 and other relevant regulations and standards.
- Coordinate annual audit scoping with Compliance teams to identify security activities for review.
Training & Awareness
- Design and deliver security-awareness programs tailored to the scientific research community.
- Promote a cybersecurity-conscious culture throughout the organization.
Qualifications Required
- Bachelor s degree and minimum 10 years of experience in information security/cybersecurity; or master s degree and 9 years; or PhD and 5 years.
- Senior-level information-security leadership experience in a scientific research environment.
- Experience advising executives on security issues related to scientific research data.
- Proven ability to design and implement global security solutions for scientific data.
- Deep knowledge of ISO 27001, NIST CSF, and global privacy regulations (e.g., GDPR).
- Strong communication, project-management, data-analytics, problem-solving, and leadership skills.
- At least two of the following certifications: CISSP, CISM, CRISC, CISA.
Beneficial
- Advanced degree in a related field.
- Experience with contract and vendor negotiations in a research context.
- Expertise in cybersecurity risk management for scientific programs and data.
- Previous experience as a CISO within a medium or large research organization.
Similar jobs
Lab Clerk
UnitedHealth Group · Snohomish, United States
14 minutes ago$16 - $29/hrLab Clerk
UnitedHealth Group · Lake Stevens, United States
14 minutes ago$16 - $29/hrHealthcare Admin Assistant
Innosoul inc · Indianapolis, United States
26 minutes agoLead Architect - Network Security
Iberdrola · Orange, United States
31 minutes ago$128.3k - $160.4k/yrNetwork Engineering, Advisor with Security Clearance
Peraton · Landover, United States
37 minutes ago$135k - $216k/yrPrincipal Cloud Platform Architect with Security Clearance
Leidos · Gaithersburg, United States
44 minutes ago$131.3k - $237.3k/yr