CareerPlanSign in

BISO - Commercial IT

US - Gaithersburg - MD💼 Full-time🗓 2026-08-26 → 2026-09-29

Core

Act as the main cybersecurity partner to Commercial IT and business areas, representing the CISO to lower cyber risk and improve resilience across SaaS-heavy, data-centric platforms dedicated to clients and revenue generation.

Role type

Senior IC Business Information Security Officer (BISO)

Builds

Secure configurations, governance frameworks, risk roadmaps, and incident response playbooks for Commercial IT ecosystems.

Domain

Life Sciences / Commercial IT / SaaS Security

Required skills

Information security leadership, SaaS/CRM security (Veeva, Salesforce), Digital experience and marketing technology security, Data platform and cloud security, Integration and API security, Commercial operations and revenue process awareness, Vulnerability and security testing management, Risk dashboarding, Incident response collaboration

Preferred skills

Master's degree in science or relevant technical field

Technologies

Veeva CRM, Veeva Vault, Veeva OCE, Salesforce, Adobe Experience Manager, Adobe Analytics, Adobe Target, Tealium, Databricks, AWS, MuleSoft, SnapLogic, Model N, Power BI

Responsibilities

Lead governance and risk-based decision-making by chairing key forums and translating enterprise security policy into Commercial-ready standards. Establish SaaS security governance by defining secure configuration baselines, environment management, and identity patterns for core platforms. Strengthen digital channel security by partnering with digital teams to embed secure SDLC practices and mitigate web-layer risks. Drive security controls aligned with privacy in marketing and data collection, ensuring compliance with GDPR and other global rules. Improve control maturity for commercial content, records, and revenue interfaces, including SOX-relevant controls. Run vulnerability, audit, and testing remediation to closure across SaaS tenants and web properties. Enhance incident readiness and response coordination by building Commercial-relevant playbooks and supporting post-incident reviews. Advance third-party and agency risk management by defining onboarding patterns and ongoing monitoring for vendors. Measure and communicate outcomes through KPIs, OKRs, and dashboards demonstrating risk ownership and resilience improvements. Lead and develop the BISO team by directing risk reporting, remediation, and consulting functions.

Seniority

Senior, hands-on IC with team leadership

Sourced via workday · Listed on CareerPlan, which tracks 853,000+ jobs from 20+ sources.