BISO - Commercial IT
Core
Act as the main cybersecurity partner to Commercial IT and business areas, representing the CISO to lower cyber risk and improve resilience across SaaS-heavy, data-centric platforms dedicated to clients and revenue generation.
Role type
Senior IC Business Information Security Officer (BISO)
Builds
Secure configurations, governance frameworks, risk roadmaps, and incident response playbooks for Commercial IT ecosystems.
Domain
Life Sciences / Commercial IT / SaaS Security
Required skills
Information security leadership, SaaS/CRM security (Veeva, Salesforce), Digital experience and marketing technology security, Data platform and cloud security, Integration and API security, Commercial operations and revenue process awareness, Vulnerability and security testing management, Risk dashboarding, Incident response collaboration
Preferred skills
Master's degree in science or relevant technical field
Technologies
Veeva CRM, Veeva Vault, Veeva OCE, Salesforce, Adobe Experience Manager, Adobe Analytics, Adobe Target, Tealium, Databricks, AWS, MuleSoft, SnapLogic, Model N, Power BI
Responsibilities
Lead governance and risk-based decision-making by chairing key forums and translating enterprise security policy into Commercial-ready standards. Establish SaaS security governance by defining secure configuration baselines, environment management, and identity patterns for core platforms. Strengthen digital channel security by partnering with digital teams to embed secure SDLC practices and mitigate web-layer risks. Drive security controls aligned with privacy in marketing and data collection, ensuring compliance with GDPR and other global rules. Improve control maturity for commercial content, records, and revenue interfaces, including SOX-relevant controls. Run vulnerability, audit, and testing remediation to closure across SaaS tenants and web properties. Enhance incident readiness and response coordination by building Commercial-relevant playbooks and supporting post-incident reviews. Advance third-party and agency risk management by defining onboarding patterns and ongoing monitoring for vendors. Measure and communicate outcomes through KPIs, OKRs, and dashboards demonstrating risk ownership and resilience improvements. Lead and develop the BISO team by directing risk reporting, remediation, and consulting functions.
Seniority
Senior, hands-on IC with team leadership