An application made for this job — a tailored resume and cover letter that speak straight to the posting.
AstraZeneca's ETS seeks a BISO to be the principal cybersecurity partner, aligning security outcomes with enterprise technology strategy across cloud, on‑premises, networks, and the digital workplace. The role chairs governance, drives risk-based decisions, and leads security across cloud infrastructure, identity, service operations, and supplier ecosystems while shaping resilience and incident readiness.
You will collaborate with ETS leadership to embed security in delivery, monitor KPIs,
The BISO will serve as the primary strategic cybersecurity partner to the IT Enterprise Technology Services (ETS) organization and its associated technology domains, representing the CISO by leading cybersecurity engagement, alignment, and delivery of cybersecurity risk and resilience outcomes across AstraZeneca’s foundational technology estate.
ETS is the enterprise technology backbone of AstraZeneca – delivering sustainable and globally scaled enterprise technology services that enable the company’s scientific, manufacturing, and commercial activities. As AstraZeneca’s global technology operations organization, ETS focuses on the reliable delivery and operation of enterprise technology services, while cybersecurity and IT risk accountability is owned within the CISO Cybersecurity organization that this role represents.
This customer-facing role is closely coupled with the ETS leadership team and operates as a dotted-line function to the ETS VP-level leadership, supporting the cloud and infrastructure, network and connectivity, digital workplace, identity and access, service operations, and technology governance capabilities on which the enterprise depends.
Strategic partnership and governance: Act as the primary strategic partner and security consultant to ETS leadership, driving alignment between enterprise technology priorities, operational service commitments, and the enterprise cybersecurity strategy. Chair or participate in relevant governance forums, ensuring risk-based decision-making, clear accountability, and visibility of cybersecurity outcomes across cloud, infrastructure, network, workplace, and service management portfolios.
Cloud and infrastructure security: Provide cybersecurity leadership across ETS cloud environments and on-premises infrastructure, including hosting, cloud subscriptions, compute, storage, and operating systems supporting both ETS platforms and applications owned by other business technology groups. Drive cloud security posture management, infrastructure-as-code hardening, secure configuration baselines, workload protection, privileged access management for infrastructure, and consistent controls across AWS and on-premises platforms and Windows and Linux server estates.
Network security and connectivity: Partner with network engineering teams to ensure robust network security architecture across AstraZeneca’s global networks, including segmentation and micro-segmentation, firewall governance, internet and proxy connectivity, DNS security, intrusion detection and prevention, traffic inspection, secure remote access, and secure integration with third‑party networks, sites, data centres, and cloud service providers. Advance network reliability and resilience objectives alongside security outcomes.
Digital workplace and Site IT security: Guide the security of end‑user devices, workplace engineering, and endpoint management, together with productivity and collaboration services such as Microsoft 365, Teams, SharePoint, OneDrive, Viva, and the Power Platform. Champion protection against phishing, business email compromise, malware delivery, data exfiltration, unauthorized sharing, and account compromise, and balance controls with employee technology experience so security enables rather than hinders workforce productivity across the global device estate and local technology support functions.
Service operations security: Ensure cybersecurity principles are embedded within ETS service operations, including monitoring, incident and problem management, patching, release coordination, change management, service continuity, and operational automation. Integrate security into ITSM processes and the CMDB, drive timely patching and vulnerability remediation, and ensure change and release practices preserve a strong, auditable security posture across the estate.
Technology governance and standards: Embed cybersecurity into ETS technology governance disciplines, including the service catalogue and demand management, configuration data, technology standards, lifecycle management, supplier coordination, and operational performance reporting. Ensure security requirements are built into technology standards, platform guardrails, reusable controls, and lifecycle and decommissioning processes, reducing risk from unsupported and end‑of‑life technology.
Risk management and assurance: Carry out cyber risk assessments and make recommendations to ETS leadership on cybersecurity best practices, control improvements, and appropriate technology solutions. Support security assessments, threat modelling, and design reviews for complex enterprise platforms, infrastructure services, and reusable capabilities. Partner with control owners to ensure security requirements are built into engineering standards, infrastructure baselines, and operational workflows.
Vulnerability management and continuous improvement: Facilitate vulnerability management, audit and penetration test finding remediation, and implementation of cybersecurity control maturity improvements across the ETS technology estate. Deliver ETS leadership actionable information regarding identity, service account, infrastructure, network, endpoint, and platform vulnerability management priorities. Identify and lead improvements in cyber processes, engagement models, and operational effectiveness; establish KPIs, OKRs, and feedback loops to measure and optimise outcomes.
Third‑party and supplier security: Lead a practical approach to third‑party cybersecurity risk for the ETS ecosystem of cloud providers, infrastructure and network vendors, managed service providers, and technology suppliers. Govern vendor security assessments, contractual controls, ongoing assurance, and secure integration patterns that enable reliable enterprise service delivery without compromising confidentiality, integrity, or availability.
Risk reporting and metrics: Create an ETS‑focused risk dashboard and cybersecurity metrics that translate complex security data into clear, actionable insight for technology and service leaders. Coordinate risk profile development and distribution to ETS stakeholder audiences, and use data to drive risk‑reduction outcomes and informed prioritisation across the estate.
Incident preparedness and response: Partner with enterprise security operations, infrastructure teams, network teams, and service management leaders to enhance readiness, playbooks, and crisis alignment for incidents that could affect enterprise infrastructure, connectivity, workplace services, identity, or IT service continuity. Support cybersecurity assessments and penetration tests, and contribute to post‑incident reviews and business‑centric improvements.
Threat awareness: Maintain significant knowledge of threats relevant to enterprise IT infrastructure and operations, including ransomware, cloud infrastructure breach, network intrusion, identity and credential compromise, endpoint compromise, email account takeover, supply‑chain compromise, and disruption to critical IT services. Routinely share insights and practical implications with stakeholders.
Stakeholder management: Build trusted relationships with senior leaders across ETS and the broader IT and Cybersecurity communities, including infrastructure, network, workplace, identity, and service operations leaders, and represent ETS cybersecurity needs within enterprise governance bodies.
When we put unexpected teams in the same room, we unleash bold thinking with the power to encourage life‑changing medicines. In‑person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.
The annual base pay for this position ranges from $190,956.80 - $286,435.20 USD Annual. Hourly and salaried non‑exempt employees will also be paid overtime pay when working qualifying overtime hours. Base pay offered may vary depending on multiple individualized factors, including market location, job‑related knowledge, skills, and experience. In addition, our positions offer a short‑term incentive bonus opportunity; eligibility to participate in our equity‑based long‑term incentive program (salaried roles), to receive a retirement contribution (hourly roles), and commission payment eligibility (sales roles). Benefits offered included a qualified retirement program [401(k) plan]; paid vacation and holidays; paid leaves; and, health benefits including medical, prescription drug, dental, and vision coverage in accordance with the terms and conditions of the applicable plans. Additional details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an at‑will position and the Company reserves the right to modify base pay (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.
27-Aug-2026
17-Sept-2026
Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.