Vice President, Business Information Security Office (BISO) & Cyber Security Risk
About Our Team
The Business Information Security Office (BISO) team partners closely with business, product, and technology leaders to deliver measurable security outcomes that directly support enterprise objectives. We focus on managing complex and critical risk, embedding secure-by-design practices, and driving long-term cybersecurity maturity across the organization. This role also carries a dedicated cyber security risk management mandate, connecting business-aligned security partnership with rigorous identification, assessment, and treatment of cyber and technology risk. Our work enables trusted innovation, operational resilience, and informed risk decision-making at scale.
About the Role
As Vice President, Business Information Security & Cyber Security Risk, you lead the enterprise BISO function and own cyber security risk management for the organization, while personally serving as the senior security partner for your assigned business unit. You carry a dual mandate: you build, lead, and develop a team of BISOs supporting business units across the organization, and you act as the accountable BISO for your assigned business unit, modeling the standard of partnership, judgment, and delivery you expect from the team.
Reporting into the Elsevier Information Security organization, you set the vision, operating model, and priorities for how security partners with the business at scale, and you own cyber security risk management, including risk identification, assessment, treatment, and acceptance, as a distinct, standing capability. You are accountable for the consistency, quality, and measurable risk outcomes of BISO coverage across all supported business units, and for a clear, well-understood cyber risk posture reported to executive and business leadership.
Key Responsibilities
Team Leadership & Function Strategy
· Build, lead, and develop a team of BISOs and cyber risk professionals supporting business units across the organization, owning hiring, coaching, performance management, and career development, and setting clear standards of performance.
· Define and evolve the BISO and cyber risk operating model, engagement standards, and coverage allocation, deploying resources across business units based on risk, business criticality, and strategic priorities.
· Establish consistent methods, playbooks, and reusable artifacts so partnership, risk assessment, and reporting meet a common quality bar; manage the function's budget, headcount, and vendor relationships.
· Serve as the senior escalation point on complex or high-severity risk decisions, providing executive judgment and air cover for the team.
Executive Business Partnership & Program Governance
· Serve as the senior security partner and accountable BISO for your assigned business unit, building trusted relationships with business unit presidents, product leaders, and technology executives.
· Embed security early in strategy, planning, product development, and delivery for your business unit, and ensure the team does the same across their business units.
· Sponsor and govern the portfolio of enterprise and business-aligned security initiatives, ensuring requirements are integrated into major technology programs and removing organizational blockers.
· Represent the aggregated risk posture of your portfolio to executive leadership, balancing risk management with business objectives and delivery speed.
Security Assurance & Cyber Risk Management
· Own the cyber and technology risk management framework, risk taxonomy, and risk appetite and tolerance thresholds, aligned to enterprise risk management.
· Oversee the portfolio's security assessments, including vulnerability scanning, penetration testing, application and infrastructure reviews, and third-party security risk assessments.
· Ensure risks and findings across applications, infrastructure, cloud, data, and third parties are identified, assessed, prioritized, and documented in accurate risk registers, with visibility maintained through risk reviews and dashboards.
· Translate assessments, threat modeling, and control gap analyses into prioritized, business-aligned remediation and risk treatment plans with accountable owners.
· Drive remediation and risk treatment to closure, escalating blocked, overdue, or out-of-appetite issues to executive leadership, and ensure compensating controls are documented where treatment is deferred.
· Facilitate formal risk acceptance, exception, and escalation processes with appropriate business ownership and executive oversight.
Technical Security
· Application & Product Security: secure SDLC, threat modeling, API security, and remediation of application vulnerabilities across the business unit's products and services.
· Cloud & Infrastructure Security: secure configuration, hardening, and posture management (CSPM) across cloud platforms (AWS, Azure, GCP) and supporting infrastructure.
· Identity & Access Management: least-privilege access, strong authentication, authorization, and privileged access controls.
· Data Protection: data classification, encryption, key management, and controls that safeguard sensitive and regulated data.
· Vulnerability & Threat Management: vulnerability scanning, penetration testing, and prioritized remediation informed by threat intelligence.
· Detection & Response: SIEM, EDR/XDR, logging, and telemetry that enable monitoring, detection, and incident response in partnership with the SOC and IR teams.
· DevSecOps & Pipeline Security: automated security testing, secrets management, and dependency and container scanning embedded into CI/CD pipelines.
Customer Security & Client Assurance
· Ensure timely, accurate, and risk-appropriate responses to customer-facing security inquiries, including RFPs, RFIs, questionnaires, audits, and due-diligence requests, across supported business units.
· Partner with Sales, Customer Support, Legal, Privacy, and Trust teams to enable revenue and customer trust, setting the standard for how the team supports client assurance.
· Reduce ad-hoc requests through proactive enablement, reusable response artifacts, and alignment with enterprise Trust Center capabilities.
Metrics, Reporting & Continuous Improvement
· Define and own the security and risk scorecard and metrics reflecting risk posture, control effectiveness, and risk treatment progress.
· Provide clear, consistent reporting to executive leadership and risk forums through QBRs, highlighting trends, risk concentrations, and measurable improvements over time.
· Use data-driven insights to inform prioritization, resource allocation, and continuous improvement across the BISO and cyber risk functions.
· Promote measurable improvements in security awareness and behaviors, particularly within high-risk user and technology populations.
Requirements
Leadership & Experience
· Extensive experience in a Business Information Security Officer (BISO) role, security leadership, or a comparable senior security role, including direct accountability for enterprise risk outcomes.
· Proven experience building, leading, and developing teams of security and risk professionals, including distributed teams supporting multiple business units, with a track record of hiring, coaching, and retaining talent.
· Demonstrated experience owning a cyber security risk management function, including risk frameworks, risk assessment methodologies, and risk treatment.
· Demonstrated ability to define operating models, set strategy, and manage a function's budget, headcount, and priorities at scale.
· Experience partnering with and influencing executive and business-unit leadership in complex, matrixed enterprise environments.
Technical & Risk Expertise
· Cloud & Application Security: Working knowledge of cloud security (e.g., AWS, Azure, GCP) and application security practices, including secure SDLC, threat modeling, API security, and remediation of application vulnerabilities.
· Security Tooling & Telemetry: Familiarity with core security platforms such as SIEM, SOAR, EDR/XDR, CSPM, SAST/DAST, or vulnerability scanning tools, with the ability to interpret outputs and guide remediation with engineering teams.
· Cyber Risk Management: Deep experience with enterprise cyber risk management, risk registers and taxonomies, risk appetite, risk assessment and treatment, and third-party risk.
· Risk Management & Threat Modeling: Proven ability to oversee technical risk assessments, threat modeling, and control gap analyses, translating technical findings into business risk and prioritized remediation plans.
· Security Operations & Incident Response: Experience partnering with SOC, IR, and engineering teams on security monitoring, vulnerability management, and incident response, including real-world breach or security event handling.
· Regulatory, Privacy & Security Standards: Experience implementing and mapping controls to frameworks and regulations such as NIST CSF/800-53, ISO 27001, CIS Controls, PCI DSS, SOX, HIPAA, or GDPR within complex enterprise environments.
Skills & Attributes
· Proven ability to influence without authority and drive outcomes through collaboration at all levels of the organization.
· Excellent executive communication skills, with the ability to translate complex security and risk concepts into business-relevant language for senior audiences.
· Strong analytical and problem-solving skills, including leading teams to identify issues, evaluate options, and coordinate effective solutions.
· Comfortable operating in complex, matrixed environments with competing priorities and stakeholders.
Qualifications
· 15+ years of IT Security and/or cyber risk experience
· 8+ years of management/leadership experience, including managing security and/or risk teams
· BS Engineering/Computer Science or equivalent experience required; advanced degree preferred
· Licensing/certification required (at least one of the following): CISSP, CISM, CRISC, SANS, GIAC (or related), ethical hacking/penetration tester certification, and/or security risk assessment certification
This job is eligible for an annual incentive bonus.
We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Clickhereto access benefits specific to your location.
We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1-855-833-5120.
Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scamshere.
Please read our Candidate Privacy Policy.
We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
USA Job Seekers:

