BISO – Enterprise Technology Services (ETS)

AstraZenecaGaithersburg, MD
Hybrid

About The Position

The BISO will serve as the primary strategic cybersecurity partner to the IT Enterprise Technology Services (ETS) organization and its associated technology domains, representing the CISO by leading cybersecurity engagement, alignment, and delivery of cybersecurity risk and resilience outcomes across AstraZeneca’s foundational technology estate. ETS is the enterprise technology backbone of AstraZeneca – delivering sustainable and globally scaled enterprise technology services that enable the company’s scientific, manufacturing, and commercial activities. As AstraZeneca’s global technology operations organization, ETS focuses on the reliable delivery and operation of enterprise technology services, while cybersecurity and IT risk accountability is owned within the CISO Cybersecurity organization that this role represents. This customer-facing role is closely coupled with the ETS leadership team and operates as a dotted-line function to the VP-level leadership, supporting the cloud and infrastructure, network and connectivity, digital workplace, identity and access, service operations, and technology governance capabilities on which the enterprise depends.

Requirements

  • 10+ years of experience in information security positions, with 5+ years’ experience overseeing an information security function and influencing senior business and IT stakeholders.
  • Demonstrated experience supporting enterprise technology operations – cloud and on-premises infrastructure, networks, digital workplace, identity, and IT service management – with the ability to translate technical and operational priorities into effective cybersecurity controls and risk decisions.
  • Extensive experience with enterprise IT infrastructure security, including cloud platforms (IaaS, PaaS, SaaS), compute and storage, operating system hardening, infrastructure-as-code, and secure configuration across hybrid and multi-cloud environments (for example AWS and on-premises).
  • Understanding of enterprise network security principles, including segmentation and micro-segmentation, firewall governance, zero-trust network access, secure remote connectivity, DNS security, intrusion detection/prevention, proxy/internet connectivity, and secure integration with cloud providers and third-party networks.
  • Familiarity with endpoint detection and response, device and mobile device management, patch management, data loss prevention, encryption, and secure configuration across diverse user device estates, together with security of productivity and collaboration platforms such as Microsoft 365, Teams, SharePoint, and OneDrive.
  • Understanding of ITSM frameworks and processes (ITIL or equivalent) and how cybersecurity integrates with monitoring, incident management, change management, problem management, request fulfillment, and configuration management (including the CMDB, for example in ServiceNow) in enterprise environments.
  • Experience implementing and operationalizing controls defined by NIST CSF, CIS-18, ISO 27001/27002, and related cybersecurity control frameworks, and applying them pragmatically to infrastructure, network, workplace, identity, and operational ecosystems.
  • Experience managing vulnerability management and recurring hygiene efforts across cloud infrastructure, servers, network devices, endpoints, and identities; familiarity with penetration testing, infrastructure and application security testing, and risk-based remediation approaches.
  • Familiarity with risk dashboarding, data analysis, and leveraging actionable data to achieve risk reduction outcomes, including the ability to translate complex security telemetry into clear business and technology insight.
  • Understanding of global security operations and incident response processes, including scenarios such as cloud infrastructure breach, network intrusion, ransomware, endpoint compromise, identity and account takeover, and disruption to enterprise IT services.
  • Strong written and verbal communication skills, with proven ability to present complex technical information to both technical and non-technical audiences, including enterprise technology leadership, infrastructure and network leaders, service delivery managers, and governance bodies.
  • Proven ability to manage competing priorities and operate under time constraints tied to infrastructure changes, releases, service commitments, and enterprise delivery timelines, and drive outcomes through influence across matrixed teams.
  • Experience working collaboratively across IT, infrastructure, network, workplace, identity, service management, legal, and sourcing disciplines, and the ability to integrate cybersecurity considerations into multi-disciplinary decision-making.
  • Excellent problem-solving and troubleshooting skills, with a proven autonomous working style, clear direction-setting, and the ability to establish and pursue meaningful goals in ambiguous environments.
  • Bachelor's degree in science or relevant technical field of study; Master's preferred.

Nice To Haves

  • Prior experience in a regulated pharmaceutical, biotechnology, or life sciences environment, with understanding of GxP systems, regulatory expectations (e.g., FDA, EMA, MHRA), and the interplay between cybersecurity, data integrity, and patient safety as they relate to enterprise infrastructure and services.
  • Familiarity with designing or implementing zero-trust security models across enterprise environments, including identity-centric access controls, continuous verification, least-privilege enforcement, micro-segmentation, and context-aware policy engines spanning infrastructure, network, and workplace services.
  • Practical experience with cloud-native security tools such as cloud security posture management (CSPM), cloud workload protection platforms (CWPP), cloud infrastructure entitlement management (CIEM), and container security solutions across major cloud providers (AWS, Azure, GCP).
  • Experience leading or contributing to third-party cybersecurity risk assessments, vendor security governance programs, and supply chain risk frameworks covering both technology suppliers and managed service providers.
  • Demonstrated ability to develop and present meaningful cybersecurity metrics, risk dashboards, and executive-level reporting that drives informed decision-making and demonstrates return on security investment to business and technology leadership.
  • Demonstrated ability to apply automation, and where appropriate LLMs and agentic tooling, to improve cybersecurity and operational outcomes – for example faster risk triage, better control evidence, and improved detection and response – while protecting sensitive data.
  • Relevant industry certifications are valued, such as CISSP, CISM, CISA, CCSP, CRISC, SABSA, TOGAF (Security Architecture), AWS/Azure/GCP Security Specialty, or equivalent professional qualifications demonstrating breadth across security leadership, infrastructure, cloud, and risk management disciplines.
  • Experience contributing to or overseeing business continuity planning and disaster recovery strategies for critical IT infrastructure, enterprise services, and operational platforms, including tabletop exercises, recovery testing, and resilience architecture.

Responsibilities

  • Act as the primary strategic partner and security consultant to ETS leadership, driving alignment between enterprise technology priorities, operational service commitments, and the enterprise cybersecurity strategy.
  • Provide cybersecurity leadership across ETS cloud environments and on-premises infrastructure, including hosting, cloud subscriptions, compute, storage, and operating systems supporting both ETS platforms and applications owned by other business technology groups.
  • Drive cloud security posture management, infrastructure-as-code hardening, secure configuration baselines, workload protection, privileged access management for infrastructure, and consistent controls across AWS and on-premises platforms and Windows and Linux server estates.
  • Partner with network engineering teams to ensure robust network security architecture across AstraZeneca’s global networks, including segmentation and micro-segmentation, firewall governance, internet and proxy connectivity, DNS security, intrusion detection and prevention, traffic inspection, secure remote access, and secure integration with third-party networks, sites, data centres, and cloud service providers.
  • Guide the security of end-user devices, workplace engineering, and endpoint management, together with productivity and collaboration services such as Microsoft 365, Teams, SharePoint, OneDrive, Viva, and the Power Platform.
  • Ensure cybersecurity principles are embedded within ETS service operations, including monitoring, incident and problem management, patching, release coordination, change management, service continuity, and operational automation.
  • Embed cybersecurity into ETS technology governance disciplines, including the service catalogue and demand management, configuration data, technology standards, lifecycle management, supplier coordination, and operational performance reporting.
  • Carry out cyber risk assessments and make recommendations to ETS leadership on cybersecurity best practices, control improvements, and appropriate technology solutions.
  • Facilitate vulnerability management, audit and penetration test finding remediation, and implementation of cybersecurity control maturity improvements across the ETS technology estate.
  • Lead a practical approach to third-party cybersecurity risk for the ETS ecosystem of cloud providers, infrastructure and network vendors, managed service providers, and technology suppliers.
  • Create an ETS-focused risk dashboard and cybersecurity metrics that translate complex security data into clear, actionable insight for technology and service leaders.
  • Partner with enterprise security operations, infrastructure teams, network teams, and service management leaders to enhance readiness, playbooks, and crisis alignment for incidents that could affect enterprise infrastructure, connectivity, workplace services, identity, or IT service continuity.
  • Maintain significant knowledge of threats relevant to enterprise IT infrastructure and operations, including ransomware, cloud infrastructure breach, network intrusion, identity and credential compromise, endpoint compromise, email account takeover, supply chain compromise, and disruption to critical IT services.
  • Build trusted relationships with senior leaders across ETS and the broader IT and Cybersecurity communities, including infrastructure, network, workplace, identity, and service operations leaders, and represent ETS cybersecurity needs within enterprise governance bodies.

Benefits

  • qualified retirement program [401(k) plan]
  • paid vacation and holidays
  • paid leaves
  • health benefits including medical, prescription drug, dental, and vision coverage
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service