Executive Advisor -Business Information Security Officer

Elevance HealthAtlanta, IN
11hHybrid

About The Position

Executive Advisor - Business Information Security Officer Location: This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace. Alternate locations may be considered if candidates reside within a commuting distance from an office. Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law. The Executive Advisor - Business Information Security Officer serves as a dedicated security and risk management leadership function aligned to the major business and technology-enabling divisions of Elevance Health. BISOs are embedded security leaders – connecting executive business and innovation leaders, technology professionals, compliance management teams, and the Global Information Security organization. How You Will Make an Impact: Leads Information Security and Risk Management for an assigned Business Unit Leads Information Security and Technology Risk Management for an assigned Business Unit, ensuring alignment with enterprise security strategy, business objectives, and regulatory obligations. Serves as the primary business-facing point of contact for information security and technology risk matters, coordinating enterprise security capabilities and services as needed. Acts as a key leadership contact during incident response activities, ensuring effective business engagement, executive communication, and post-incident remediation. Owns the development and execution of the Business Unit security roadmap, aligned with enterprise priorities, business strategy, and defined risk tolerance. Identifies, prioritizes, and recommends opportunities to reduce risk and improve security outcomes through targeted assessments, continuous monitoring, and metrics-driven analysis. Participates in enterprise planning activities, including vendor and third-party risk assessment, technology platform selection and retirement, security architecture alignment, prioritization, and integration planning. Serves as the Information Security and Technology Risk lead for mergers, acquisitions, and divestitures, including due diligence, integration planning, and risk remediation. Establishes and participates in governance forums to assess, accept, mitigate, or escalate technology risk in alignment with enterprise risk management practices. Provides security leadership for healthcare regulatory and compliance requirements (e.g., HIPAA, HITRUST, state privacy laws), ensuring audit readiness and sustained compliance. Defines, tracks, and reports meaningful security and risk metrics to business and executive stakeholders to support informed decision-making. Acts as a trusted advisor and subject matter expert to executive management, translating technical and cyber risk into clear business and financial impact. Influences business and technology leaders to adopt secure-by-design practices and risk-aware decision-making without direct operational authority. Mentors and develops security and risk management capabilities within the Business Unit and across enterprise teams. Must be capable of providing top-tier support for 6 or more of the information security technology common body of knowledge skill sets: 1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) Security Architecture and Design, 11) Telecommunications and Network Security.

Requirements

  • Requires BS/BA in Information Technology or related field of study and a minimum of 10 years experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required; or any combination of education and experience, which would provide an equivalent background.

Nice To Haves

  • Broad-based experience to plan and design highly complex systems is strongly preferred.
  • Expert knowledge and understanding of industry-accepted data processing controls and concepts strongly preferred as applied to Security
  • Certifications: CISSP preferred and other advanced technical security certifications (e.g. Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Certification and Accreditation or equivalent certifications).

Responsibilities

  • Leads Information Security and Risk Management for an assigned Business Unit
  • Leads Information Security and Technology Risk Management for an assigned Business Unit, ensuring alignment with enterprise security strategy, business objectives, and regulatory obligations.
  • Serves as the primary business-facing point of contact for information security and technology risk matters, coordinating enterprise security capabilities and services as needed.
  • Acts as a key leadership contact during incident response activities, ensuring effective business engagement, executive communication, and post-incident remediation.
  • Owns the development and execution of the Business Unit security roadmap, aligned with enterprise priorities, business strategy, and defined risk tolerance.
  • Identifies, prioritizes, and recommends opportunities to reduce risk and improve security outcomes through targeted assessments, continuous monitoring, and metrics-driven analysis.
  • Participates in enterprise planning activities, including vendor and third-party risk assessment, technology platform selection and retirement, security architecture alignment, prioritization, and integration planning.
  • Serves as the Information Security and Technology Risk lead for mergers, acquisitions, and divestitures, including due diligence, integration planning, and risk remediation.
  • Establishes and participates in governance forums to assess, accept, mitigate, or escalate technology risk in alignment with enterprise risk management practices.
  • Provides security leadership for healthcare regulatory and compliance requirements (e.g., HIPAA, HITRUST, state privacy laws), ensuring audit readiness and sustained compliance.
  • Defines, tracks, and reports meaningful security and risk metrics to business and executive stakeholders to support informed decision-making.
  • Acts as a trusted advisor and subject matter expert to executive management, translating technical and cyber risk into clear business and financial impact.
  • Influences business and technology leaders to adopt secure-by-design practices and risk-aware decision-making without direct operational authority.
  • Mentors and develops security and risk management capabilities within the Business Unit and across enterprise teams.
  • Must be capable of providing top-tier support for 6 or more of the information security technology common body of knowledge skill sets: 1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) Security Architecture and Design, 11) Telecommunications and Network Security.

Benefits

  • We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Executive

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service