Business Information Security Officer - BISO | Supply Chain and Manufacturing

  • North Chicago, IL
  • Posted 7 days ago | Updated moments ago

Overview

Remote
On Site
USD 156,000.00 per year
Full Time

Skills

Supply Chain Management
Immunology
Neuroscience
Facebook
YouTube
LinkedIn
Management
Pivotal
Facilitation
Collaboration
Legal
Crisis Management
Incident Management
Swift
HIPAA
Auditing
Training
Security Awareness
Business Operations
Manufacturing
Information Security Management
ISO/IEC 27001:2005
Regulatory Compliance
Project Management
Data Analysis
Conflict Resolution
Problem Solving
Leadership
CISSP
CISM
ISACA
CISA
Negotiations
Cyber Security
Risk Management
Information Security
Insurance
Law
Innovation

Job Details

Company Description

AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas - immunology, oncology, neuroscience, and eye care - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at Follow @abbvie on X, Facebook, Instagram, YouTube, LinkedIn and Tik Tok.

Job Description

The Business Information Security Officer (BISO) serves as the senior information security partner within specific business units, responsible for aligning cybersecurity strategies with business goals, managing risks, and fostering a robust security culture across the organization. The BISO functions as a bridge between business IT initiatives and the cybersecurity team, providing expert guidance on security risks, compliance, and incident response.

The Business Information Security Officer (BISO) is instrumental in safeguarding the organization's assets by seamlessly aligning cybersecurity strategies with business objectives. Serving as a pivotal link between business units and the cybersecurity function, the BISO elevates the organization's security posture through expert risk management, proactive incident response, and comprehensive compliance efforts. By fostering a robust security culture, working collaboratively with diverse stakeholders, leveraging strong project management, data analytics, and leadership skills, the BISO drives business growth and innovation in a secure and resilient operational environment. This role ensures that cybersecurity is not merely a technical necessity but a strategic enabler of business success as well as competitive advantage.

Responsibilities
  • Strategic Alignment & Risk Management
    • Develop and execute cybersecurity strategies that align with business objectives and regulatory requirements.
    • Identify, assess, and mitigate information security risks across business units, utilizing risk management frameworks.
  • Leadership & Collaboration
    • Serve as the primary liaison between business units, the CISO, and the Information Security and Risk Management (ISRM) team.
    • Establish and lead a BISO Advisory capability, facilitating collaboration among IT, legal, and risk management representatives.
  • Incident Response & Crisis Management
    • Lead incident response efforts, ensuring swift detection, classification, and remediation of security incidents.
    • Conduct post-incident reviews and comprehensive tabletop exercises to enhance preparedness.
  • Compliance & Governance
    • Ensure compliance with regulatory requirements such as GDPR, HIPAA, CCPA, and alignment with standards like ISO 27001.
    • Lead audit preparation efforts, coordinating internal assessments and addressing gaps.
  • Training & Awareness
    • Design and deliver security awareness programs, emphasizing the importance of cybersecurity within business operations.
  • Cultivate a cybersecurity-conscious culture throughout all levels of the organization.

Qualifications
  • Bachelor's Degree and minimum 10 years of experience in Information Security, Cybersecurity, or a related field; or master's degree and 9 years of experience; or PhD and 5 years of experience.
  • Prior, demonstrable experience as a senior information security executive within a manufacturing environment.
  • Demonstration of experience in the consultative role of liaising and advising executive & key stakeholders on security matters. (References!)
  • Experience designing and implementing global security solutions.
  • Deep knowledge of information security management frameworks (ISO 27001, NIST CSF) and regulatory compliance requirements.
  • Proven ability to communicate effectively with a wide range of stakeholders, including executives and technical teams.
  • Strong project management, data analytics, problem-solving, and leadership skills.
  • Possession of CISSP, CISM, CRISC, CISA certifications, or at least two of these credentials.

Preferred:
  • Advanced degree in a related field.
  • Experience with contract and vendor negotiations.
  • Expertise in cybersecurity risk management, including conducting assessments and recommending solutions.
  • Prior experience as a Chief Information Security Officer (CISO) of a medium or large enterprise.

Additional Information

Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law:
  • The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future.
  • We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees.
  • This job is eligible to participate in our short-term incentive programs.
  • This job is eligible to participate in our long-term incentive programs

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole and absolute discretion unless and until paid and may be modified at the Company's sole and absolute discretion, consistent with applicable law.

AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled.

US & Puerto Rico only - to learn more, visit ;br>
US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more:

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.