Pay Rate $90 - $100
Location: Chicago, IL
Duration: 12 months
Business Information Security Officer (BISO)
Role Descriptions:
As a Research area Business Information Security Officer (BISO), you secure the organization''s scientific research assets through effective alignment of cybersecurity strategies with research goals. By embodying the crucial connection between research departments and the cybersecurity function, the BISO uplifts the organization''s security stance through knowledgeable risk management, astute incident response, and inclusive compliance efforts. Utilizing your expertise in project management, data risk assessment, and leadership, you foster a strong security culture, driving scientific innovation securely, minimizing potential cyber threats, thus positioning cybersecurity as a strategic enabler of scientific success and competitive advantage. | Major Responsibilities: In your role, you will be responsible for:
Strategic Alignment & Risk Management
- Develop and execute cybersecurity strategies aligning with scientific research objectives and regulatory measures.
- Identify, appraise, and reduce information security risks across research departments, using risk management best practices for scientific data.
- Collaborate in the establishment of ISRM, data protection, and privacy norms across the organization. Monitor security procedures effectively, offering guidance in accordance with ISRM policies.
Leadership & Collaboration
- Act as information security liaison between research groups, the CISO, and the Information Security and Risk Management (ISRM) teams.
- Establish and lead a BISO Advisory group, promoting collaboration among IT, legal, and risk management teams in a scientific research context.
- Define, generate, and present crucial risk KPI's to business leaders.
- Act as a cyber security subject matter expert (SME), coordinating and providing multidisciplinary know-how in security architecture and security management.
- Collaborate with IT teams to formulate mitigations for system security threats and risks.
- Provide consulting services on current and upcoming projects, covering all layers of IT security architecture.
Incident Response & Crisis Management
- Manage incident response efforts, assuring timely detection, classification, and resolution of security incidents in research units.
- Execute post-incident reviews and comprehensive tabletop exercises to improve preparedness.
Compliance & Governance
- Ensure research compliance with regulatory measures such as GDPR, HIPAA, CCPA, and adherence to standards like ISO 27001; applicable to scientific data.
- Familiarize with annua audit scoping efforts, coordinating with BTO Compliance teams to identify security activities targeted for review.
Training & Awareness
o Design and provide security awareness programs, underlining the importance of cybersecurity in scientific research.
o Develop a cybersecurity-conscious culture throughout the scientific research community within the organization. |
Qualifications: Required
- Bachelor's Degree and minimum 10 years of experience in Information Security, Cybersecurity, or a related field; or master's degree and 9 years of experience; or PhD and 5 years of experience.
- Prior, significant experience as a senior information security executive within a scientific research or similar environment.
- Consultative experience in advising executive & key stakeholders on security issues in the context of scientific research data. (References!)
- Experience in designing and implementing global security solutions tailored to scientific data.
- Experience in global organizations, in various geographic regions and understanding requirements in those countries (e.g., China (CSL, PIPL), Brazil, UK (GDPR), etc.)
- Thorough understanding of information security management frameworks (ISO 27001, NIST CSF) and regulatory compliance relevant to scientific data.
- Proven communication skills with a diverse stakeholder range, both technical teams and executives.
- Strong project management, data analytics, problem-solving, and leadership skills.
- Holds the CISSP, CISM, CRISC, CISA certifications, or at least two of these credentials.
Beneficial
- Advanced degree in a related field.
- Experience in contract and vendor negotiations in a scientific research context.
- Expertise in cybersecurity risk management, performing assessments and recommending solutions for scientific research programs & data.
- Previous experience as a Chief Information Security Officer (CISO) within a medium or large scientific research entity.
Key Stakeholders (optional):
- Chief Information Security Officer (CISO):
- BISO Program Office Lead
- Business/Research Technology Organization Unit Leaders:
- Information Security and Risk Management (ISRM) Teams:
- Innovation, Architecture & Infrastructure Technology Teams:
- Compliance, Legal & Privacy Teams:
- Human Resources (HR):
- Vendors and Third-Party Partners:
- Audit and Internal Controls Teams:
- Corporate Communications:
Skills: Cyber Security~BFS : Risk Management~Cyber Security - Information Security
Experience Required: 10 & Above
Diverse Lynx LLC is an Equal Employment Opportunity employer. All qualified applicants will receive due consideration for employment without any discrimination. All applicants will be evaluated solely on the basis of their ability, competence and their proven capability to perform the functions outlined in the corresponding role. We promote and support a diverse workforce across all levels in the company.