Elsevier logo

Elsevier

Vice President, Business Information Security Office (BISO) & Security Risk

🇺🇸 Alpharetta, Georgia 🕑 Full-Time 💰 TBD 💻 Cybersecurity 🗓️ September 14th, 2026
Cyber Security IT Security

Edtech.com's Summary

Elsevier is hiring a Vice President, Business Information Security Office (BISO) & Security Risk to lead the enterprise BISO function and own cyber security risk management for the organization. The role builds and leads a team of BISOs supporting business units company-wide, while personally serving as the senior security partner for one assigned business unit. It connects business-aligned security partnership with rigorous identification, assessment, and treatment of cyber and technology risk.

Highlights
  • Builds, leads, and develops a team of BISOs and cyber risk professionals, owning hiring, coaching, performance management, and career development
  • Defines and evolves the BISO and cyber risk operating model, engagement standards, and coverage allocation
  • Serves as the senior security partner and accountable BISO for an assigned business unit, building trusted relationships with business unit presidents, product leaders, and technology executives
  • Owns the cyber and technology risk management framework, risk taxonomy, and risk appetite and tolerance thresholds
  • Oversees security assessments across the portfolio, including vulnerability scanning, penetration testing, and third-party security risk assessments
  • Drives remediation and risk treatment to closure, escalating blocked or out-of-appetite issues to executive leadership
  • Provides clear, consistent reporting to executive leadership and risk forums through QBRs
  • Requires 15+ years of IT security and/or cyber risk experience, including 8+ years of management/leadership experience
  • Calls for at least one relevant certification, such as CISSP, CISM, CRISC, SANS/GIAC, or an ethical-hacking/penetration-testing credential
  • Based in Alpharetta, GA

Vice President, Business Information Security Office (BISO) & Security Risk Full Description

About the Role
Elsevier is hiring a Vice President, Business Information Security Office (BISO) & Security Risk to lead the enterprise BISO function and own cyber security risk management for the organization. You'll build and lead a team of BISOs supporting business units across the company, while personally serving as the senior security partner for your assigned business unit, connecting business-aligned security partnership with rigorous identification, assessment, and treatment of cyber and technology risk.
What You'll Do
  • Build, lead, and develop a team of BISOs and cyber risk professionals across the organization, owning hiring, coaching, performance management, and career development
  • Define and evolve the BISO and cyber risk operating model, engagement standards, and coverage allocation
  • Serve as the senior security partner and accountable BISO for your assigned business unit, building trusted relationships with business unit presidents, product leaders, and technology executives
  • Own the cyber and technology risk management framework, risk taxonomy, and risk appetite and tolerance thresholds
  • Oversee the portfolio's security assessments, including vulnerability scanning, penetration testing, and third-party security risk assessments
  • Drive remediation and risk treatment to closure, escalating blocked or out-of-appetite issues to executive leadership
  • Provide clear, consistent reporting to executive leadership and risk forums through QBRs
What You'll Need
  • Extensive experience in a Business Information Security Officer (BISO) role, security leadership, or a comparable senior security role
  • Proven experience building, leading, and developing teams of security and risk professionals across multiple business units
  • Demonstrated experience owning a cyber security risk management function, including risk frameworks and treatment
  • Working knowledge of cloud security (AWS, Azure, GCP), application security, SIEM, SOAR, EDR/XDR, and vulnerability scanning tools
  • 15+ years of IT security and/or cyber risk experience, including 8+ years of management/leadership experience
  • Bachelor's degree in Engineering, Computer Science, or equivalent experience; advanced degree preferred
  • At least one relevant certification required: CISSP, CISM, CRISC, SANS/GIAC, ethical hacking/penetration tester, or security risk assessment certification