Director, Cyber Risk Management & Remediation — Business Information Security Officer (BISO), E[...]
AstraZeneca GmbH
Introduction to role:
Are you ready to turn cyber risk into measurable outcomes that protect the platforms powering life‑changing medicines? Based in Guadalajara, this senior leader partners with Enterprise Technology Services to set the cyber risk posture across cloud, networks, identity, endpoints, collaboration, email/M365/Exchange, ITSM operations, service desk, and site IT. Your work will directly safeguard the digital foundation that enables our scientific and commercial breakthroughs for patients worldwide.
You will design the operating model that makes risk transparent and remediation predictable, engaging early on strategic initiatives, translating threats and regulatory drivers into clear priorities, and orchestrating durable control improvements. How would you establish a defensible control baseline and a credible risk narrative that influence VP‑level decisions and accelerate remediation at scale?
Accountabilities:
- Risk Lifecycle Ownership : Own the end‑to‑end risk lifecycle for ETS—identification, assessment, treatment, acceptance, and monitoring; maintain an authoritative risk register and a predictable reporting and escalation cadence to senior stakeholders.
- Executive Engagement and Influence : Advise business and technology leaders across ETS; convert threat intelligence, regulatory expectations, and operational realities into defensible priorities and investment decisions that drive measurable risk reduction.
- Governance and Risk Acceptance : Set and run governance for risk acceptance, exceptions, and waivers; ensure clear ownership, documented residual risk, time‑bound treatments, and escalations aligned to enterprise risk appetite.
- Control Baseline and Framework Mapping : Define and enforce a control baseline across ETS domains; map to NIST CSF, ISO 27001/27002, CIS Controls, and AstraZeneca policies; track control coverage and maturity over time.
- Risk Assessment and Treatment : Lead high‑impact risk assessments for transformative ETS initiatives—cloud migrations, identity modernization, endpoint refresh, collaboration and M365/Exchange evolution, ITSM uplift, and major third‑party/SaaS adoptions; ensure risks, exceptions, and treatments are consistently documented and tied to business outcomes and regulatory commitments.
- Remediation Program Leadership : Sponsor and oversee multi‑team remediation programs (e.g., vulnerability burndown, misconfiguration closure, identity hygiene, privileged access uplift, endpoint hardening, M365 tenant security, network segmentation, third‑party remediation); define milestones, RAID, benefits realization, and change management to land sustained risk reduction.
- Remediation Execution and Orchestration : Drive delivery across ETS service lines; manage dependencies and change controls with service owners; remove blockers and elevate proactively to keep remediation on track.
- Control Assurance and Audit Readiness : Oversee control health and testing for ETS; lead engagements with internal/external auditors and regulators across ISO 27001, SOC 2, SOX ITGC, and GxP/GMP where applicable; ensure evidence is durable, traceable, and audit‑ready.
- Third‑Party and Supply Chain Risk : Set the standard for supplier and SaaS risk management—onboarding patterns, minimum controls, clauses, due diligence, and continuous monitoring; integrate third‑party risks into the register and drive remediation, concentration‑risk management, or exit strategies as needed.
- Data, AI, and Privacy Enablement : Partner with data, AI, and privacy leaders to safeguard sensitive and regulated data on ETS platforms; enable compliant analytics and AI/ML through classification, encryption, DLP, monitoring, and model‑risk controls.
- Incident Preparedness and Response Leadership : Strengthen readiness with operations and crisis teams; align playbooks and BCP for ETS services; sponsor post‑incident corrective actions and embed lessons learned into updated baselines.
- Metrics, Reporting, and Executive Communication : Define KPIs and KRIs for ETS cyber risk (e.g., critical control coverage, assessment before go‑live, repeat‑finding rates, mean time to remediate, maturity trends); communicate posture, trends, and priorities to executives, governance bodies, and where required to Audit Committee and Board‑level forums.
- Stakeholder Management : Build trusted relationships with senior leaders across ETS, enterprise architecture, quality, legal/privacy, internal audit, sourcing, and cybersecurity; influence investment to resolve systemic risks and remove cross‑functional blockers.
Essential Skills/Experience:
- Information Security Leadership: 12–15 years of progressive experience in information security, including 8+ years leading risk management, remediation, BISO, or equivalent functions and influencing senior business and IT executives at VP/SVP level.
- Risk and Remediation Operating Model: Demonstrated track record of designing and operating an enterprise risk lifecycle (identification, assessment, treatment, acceptance, monitoring) and remediation portfolio in complex, global organizations, and measuring risk reduction and control maturity over time.
- AI‑Enabled Security: Demonstrated ability to apply LLMs and agentic automation to improve cybersecurity and business outcomes, translating use cases into measurable gains (for example faster risk triage, better control evidence, improved detection and response) while protecting sensitive data.
- Frameworks and Control Implementation: Deep experience implementing and operationalizing controls defined by NIST CSF, ISO 27001/27002, CIS Controls, and related frameworks across infrastructure, identity, endpoint, collaboration, and SaaS, demonstrating measurable maturity improvement at enterprise scale.
- Risk Dashboarding and Data‑Driven Execution: Proven ability to design and govern meaningful risk dashboards and metrics (for example in Power BI or equivalent), using actionable data to prioritize remediation, defend investment decisions, and demonstrate risk reduction and resilience improvements.
- Audit and Regulatory Engagement: Strong experience leading engagement with internal audit, external auditors, and regulators; track record of producing durable, traceable evidence and converting audit findings into structured remediation that closes on time.
- Incident Response and Crisis Partnership: Strong understanding of global security operations, incident response, and crisis management; experience as a senior risk and remediation partner during high‑severity events and post‑incident reviews, ensuring corrective actions translate into durable control change.
- Executive Communication: Exceptional written and verbal communication skills, with proven ability to present complex technical and risk information to executive, regulatory, and Board‑level audiences as well as in‑country and business stakeholders.
- Execution Under Pressure: Proven ability to manage competing executive‑level priorities, operate under time constraints tied to launches, regulatory commitments, and operational change windows, and drive outcomes through influence across a highly matrixed, global organization.
- Talent and Team Development: Demonstrated success building and retaining high‑performing risk and remediation teams, including senior practitioners, in a global, multicultural environment.
- Education and Certifications: Bachelor's degree in Information Security, Computer Science, Risk Management, or related field (master's degree strongly preferred). Professional certifications such as CISSP, CISM, or CRISC required.
Desirable Skills/Experience:
- Experience working in a global, matrix organization with distributed teams and significant operations in the US, UK, Sweden, China, Japan, India, and Latin America.
- Direct experience as a BISO, Head of Cyber Risk, or Head of Remediation in a regulated industry, with accountability for enterprise infrastructure and operations services.
- Hands‑on knowledge of emerging technologies and associated security risks (multi‑cloud, AI/ML and agentic systems, IoT/OT, quantum‑safe cryptography).
- Understanding of business continuity, disaster recovery, and crisis management at enterprise scale.
- Experience leading security input into M&A due diligence, integration, and divestitures.
- Track record of representing security at Audit Committee or Board‑level forums.
- Additional certifications such as CCSP, CGEIT, ISO 27001 Lead Auditor/Implementer, CISA, TOGAF, SABSA.
- Experience leading risk and remediation for major infrastructure, cloud, identity, endpoint, collaboration, and ITSM transformations.
We balance the expectation of being in the office while respecting individual flexibility. We require an average of three days per week from the office. We remain flexible to accommodate essential remote work.
Why AstraZeneca
Here, technologists and security leaders sit close to the science, enabling breakthroughs that reach patients faster and more safely. You will join a global company investing boldly in digital and data, where modern platforms, AI, and advanced analytics are used to solve high‑stakes problems and scale what works. We back ambition with support—clear priorities, real ownership, and leaders who value kindness alongside high performance—so your decisions translate into resilience for the enterprise and tangible impact for people who rely on our medicines.
AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry‑leading skills. We believe that the more inclusive we are, the better our work will be. We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics. We comply with all applicable laws and regulations on non‑discrimination in employment (and recruitment), as well as work authorization and employment eligibility verification requirements.
#J-18808-Ljbffr- ...The HR Business Partner provides... ...advisor to managers and... ..., mitigate risks and ensure... ...Lead and manage delivery of... ...incorporate risk management... ...the company security policy.... ...Microsoft Office (Excel, Word... ...essential e‑mail skills... ...disability, genetic information, veteran status...SugeridoTrabajar en la oficina
- ...We are hiring "Human Resources Business Partner" What you need?... ...organization. Availability to go to offices in Guadalajara Excellent... ...and Spanish. Able to manage high number of employees. Able... ...of legal standards and reduce risks related to daily management of...Sugerido
- ...and grow. Salesforce Business Systems Administrator... ...declarative development, security, and maintenance.... ...every feature request. Manage the integration and data... ...enterprise business systems (e.g., CRM, ERP, HRIS).... ..., execution, and risk management. We are...Sugerido
- ...Sales Operations Manager, LARC and has a strong... ...Management, the Business Operations Center... ...Provides historic sales information to sales team... ...and documents risk and opportunities... ...including Microsoft Office Suite, especially... ...SAP, Quoting tool (e.g. BMI), CRM e.g....SugeridoContratoTrabajar en la oficinaTurno de mañana
- ...ideas, las experiencias y la información estén disponibles en el... ...experiencia con módulos Oracle E‑Business Suite R12: ~ Oracle Accounts... ...Ledger ~ Oracle Cash Management Conocimiento práctico de... ...de negocio Job Systems/Information Technology Organization...SugeridoPráctica
$50,000
...Ops Project Manager III At Jabil... ...strategic business objectives.... ...project plans and risk analyses... ...all company security policies.... ...Assist regional directors and country... ...with MS Office, PowerPoint,... ...the Senior Director Program Management... ...technical information for projects...ContratistaTemporalTrabajar en la oficinaRemotoHorario flexible- ...the Infrastructure Manager and maintains and... ...infrastructure, aligning with business objectives. The... ...compliance with security and quality... ...Microsoft AD/Entra, Office 365 Suite, and... ...and infrastructure (e.g., MDT, DNS, DHCP... ...Computer Science, Information Technology, or related...Trabajar en la oficina
- ...As the Director of Operations for our Guadalajara Plant, you will lead a 24-hour manufacturing operation and play a critical role... ...accountable for developing leaders, applying economic-based business management, and realizing a clear operational vision across key functions...
- ...Link-Worldwide is seeking a Director of Operations for their Guadalajara Plant in Mexico. This role involves... ...with global teams, promote Principle-Based Management principles, and utilize performance data to achieve business objectives. Candidates should be skilled in...
- ...purchasing, order management and logistics to mitigate risk and enable profitability... ...purchases with the business strategies and... ...-time delivery. Manages the order status process... ...and delivery information is accurate in company... ...or resources to remedy. Work Experience...Inicio inmediato
- ...Operations Manager Location: Zapopan... ...industries to securely and responsibly... ...service enables businesses to meet both... ...compliant, data secure, fully traceable... ...comprehensive solution for e-waste and IT... ...monthly cost information with staff and... ...in MS Office Suite. ~ Objective...Trabajar en la oficina
- ...Head of Ops. Support in managing GC Rooms Operations,... ...keep Ops leadership team informed. Identify trends, opportunities... ...software packages (i.e. Excel, Microsoft Word,... ...budget. Strong business focus, planning, and... ...corporate high‑energy office environment. Experience...Trabajar en la oficina
- ...responsible for leading BU Cell Manager, Production Manager,... ...operations business plans to include all program... ...team follows safety and security procedures. Responsible... ...knowledge required Risk Assessment and... ...Proficiency with Microsoft Office applications required,...Tiempo completoTrabajar en la oficinaHorario flexible
- ...decentralized finance (DeFi), transforming how businesses manage their finances. With thriving hubs in... ...payment flows. Identify operational risks, gaps, and tradeoffs, then present... ...free snacks and paid lunches in the office. We've got your health covered with...Trabajar en la oficinaRemotoTrabajo híbrido
- ...barriers that prevent Business HR from focusing... ...Principle Based Management (PBM®) with employees... ...and sensitive information by elevating concerns... ..., IT, credit, risk, sales, marketing,... ...Experience using Microsoft office suite of products... ...which you had to manage multiple, often...Trabajar en la oficina
- ...Job Summary Job Title: Sr. Director, Business Transformation and Customer Experience (CX)... ...lead solution design, Business Process Management (BPM), and related Continuous Improvement... ...Insulet. Responsibilities Manage new service onboarding, including design...Horario flexibleTrabajo por turnos
- ...:: Technical Program Manager Location :: Guadalajara... ...technical workshops, office hours, and the... ...practices to mitigate business risks and protect user trust... ...level coding proficiency (e.g., ability to read and... ..., Legal, Privacy, and Security reviews). Excellent...PrácticaContratoTrabajar en la oficina
- ...specializing in Systems/Information Technology for... ...FUEL SYSTEMS BUSINESS , located in... ..., 2 days home office) This role is... ...issues, managing incidents, supporting... ...end users Manage configurations,... ...to enable informed decisions. Problem... ...Issue and Risk Management - Manages...Desde casaTrabajo híbrido
- ...energy solutions, our ecosystems help your business move faster, operate smarter and grow... ...Job Title: Operations Construction Manager Company: Prologis Key responsibilities... ...to quickly learn new technologies (i.e. Excel, MS Project, Google Earth, ACAD viewer...ContratistaTiempo completo
- ...Broadcast Operations Venue Manager, FIFA World Cup 2026 - Guadalajara... ..., proactively managing risks, issues and dependencies, and... ...technical services for broadcast (e.g. Security, Cleaning & waste, etc.)... ...Technology ~ Proficient in MS Office (Excel, Word, PowerPoint, Visio...De duración determinadaTiempo completoTrabajar en la oficinaInicio inmediato
- ...Professional (incl. Management Positions)... ...internally Manage guided escalations... ...with business units and account... ...price agreement information Process customer... ...well as smart and secure IoT. Together,... ...Microsoft Office 365 Customer... ...global community e.g. cross-site exchange...ContratistaTiempo completoEmpleo permanenteContratoTrabajar en la oficinaRemotoTrabajo híbridoHorario flexible
- ...with government agencies. The Director drives operational excellence... ...matters. Provide guidance to HR and business partners on payroll policies,... ..., set measurable goals, and manage team performance in alignment... ...and timekeeping systems (e.g., Oracle, ADP, Kronos, or similar...
- ...we're looking to add a Sr Director, Program Management located in Guadalajara, North... ...to generate growth for the business. What a typical day looks... ...Project team(s) and Project manager(s) Provide the necessary leadership... ...), proactively managing risks, and ensuring measurable...Horario flexible
- ...we're looking to add a Sr Director, Program Management located in Guadalajara, North... ...to generate growth for the business. What a typical day looks... ...Project team(s) and Project manager(s) Provide the necessary leadership... ..., and proactively managing risks and mitigation plans....Horario flexible
- ...growth, we're looking to add a Sr Director, Operations (SMT)located in... ...Sr Director, Operations will manage multiple projects in parallel... ...phases and pre-quote to win new business. With core focus in SMT... ...knowledge for complex assemblies (e.g., high-density BGAs/ASIC/CPU...Horario flexible
- Una empresa de logística busca un profesional para realizar inspecciones de mercancías y brindar apoyo en las operaciones. El candidato ideal tendrá una licenciatura o carrera trunca, así como al menos un año de experiencia en logística. Se requiere licencia de manejo y...
- ...are seeking a seasoned Project Manager with a servant-leadership... ...visibility and ensure critical information flows smoothly across teams.... ...updates on project metrics, risks, and overall status. Requirements... ...awareness, conflict resolution, and risk/issue management....
- ...Will Own End-to-End Execution Manage OBC, NFO, and express shipments globally... ...flights and routing proactively. Identify risks early and activate contingency plans.... ...Hybrid role with some days in our office in Guadalajara Work within an international...Trabajar en la oficinaInicio inmediatoTrabajo híbrido
- ...plantillas operativas y control de asistencia. Implementar mejoras continuas en procesos logísticos. Dar seguimiento a auditorías e inventarios cíclicos. ~ Mantener comunicación constante con clientes y áreas internas. REQUISITOS Escolaridad ~...
- ...Overview Director, LATAM SC Customer Operations... ...across a large business group or region(s)... ...professionals (managers and senior individual... ...execution. Manages planning, design,... ...one or more areas (e.g., key policy decisions... ...and analysis to inform business plans and...Tiempo completoTrabajo por turnos
¿Desea recibir más vacantes?
Suscríbase y reciba vacantes similares a Director, Cyber Risk Management & Remediation — Business Information Security Officer (BISO), E[...]. ¡Sea el primero en aplicar!
- jefe de campo Estado de Jalisco
- director de ti Estado de Jalisco
- director idiomas Estado de Jalisco
- director supply chain Estado de Jalisco
- jefe de control de inventario Estado de Jalisco
- jefe de ti Estado de Jalisco
- director operativo Estado de Jalisco
- jefe seguridad privada Estado de Jalisco
- jefe laboratorio Estado de Jalisco
- jefe nominas Estado de Jalisco



