Executive Director - Business Information Security Officer; BISO
Listed on 2026-09-27
-
IT/Tech
Information Security & Data Protection, Cybersecurity, IT Consultant, Change Management
Location: Northern
We're building a world of health around every individual - shaping a more connected, convenient and compassionate health experience. At CVS Health®, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger - helping to simplify health care one person, one family and one community at a time.
PositionSummary
The Executive Director - Business Information Security Officer (BISO) will serve as a senior leader and trusted security advisor supporting all CVS Health lines of business, with accountability for leading the BISO team and driving mission, vision, and governance model. This individual will provide senior-level leadership, strategic and tactical guidance for a world-class enterprise cybersecurity program. As a business enabler, the BISO is an effective communicator with the technical aptitude to embed security strategy and risk-based decision-making into all aspects of the business.
The BISO understands security risks, threats, vulnerabilities, control frameworks, and security technologies and translates their impact in business terms. The BISO must be capable of working closely with senior IT business leaders, executive leadership, and business subject matter experts (SMEs). This role requires demonstrated leadership, exceptional organizational skills, strong business and financial acumen, and the ability to influence and drive change at scale across the organization.
Job Duties & Responsibilities
- Serve as a trusted advisor with business unit leadership and act as a liaison to ensure cybersecurity practices are built into business unit initiatives for the entire lifecycle, with accountability for strategic alignment and outcomes.
- In conjunction with security risk management and business leaders, define and report key performance indicators (KPIs) and metrics aligning with business initiatives and deliver them to non-technical teams in terms that are accessible and comprehensible, including senior-leader-level reporting and insights.
- Drive risk management strategy by designing business unit security objectives, communicating the vision, and driving accomplishments and outcomes, with ownership for prioritization and execution across teams.
- Lead or support critical projects and initiatives, ensuring alignment with strategic goals and timely execution, including sponsorship of large-scale, cross-functional initiatives. Track progress and report on key performance indicators.
- Develop and disseminate clear and effective communication materials, including presentations, reports, and memos for both internal and external stakeholders, tailored for senior-leader audiences.
- Gather, analyze, and present data to support decision-making processes, identify trends with quantitative and qualitative insights and recommendations, and drive continuous improvement efforts and dependency alignment across the BISO function.
- Act as a key problem-solving resource, helping to address complex issues and challenges within the organization, including those with enterprise-wide impact.
- Organize and lead meetings and forums, and set agendas ensuring that discussions are productive, action items are documented, and decisions are followed through, including leadership-level governance and operating reviews.
- Stay abreast of new laws, regulations, and standards, and assess their impact to the business, providing guidance and recommendations to IT business leadership.
- Negotiate to remove complexity and obstacles that hinder efficient security controls enterprise-wide, leveraging senior-leader influence.
- Provide motivation to business units to adopt cybersecurity…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).