HimalayasHimalayas logo
AmerisourceBergenAM

BISO (Business Information Security Office) Lead

Cencora, formerly AmerisourceBergen, is a global pharmaceutical sourcing and distribution services company, partnering with healthcare providers and pharmaceutical manufacturers to improve product access and patient care. It was formed in 2001 and rebranded in 2023.

AmerisourceBergen

Employee count: 5000+

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!

Job Details

Purpose & Impact

The Business Information Security Office Lead serves as the strategic bridge between business/IT stakeholders and security teams, ensuring that security architecture principles, security requirements, risk management practices, and governance, risk, and compliance (GRC) requirements are deeply embedded into technology implementations, enterprise processes, and organizational decision-making. This role owns and drives secure architecture reviews, provides authoritative guidance on design patterns, risk treatment strategies, and compliance obligations — ultimately reducing risk exposure across multiple platforms and business domains.

Responsibilities

Lead Security Architecture Design & Review

  • Drive and contribute to the end-to-end secure architecture review process for on-prem, cloud, and hybrid applications/infrastructure, ensuring adherence to secure design principles, reference architectures, security requirements and compliance standards.
  • Support the use of and contribute to security architecture patterns, blueprints, and reference models that align with enterprise strategy and evolving threat landscapes.
  • Evaluate proposed technical designs and system integrations to ensure security requirements are met, providing prescriptive architectural and control recommendations.
  • Perform security reviews for operational and architectural changes

Drive Enterprise Risk Management

  • Lead and support comprehensive risk assessments — including threat modeling, control gap analysis, compensating control and risk quantification — for complex, high-impact projects and initiatives.
  • Support the maintenance of the risk register, ensuring identified risks are documented, assigned ownership is appropriate, tracked through remediation, and reported to leadership.
  • Propose and validate risk mitigation and treatment strategies, balancing security requirements with business objectives and risk appetite.

Support Governance Activities the GRC Program

  • Support and advance the organization's Governance, Risk, and Compliance (GRC) program, ensuring alignment with regulatory requirements and industry frameworks (e.g., NIST CSF/800-53, ISO 27001/27002, SOC 2, GDPR, HIPAA, CMMC).
  • Lead the evidence gathering, control testing, and documentation processes for internal and external audits, regulatory examinations, and certification efforts.
  • Develop, refine, and enforce security policies, standards, and guidelines in collaboration with legal, compliance, and business stakeholders.

Serve as Primary Security Officer & Risk Contact

  • Act as the authoritative resource for security architecture and risk management across business initiatives, ensuring requirements are understood, prioritized, and implemented effectively.
  • Embed security and risk considerations early in the technology and project lifecycle (shift-left approach), partnering with solution architects, engineering, and product teams.

Communicate & Report on Risk Posture

  • Translate complex security architecture risks and GRC findings into business terms for project managers, executive leadership, and board-level audiences — highlighting operational, financial, and reputational impacts.
  • Drive the development and maintenance of dashboards and reports tracking key risk indicators (KRIs), vulnerability trends, audit findings, control effectiveness, compliance status across assigned domains, etc.
  • Present periodic risk and compliance briefings to senior leadership and governance committees.
  • Build deep institutional knowledge through continuous engagement with business and IT stakeholders to ensure alignment to information security expectations.

Support Incident Response & Resilience

  • Assist in planning and coordinating remediation and recovery efforts during security incidents, with a focus on architectural root-cause analysis and control improvement.
  • Incorporate lessons learned from incidents into architecture standards and risk assessments to strengthen the organization's security posture.

Mentor & Build Organizational Capability

  • Provide guidance, coaching, and knowledge-sharing to junior architects, BISO staff, and cross-functional team members to elevate organizational security and risk management maturity.
  • Foster a risk-aware culture through training, awareness programs, and stakeholder engagement.

Required Qualifications

  • Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field.
  • 7–10 years of progressive experience in security architecture, IT risk management, and/or GRC.
  • Deep knowledge of cybersecurity frameworks and regulatory standards including OWASP, NIST CSF, NIST 800-53, ISO 27001/27002, SOC 2, GDPR, and HIPAA.
  • Demonstrated experience designing and reviewing secure architectures across cloud (AWS, Azure, GCP), hybrid, and on-premises environments.
  • Proven ability to conduct threat modeling, risk quantification, and control assessments for complex enterprise environments.
  • Hands-on experience with GRC platforms and tools (e.g., ServiceNow , Archer, OneTrust, or similar).
  • Ability to influence cross-functional teams and communicate security architecture and risk concepts — both verbally and in writing — to business leaders, technical teams, and executive stakeholders.
  • Experience developing and maintaining security policies, standards, and risk registers.

Preferred Skills

  • Experience implementing and improving cybersecurity solutions and supporting operational processes
  • Experience in infrastructure/network engineering and IT operations
  • Experience designing and implementing Zero Trust architecture principles at scale.
  • Familiarity with DevSecOps practices and integrating security into CI/CD pipelines.
  • Experience with risk quantification methodologies (e.g., FAIR).
  • Knowledge of cloud-native security services and infrastructure-as-code security scanning.
  • Experience supporting M&A due diligence or third-party risk management from an architecture and GRC perspective.

Certifications

  • CISSP, CISM, or CCSP — required (or obtained within 12 months of hire).
  • CRISC (Certified in Risk and Information Systems Control) — highly preferred.
  • Additional certifications valued: CGEIT, TOGAF, SABSA, AWS/Azure Security Specialty.

What Cencora offers

We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members’ ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https://www.virtualfairhub.com/cencora

Full time

Equal Employment Opportunity

Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.

The company’s continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.

Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email hrsc@cencora.com. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned

Affiliated Companies

Affiliated Companies: AmerisourceBergen Services Corporation

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Education

Bachelor degree

Experience

7 years minimum

Experience accepted in place of education

Location requirements

Hiring timezones

United States +/- 0 hours

About AmerisourceBergen

Learn more about AmerisourceBergen and their company culture.

View company profile

Cencora, formerly known as AmerisourceBergen Corporation, stands as a prominent global pharmaceutical solutions organization. The company was formed in 2001 through the merger of AmeriSource Health Corporation and Bergen Brunswig. Operating with a clear purpose, Cencora is dedicated to creating healthier futures by improving the accessibility and efficiency of pharmaceutical development and delivery worldwide. The organization partners extensively with pharmaceutical innovators, healthcare providers, and pharmacies across the entire value chain. This collaboration aims to optimize market access for therapies, ensuring that medications reach patients effectively and reliably.

With a significant global presence, Cencora employs a substantial workforce of over 46,000 team members. These individuals contribute to positive health outcomes by facilitating the secure and dependable delivery of pharmaceuticals, healthcare products, and comprehensive solutions. The company's operations span numerous countries, including major distribution networks in the United States and Canada, as well as packaging facilities in the U.S. and the United Kingdom. Cencora's core business revolves around pharmaceutical distribution, but it has strategically expanded its platform to include a wide array of pharma and biopharma services. These services are designed to support pharmaceutical innovation, from pre-commercialization and clinical trial stages to broad market availability and patient adherence programs. The company handles a significant portion of all pharmaceuticals sold and distributed in the United States and serves a diverse clientele, including acute care hospitals, retail pharmacies, medical clinics, and veterinary practices. In August 2023, AmerisourceBergen officially rebranded to Cencora, a name chosen to reflect its unified global presence and its central role in healthcare.

Employee benefits

Learn about the employee benefits and perks provided at AmerisourceBergen.

View benefits

Vision insurance

Vision care benefits.

401(K)

Retirement savings plan.

Dental insurance

Dental coverage for employees.

Company equity

Opportunity for company equity.

View AmerisourceBergen's employee benefits
Claim this profileAmerisourceBergen logoAM

AmerisourceBergen

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

107 remote jobs at AmerisourceBergen

Explore the variety of open remote roles at AmerisourceBergen, offering flexible work options across multiple disciplines and skill levels.

View all jobs at AmerisourceBergen

Remote companies like AmerisourceBergen

Find your next opportunity by exploring profiles of companies that are similar to AmerisourceBergen. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan