> Markdown version of [/jobs/ext/1826160-sr-business-information-security-officer-biso](https://www.wearedevelopers.com/jobs/ext/1826160-sr-business-information-security-officer-biso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Business Information Security Officer (BISO) - **Company:** Omnicell, Inc. - **Location:** Dallas, TX, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing Security, Cyber Security, Information Systems, Data Centers, EHealth, Identity and Access Management, Network Security, Cloud Services, Data Streaming, Data Logging, Data Classification, Information Technology, Cloud Migration - **Published:** July 4, 2026 - **Apply:** https://www.juju.com/job/00000000gduwzz ## About the Role + 7+ years of experience in information security, cybersecurity, or IT risk management, with at least 3+ years in a customer- or business-facing security role (e.g., BISO, Security Architect, GRC, Product/Cloud Security, or similar) + Demonstrated experience working with complex, multi-business-unit or enterprise stakeholders, ideally in highly regulated industries (e.g., healthcare, life sciences, finance, or public sector) + Proven ability to translate complex technical risks into business language for VP- and director-level audiences + Strong understanding of: + Enterprise security programs (policies, standards, risk registers, CAPs) + Core domains such as IAM, network and cloud security, data protection, third-party risk, incident response, and BCDR + How security controls are evidenced and evaluated in audits and certifications (e.g., HITRUST, SOC 2, HIPAA/HITECH compliance activities) + Excellent written and verbal communication and storytelling skills, including the ability to create executive-ready narratives and lead productive discussions with non-security stakeholders + Strong influence, relationship-building, and prioritization skills in a complex, matrixed organization Preferred Qualifications + Bachelor's or MBA degree in Cybersecurity, Information Systems, Computer Science, Business, Risk Management + Professional certifications such as CISSP, CISM, CRISC, CISA, CCSK/CCSP, CIPM/CIPT, CGEIT, or equivalent + Experience in healthcare, medical devices, digital health, or SaaS/cloud services supporting regulated customers (e.g., hospitals, health systems, payers) + Prior experience as a BISO, regional security lead, or customer-facing security architect serving healthcare or other highly regulated markets ## Description The Sr. Business Information Security Officer (BISO) serves as the primary bridge between Omnicell's Enterprise Security Team and designated lines of business and functions. This role helps business units understand, adopt, and operationalize security policies and processes in a way that enables secure growth while meeting regulatory, customer, and audit expectations. + Aligns security priorities with business strategies and go-to-market plans. + Translates technical risk into clear business and regulatory impact for leaders. + Simplifies and integrates security into processes, projects, and technology initiatives. + Builds trust and credibility with executives, product teams, IT, Legal, and Privacy. The BISO partners closely with Enterprise Security pillars (Cyber Architecture & GRC, SecOps, Product/Cloud Security, IAM, Third-Party Risk, Resilience), Privacy, Legal, and commercial, services, and operations leadership. Essential Duties & Responsibilities Business Partnership and Risk Advisory + Serve as the primary security liaison for designated business units and functions (e.g., commercial and service leadership, operations, and enabling functions). + Participate in business reviews, portfolio planning, and steering committees to ensure security and privacy requirements are identified early. + Provide clear, risk-based guidance on new initiatives (e.g., product launches, SaaS and cloud deployments, integrations, use of AI, new market segments), documenting recommended controls and trade-offs. + Help business leaders balance growth, customer expectations, and regulatory obligations with Omnicell's security, privacy, and compliance standards. Security Governance, Alignment & Coverage + Ensure business units operate within Omnicell's Global Cybersecurity Policy Suite, Enterprise Security Policy, and supporting standards (e.g., IAM, Network Security, Data Protection, Incident Response, Third-Party Risk). + Interpret global policies in the context of regulations and frameworks (e.g., HIPAA/HITECH, HITRUST, SOC 2, state privacy laws such as CCPA/CPRA, payer/provider security requirements). + Maintain a documented security engagement model for stakeholders, including RACI for key controls, decision rights, and escalation paths. + Represent the security risk posture and control maturity in enterprise security and IT risk governance forums. Risk Management, Assessments & Reporting + Maintain a security risk register aligned with NIST CSF v2.0, Omnicell's risk taxonomy, and enterprise risk processes. + Coordinate or lead risk and privacy impact assessments for systems, data flows, and business processes, in partnership with Privacy, Legal, Product, and IT. + Translate assessment findings into corrective action plans (CAPs) with clear owners, timelines, and mapping to applicable control frameworks (e.g., NIST CSF, NIST 800-53, HITRUST, SOC 2, Omnicell policies, and relevant regulations). + Contribute data to enterprise security metrics and dashboards (e.g., vulnerabilities, incident trends, IAM metrics, training completion) and help drive remediation and continuous improvement. Security Enablement, Projects &Change Initiatives + Embed security into programs and projects (e.g., cloud migrations, data center moves, partner integrations, major customer programs, M&A integrations, and divestitures) by ensuring requirements are captured and designs align with enterprise reference architectures and policies. + Partner with Product/Cloud Security and IT to ensure hosted workloads follow standards across segmentation, logging, IAM, PAM, CSPM, DLP, EDR, and related controls. + Support data classification and handling for operations, ensuring that confidential information, PHI, and PII are managed per Omnicell policies and applicable US laws and regulations. + Promote and coordinate security training and awareness tailored for audiences (commercial, operations, support, engineering, and partners). Customer, Audit & Regulatory Engagement + Support customer security assessments, RFPs, due diligence, and contract negotiations for opportunities, ensuring accurate and consistent representation of Omnicell's security posture. + Collaborate with Legal, Privacy, and Enterprise Security to provide timely, high-quality responses to regulators, auditors, and key strategic customers. + Coordinate evidence collection and responses for audits and certifications that include scope (e.g., HITRUST, SOC 2, ISO 27001, HIPAA-related assessments). + Help maintain and improve customer-facing security narratives and documentation relevant to healthcare providers, health systems, and other regulated customers. Incident Management, Business Continuity & Resilience + Act as a key security lead for incidents impacting systems, customers, or data, in accordance with global Incident Response policies and playbooks. + Coordinate with SecOps, Privacy, Legal, and leadership on triage, containment, remediation, and required customer or regulatory notifications (e.g., HIPAA breach notifications). + Ensure lessons learned from incidents and near misses are captured and drive durable improvements (policy updates, new controls, training, or process changes). + Partner with Enterprise Resilience / BCDR leaders to align continuity and recovery plans for operations with security and risk priorities. Leadership, Influence & Culture + Build and maintain trusted relationships with general managers, functional leaders, IT, Product, and strategic partners. + Influence decision-making by presenting clear, concise narratives on risk, options, and recommended paths that align with Omnicell's risk appetite and customer commitments. + Mentor security champions and points of contact within business units to distribute ownership of security beyond Enterprise Security. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [The Sustainability Race: AI's Promises, Pitfalls and Potential](https://www.wearedevelopers.com/videos/100155-the-sustainability-race-ai-s-promises-pitfalls-and-potential) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Building the Nervous System of AI - Michael Kagan (NVIDIA)](https://www.wearedevelopers.com/videos/2133-building-the-nervous-system-of-ai-michael-kagan-nvidia) ## Related Articles - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023)