Sr. Business Information Security Officer (BISO)
OmnicellAbout the role
Department: Information Technology – Enterprise Security
Location: Grapevine, TX or Cranberry Township, PA (Remote)
Position Overview
The Sr. Business Information Security Officer (BISO) serves as the primary bridge between Omnicell’s Enterprise Security Team and designated lines of business and functions. This role helps business units understand, adopt, and operationalize security policies and processes in a way that enables secure growth while meeting regulatory, customer, and audit expectations.
- Aligns security priorities with business strategies and go‑to‑market plans.
- Translates technical risk into clear business and regulatory impact for leaders.
- Simplifies and integrates security into processes, projects, and technology initiatives.
- Builds trust and credibility with executives, product teams, IT, Legal, and Privacy.
The BISO partners closely with Enterprise Security pillars (Cyber Architecture & GRC, SecOps, Product/Cloud Security, IAM, Third‑Party Risk, Resilience), Privacy, Legal, and commercial, services, and operations leadership.
Essential Duties & Responsibilities
Business Partnership and Risk Advisory
Serve as the primary security liaison for designated business units and functions (e.g., commercial and service leadership, operations, and enabling functions).
Participate in business reviews, portfolio planning, and steering committees to ensure security and privacy requirements are identified early.
Provide clear, risk‑based guidance on new initiatives (e.g., product launches, SaaS and cloud deployments, integrations, use of AI, new market segments), documenting recommended controls and trade‑offs.
Help business leaders balance growth, customer expectations, and regulatory obligations with Omnicell’s security, privacy, and compliance standards.
Security Governance, Alignment & Coverage
Ensure business units operate within Omnicell’s Global Cybersecurity Policy Suite, Enterprise Security Policy, and supporting standards (e.g., IAM, Network Security, Data Protection, Incident Response, Third‑Party Risk).
Interpret global policies in the context of regulations and frameworks (e.g., HIPAA/HITECH, HITRUST, SOC 2, state privacy laws such as CCPA/CPRA, payer/provider security requirements).
Maintain a documented security engagement model for stakeholders, including RACI for key controls, decision rights, and escalation paths.
Represent the security risk posture and control maturi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s