Vice President, Business Information Security Office (BISO) & Security Risk
RELX
Vice President, Business Information Security Office (BISO) & Cyber Security Risk About Our Team The Business Information Security Office (BISO) team partners closely with business, product, and technology leaders to deliver measurable security outcomes that directly support enterprise objectives. We focus on managing complex and critical risk, embedding secure-by-design practices, and driving long-term cybersecurity maturity across the organization.
This role also carries a dedicated cyber security risk management mandate, connecting business-aligned security partnership with rigorous identification, assessment, and treatment of cyber and technology risk. Our work enables trusted innovation, operational resilience, and informed risk decision-making at scale. About the Role As Vice President, Business Information Security & Cyber Security Risk, you lead the enterprise BISO function and own cyber security risk management for the organization, while personally serving as the senior security partner for your assigned business unit.
You carry a dual mandate: you build, lead, and develop a team of BISOs supporting business units across the organization, and you act as the accountable BISO for your assigned business unit, modeling the standard of partnership, judgment, and delivery you expect from the team. Reporting into the Elsevier Information Security organization, you set the vision, operating model, and priorities for how security partners with the business at scale, and you own cyber security risk management, including risk identification, assessment, treatment, and acceptance, as a distinct, standing capability.
You are accountable for the consistency, quality, and measurable risk outcomes of BISO coverage across all supported business units, and for a clear, well-understood cyber risk posture reported to executive and business leadership. Key Responsibilities Team Leadership & Function Strategy · Build, lead, and develop a team of BISOs and cyber risk professionals supporting business units across the organization, owning hiring, coaching, performance management, and career development, and setting clear standards of performance.
· Define and evolve the BISO and cyber risk operating model, engagement standards, and coverage allocation, deploying resources across business units based on risk, business criticality, and strategic priorities. · Establish consistent methods, playbooks, and reusable artifacts so partnership, risk assessment, and reporting meet a common quality bar; manage the function's budget, headcount, and vendor relationships.
· Serve as the senior escalation point on complex or high-severity risk decisions, providing executive judgment and air cover for the team. Executive Business Partnership & Program Governance · Serve as the senior security partner and accountable BISO for your assigned business unit, building trusted relationships with business unit presidents, product leaders, and technology executives.
· Embed security early in strategy, planning, product development, and delivery for your business unit, and ensure the team does the same across their business units. · Sponsor and govern the portfolio of enterprise and business-aligned security initiatives, ensuring requirements are integrated into major technology programs and removing organizational blockers. · Represent the aggregated risk posture of your portfolio to executive leadership, balancing risk management with business objectives and delivery speed.
Security Assurance & Cyber Risk Management · Own the cyber and technology risk management framework, risk taxonomy, and risk appetite and tolerance thresholds, aligned to enterprise risk management. · Oversee the portfolio's security assessments, including vulnerability scanning, penetration testing, application and infrastructure reviews, and third-party security risk assessments.
·