Jobs / United States / Astrazeneca Pharmaceuticals Lp
BISO - Commercial IT
Astrazeneca Pharmaceuticals Lp · 🇺🇸 US - Gaithersburg - MD
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 99 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 31 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What Astrazeneca Pharmaceuticals Lp paid sponsored hires in similar roles4 certified filings for “Director, R&D IT - Dvlpmt & Late TA, IT Product Mgmt Clinic” (Data Scientists) in MD: $194k–$201k, median $194k. Most were filed at wage level IV (75%) — 4 lottery entries, ≈61% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Astrazeneca Pharmaceuticals Lp
The US Department of Labor certified 99 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 31 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Astrazeneca Pharmaceuticals Lp →
About the role
The Commercial IT Cybersecurity Business Information Security Officer (BISO) acts as the main cybersecurity partner to Commercial IT and related business areas. This role represents the CISO to lower cyber risk and improve resilience across platforms dedicated to clients and revenue generation. This role leads security for a SaaS-heavy, data-centric Commercial ecosystem spanning CRM, omnichannel engagement, digital experience, analytics and personalization, data and AI platforms, pricing and revenue, integration and API fabric, BI, and MDM. Key platforms include Veeva (CRM/Vault/OCE), Salesforce (Service/Health/Life Sciences/Marketing Cloud, Data 360), Adobe Experience Cloud (AEM/Analytics/Target), Tealium, Databricks on AWS, Model N, MuleSoft/SnapLogic, Power BI, and Reltio, supporting both global operations and localized implementation alongside agency and third-party delivery models. Ready to shape how these critical capabilities stay secure while enabling bold Commercial ambitions? Accountabilities • Act as the Commercial IT security lead and CISO representative. Serve as the primary cybersecurity liaison for the commercial IT division and associated business units worldwide. Coordinate the security strategy with business objectives and customer-centered, revenue-enhancing outcomes. • Lead governance and risk-based decision-making by chairing or participating in key forums, ensuring risk visibility, documented risk acceptance and ownership, and translating enterprise security policy into Commercial-ready standards, guardrails, and roadmaps. • Provide continuous risk advisory and posture management by maintaining awareness of threat trends and regulatory drivers relevant to Commercial operations, proactively advising on priorities, architecture decisions, and long-term security posture. • Establish SaaS security governance across core Commercial platforms by defining and implementing secure configuration baselines, environment and tenant management, identity, SSO and MFA patterns, logging and monitoring, and continuous control monitoring for Veeva, Salesforce, Adobe Experience Cloud, Tealium, and connected tooling. • Strengthen digital channel and web experience security by partnering with digital teams to embed secure SDLC and release practices for externally hosted web content and experiences, aligning protections such as WAF, CDN and DDoS where applicable, and mitigating web-layer and brand-abuse risks including impersonation, account takeover, credential stuffing, web skimming and scraping. • Drive security controls aligned with privacy in marketing and data collection. Ensure consent, tracking governance, and secure handling of healthcare professional and consumer information across digital marketing operations. Follow GDPR and other global privacy rules. • Improve control maturity for commercial content, records and revenue interfaces by maturing controls for content lifecycle and records (including audit trail and e-signature expectations where applicable) and for financial and ordering interfaces where Commercial platforms touch revenue processes, including SOX-relevant controls. • Run vulnerability, audit, and testing remediation to closure. Facilitate risk assessment and ongoing maintenance across SaaS tenants, web properties, and integrations. Drive timely remediation of audit and penetration test findings while reducing repeat issues. • Enhance incident readiness and response coordination by partnering with enterprise SecOps to build Commercial-relevant playbooks, align crisis and BCP activities, support post-incident reviews, and drive business-centric improvements for scenarios such as SaaS compromise, third-party or agency incidents, data exposure and digital channel compromise. • Advanc