Cybersecurity Business Analyst - Business Units
Company: Eli Lilly and Company
Location: Indianapolis
Posted on: July 17, 2025
|
|
Job Description:
At Lilly, we unite caring with discovery to make life better for
people around the world. We are a global healthcare leader
headquartered in Indianapolis, Indiana. Our employees around the
world work to discover and bring life-changing medicines to those
who need them, improve the understanding and management of disease,
and give back to our communities through philanthropy and
volunteerism. We give our best effort to our work, and we put
people first. We’re looking for people who are determined to make
life better for people around the world. Within the Cybersecurity
organization, the Business Information Security Organization (BISO)
supports the adoption of Cybersecurity initiatives within business
areas and influences the Cybersecurity organization based on
business needs and risks. The Lilly Business Units Cybersecurity
Business Analyst is a key resource within that team. They are an
advanced professional who applies comprehensive expertise across a
function or region. They make impactful decisions, solve major
problems, and build key customer relationships within their scope
of responsibility, ensuring the ongoing partnership between
Cybersecurity and Lilly Business Units across the globe. What You
Will Do: Lead business-focused Cybersecurity strategic,
operational, and tactical efforts on the Lilly Business Units
Cybersecurity roadmap, including data security, working securely,
and business enablement programs. Facilitate the adoption of
business-facing Cybersecurity initiatives within Lilly Business
Units through partnership with Cybersecurity teams. Align the
priorities between cybersecurity and the businesses to ensure
security is embedded in all solutions and any security risk is
transparently accepted. Build relationships with internal and
external customers to assess and reduce Cybersecurity risks.
Collaborate across the business and IT teams to raise security
awareness, provide advisory services, and influence
security-conscious behaviors Contribute to Cyber metrics and
scorecards socialization with business area leadership. Report key
security performance metrics to measure and communicate risk
exposure to business leadership. Monitor and drive compliance and
mitigation activities to ensure the business security posture
improvements improve alignment with security policies. Ensure
security is embedded into systems, security documentation,
applications, and processes through secure design and architecture
principles. Stay current on emerging cybersecurity threats, attack
vectors, and mitigation techniques to enhance preventative and
detective capabilities. Leadership Expectations: Serve as a visible
leader and subject matter expert who influences across and upward.
Guide strategic direction and drive critical business decisions.
Promote innovative thinking across the organization. Build
strategic relationships with key internal partners and
stakeholders. Exercise expert-level judgment to tackle complex
technical or operational challenges. Make decisions that critically
impact business direction. Anticipate potential issues and develop
proactive solutions. Bring structure to ambiguity on complex
endeavors. Demonstrate cyber knowledge and business acumen.
Challenge conventional thinking to drive transformational
improvements. Technical Skills: Requires Cybersecurity depth and/or
breadth. Recognized as the internal expert in their area. Makes
complex technical decisions within general functional, company, and
industry guidelines. Anticipates, identifies, and solves complex
technical problems affecting the functional or business area.
Exercises expert-level judgment to tackle complex technical or
operational challenges. Applies deep knowledge of company,
industry, and regulations/policies. Stays ahead of industry
advancements to maintain a competitive edge. Viewed as a go-to
expert resource for their function or region. Develops innovative
solutions leveraging deep specialization. Stays current on leading
practices, regulations, and industry trends. Your Basic
Qualifications: Bachelor’s degree in computer science,
Cybersecurity, or a related field; a graduate degree is preferred.
5 years of experience in IT or cybersecurity strategy, governance,
and operations. Comprehensive expertise across cybersecurity
domains, including prevention, detection, response, recovery, and
compliance. In-depth knowledge of industry regulations, security
frameworks (NIST, ISO, etc.), and global IT risk standards.
Established expertise in managing cyber programs, complex projects,
and cross-functional teams. Recognized industry certifications
(CISSP, CISM, CRISC) are required. What You Should Bring:
Flexibility to travel internationally (less than 10 percent of
time) Outstanding communication skills with the ability to
articulate cyber risks. Track record of influencing upward,
including presenting security program metrics and business cases.
Lilly is dedicated to helping individuals with disabilities to
actively engage in the workforce, ensuring equal opportunities when
vying for positions. If you require accommodation to submit a
resume for a position at Lilly, please complete the accommodation
request form (
https://careers.lilly.com/us/en/workplace-accommodation ) for
further assistance. Please note this is for individuals to request
an accommodation as part of the application process and any other
correspondence will not receive a response. Lilly is proud to be an
EEO Employer and does not discriminate on the basis of age, race,
color, religion, gender identity, sex, gender expression, sexual
orientation, genetic information, ancestry, national origin,
protected veteran status, disability, or any other legally
protected status. Our employee resource groups (ERGs) offer strong
support networks for their members and are open to all employees.
Our current groups include: Africa, Middle East, Central Asia
Network, Black Employees at Lilly, Chinese Culture Network,
Japanese International Leadership Network (JILN), Lilly India
Network, Organization of Latinx at Lilly (OLA), PRIDE (LGBTQ
Allies), Veterans Leadership Network (VLN), Women’s Initiative for
Leading at Lilly (WILL), enAble (for people with disabilities).
Learn more about all of our groups. Actual compensation will depend
on a candidate’s education, experience, skills, and geographic
location. The anticipated wage for this position is $63,750 -
$145,200 Full-time equivalent employees also will be eligible for a
company bonus (depending, in part, on company and individual
performance). In addition, Lilly offers a comprehensive benefit
program to eligible employees, including eligibility to participate
in a company-sponsored 401(k); pension; vacation benefits;
eligibility for medical, dental, vision and prescription drug
benefits; flexible benefits (e.g., healthcare and/or dependent day
care flexible spending accounts); life insurance and death
benefits; certain time off and leave of absence benefits; and
well-being benefits (e.g., employee assistance program, fitness
benefits, and employee clubs and activities).Lilly reserves the
right to amend, modify, or terminate its compensation and benefit
programs in its sole discretion and Lilly’s compensation practices
and guidelines will apply regarding the details of any promotion or
transfer of Lilly employees. WeAreLilly
Keywords: Eli Lilly and Company, Fairfield , Cybersecurity Business Analyst - Business Units, IT / Software / Systems , Indianapolis, Ohio