it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

8 jobs found

Email me jobs like this
Refine Search
Current Search
cyber security business information officer biso
BISO: Strategic Security Partner for Business Units
LexisNexis Risk Solutions
LexisNexis Risk Solutions in Greater London is looking for a Cyber Security Business Information Officer (BISO) to act as the primary security partner across business units. This role focuses on embedding security into initiatives and ensuring a robust cybersecurity posture. The ideal candidate will have several years of experience in similar roles, expertise in cloud and application security, and the ability to communicate security risks in business terms. The position offers a collaborative environment, ensuring security is prioritized through all stages of product development.
13/07/2026
Full time
LexisNexis Risk Solutions in Greater London is looking for a Cyber Security Business Information Officer (BISO) to act as the primary security partner across business units. This role focuses on embedding security into initiatives and ensuring a robust cybersecurity posture. The ideal candidate will have several years of experience in similar roles, expertise in cloud and application security, and the ability to communicate security risks in business terms. The position offers a collaborative environment, ensuring security is prioritized through all stages of product development.
Cyber Security Business Information Officer (BISO)
LexisNexis Risk Solutions
.Cyber Security Business Information Officer (BISO) page is loaded Cyber Security Business Information Officer (BISO)locations: Oxford: Londontime type: Full timeposted on: Posted Todayjob requisition id: R112581 About Our Team The Business Information Security Office (BISO) team partners with business, product, and technology leaders to deliver measurable security outcomes that support enterprise objectives. We focus on managing complex risk, embedding secure by design practices, and driving long term cybersecurity maturity. Our work enables trusted innovation, operational resilience, and informed risk decision making across the organization. About the Role As a Business Information Security Officer (BISO), you act as the primary security partner for assigned business units, bridging business strategy and enterprise cybersecurity. You are accountable for planning and executing security initiatives that reduce risk, strengthen cyber defenses, and enable delivery at scale. The role is highly collaborative, advisory, and outcome focused-ensuring security is embedded early and pragmatically across products, platforms, and major initiatives. Responsibilities: Act as the primary security partner for assigned business units, building trusted senior stakeholder relationships. Embed security early into business initiatives, product development, and technology delivery. Sponsor and support enterprise and business aligned security initiatives end to end. Provide expert security guidance across concurrent IT, engineering, and business projects. Oversee security assessments including vulnerability management, penetration testing, and third party risk. Translate security findings into prioritized, actionable remediation plans with clear ownership. Provide security input into solution architecture and major technology decisions. Serve as the security point of contact for customer facing inquiries, audits, and due diligence. Identify, document, and govern cyber risks, supporting risk acceptance and escalation processes. Develop and report meaningful security metrics to inform leadership decisions and continuous improvement. Requirements: Several years' experience in a BISO or senior security leadership / advisory role. Strong cloud and application security experience (AWS, Azure, GCP; secure SDLC). Hands on knowledge of security tooling (SIEM, SOAR, EDR/XDR, CSPM, SAST/DAST). Experience embedding security into CI/CD pipelines and DevSecOps practices. Proven capability in risk assessments, threat modeling, and control gap analysis. Experience collaborating with SOC and Incident Response teams during security events. Working knowledge of security frameworks and regulations (NIST, ISO 27001, CIS, GDPR, etc.). Ability to translate technical risk into clear, business relevant language. Strong stakeholder management skills with the ability to influence without authority. Bachelor's degree in Engineering, Computer Science, or equivalent experience, plus relevant certifications (CISSP, CISM, GIAC, or similar). We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click to access benefits specific to your location. We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our or please contact 1-. Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams . Please read our .We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law. USA Job Seekers: .RELX is a global provider of information-based analytics and decision tools for professional and business customers, enabling them to make better decisions, get better results and be more productive.Our purpose is to benefit society by developing products that help researchers advance scientific knowledge; doctors and nurses improve the lives of patients; lawyers promote the rule of law and achieve justice and fair results for their clients; businesses and governments prevent fraud; consumers access financial services and get fair prices on insurance; and customers learn about markets and complete transactions.Our purpose guides our actions beyond the products that we develop. It defines us as a company. Every day across RELX our employees are inspired to undertake initiatives that make unique contributions to society and the communities in which we operate.
13/07/2026
Full time
.Cyber Security Business Information Officer (BISO) page is loaded Cyber Security Business Information Officer (BISO)locations: Oxford: Londontime type: Full timeposted on: Posted Todayjob requisition id: R112581 About Our Team The Business Information Security Office (BISO) team partners with business, product, and technology leaders to deliver measurable security outcomes that support enterprise objectives. We focus on managing complex risk, embedding secure by design practices, and driving long term cybersecurity maturity. Our work enables trusted innovation, operational resilience, and informed risk decision making across the organization. About the Role As a Business Information Security Officer (BISO), you act as the primary security partner for assigned business units, bridging business strategy and enterprise cybersecurity. You are accountable for planning and executing security initiatives that reduce risk, strengthen cyber defenses, and enable delivery at scale. The role is highly collaborative, advisory, and outcome focused-ensuring security is embedded early and pragmatically across products, platforms, and major initiatives. Responsibilities: Act as the primary security partner for assigned business units, building trusted senior stakeholder relationships. Embed security early into business initiatives, product development, and technology delivery. Sponsor and support enterprise and business aligned security initiatives end to end. Provide expert security guidance across concurrent IT, engineering, and business projects. Oversee security assessments including vulnerability management, penetration testing, and third party risk. Translate security findings into prioritized, actionable remediation plans with clear ownership. Provide security input into solution architecture and major technology decisions. Serve as the security point of contact for customer facing inquiries, audits, and due diligence. Identify, document, and govern cyber risks, supporting risk acceptance and escalation processes. Develop and report meaningful security metrics to inform leadership decisions and continuous improvement. Requirements: Several years' experience in a BISO or senior security leadership / advisory role. Strong cloud and application security experience (AWS, Azure, GCP; secure SDLC). Hands on knowledge of security tooling (SIEM, SOAR, EDR/XDR, CSPM, SAST/DAST). Experience embedding security into CI/CD pipelines and DevSecOps practices. Proven capability in risk assessments, threat modeling, and control gap analysis. Experience collaborating with SOC and Incident Response teams during security events. Working knowledge of security frameworks and regulations (NIST, ISO 27001, CIS, GDPR, etc.). Ability to translate technical risk into clear, business relevant language. Strong stakeholder management skills with the ability to influence without authority. Bachelor's degree in Engineering, Computer Science, or equivalent experience, plus relevant certifications (CISSP, CISM, GIAC, or similar). We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click to access benefits specific to your location. We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our or please contact 1-. Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams . Please read our .We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law. USA Job Seekers: .RELX is a global provider of information-based analytics and decision tools for professional and business customers, enabling them to make better decisions, get better results and be more productive.Our purpose is to benefit society by developing products that help researchers advance scientific knowledge; doctors and nurses improve the lives of patients; lawyers promote the rule of law and achieve justice and fair results for their clients; businesses and governments prevent fraud; consumers access financial services and get fair prices on insurance; and customers learn about markets and complete transactions.Our purpose guides our actions beyond the products that we develop. It defines us as a company. Every day across RELX our employees are inspired to undertake initiatives that make unique contributions to society and the communities in which we operate.
Supply Chain Cyber Security Manager (TA2) - Europe
Unilever
Supply Chain Cyber Security Manager (TA2) - EuropeBewerbenlocations: Kingston Head Officetime type: Vollzeitposted on: Heute ausgeschriebentime left to apply: Enddatum: 23. Juli 2026 (Noch 13 Tage Zeit für Bewerbung)job requisition id: R- Supply Chain Cyber Security Manager (TA2) - Europe Are you inspired to secure automation in manufacturing? Are you looking for a new opportunity? Would you relish the opportunity to work for a global FMCG organisation? Then look no further we are currently on the hunt for a Supply Chain Cyber Security Manager (TA2) to join our dynamic and forward-thinking Global Factory Security team. This is an exciting new role in Supply Chain which is tasked to deliver maximum value by securing automation and driving cyber security across Unilever's global production sites. The Global Factory Security team covers Operational Technology (OT) deployed within factory sites including, automation and control systems, safety systems, engineering IT assets, factory and engineering data networks. We have a strategy to secure automation across Unilever's global production sites. We are poised to deliver a range of core cyber security controls to reduce the cyber security risk across our global manufacturing estate. This role will be a member of the Business Information Security Officer's team responsible for the cyber security of OT across the regional factory estate. Reporting into the BISO for Europe, PTAB & Finance, the successful candidate will work on Factory Cyber Security to deliver and maintain the OT security strategy and a variety of Digital Factory and Industry 4.0 projects, encompassing: • Safety • Quality • Cost Savings • Capacity • Innovation • Infrastructure The above would be within A&C, primarily for Batch, Continuous Processes and Packaging Systems. As Factory Security Cluster Lead (TA2), you will provide regional specialist industrial control and OT cyber security management and expertise to regional sites, including technical design, delivery and maintenance of the OT security controls and strategy. The role will ensure that the regional OT security strategy milestones and projects are delivered on time, with a strong focus on safety, quality, budget and schedule adherence. You will collaborate with the IT, Information Security, Electrical and Mechanical Maintenance, Operations, Safety and Quality Assurance personnel to support the delivery of the OT cyber strategy, in-line with business objectives and utilising your regional management and site-based technical IT skills. What would my key responsibilities include? This role will be responsible for managing, scheduling and delivering a range of OT cyber security controls to global production sites. You will be knowledgeable about IP networks and cyber security architecture and controls and able to respond to a broad range of technical queries and issues. You will be required to work closely with both the Factory Cyber Security Core Team and Supply Chain Engineering globally. Responsibilities and activities include: • Building relationships with multi-discipline factory and management stakeholders. • Presenting to multi-discipline management stakeholders. • Working knowledge and understanding of OT and IT cyber security technologies. • Working knowledge and understanding of OT and IT cyber security standards and guidelines such as: ISA62443, ISO27001, NIST800-82. • Ability to identify OT security risks and issues and design mitigating controls and solutions. • Proactive management and delivery of OT security workstreams and projects to ensure the following are carried out: o Design and approach of cyber solutions or services to meet requirements. o OT security standards compliance. o Scoping and production of deliverables. o Monitoring OT security KPI's. o Project management. o Review of team deliverables for quality and risk purposes. o Liaising with stakeholders on delivery and implementation issues. o Identifying cyber improvement opportunities. • Developing excellent relationships with colleagues in other areas of the business. • Communicating effectively, in a way that is open, honest, consistent and clear. • Working to deliver an agreed portfolio of projects under the leadership of the Supply Chain, Information Security, and Global Factory Security Lead. • Ensuring professional project execution with strong stakeholder engagement along with a high level of communication to various levels of the organization. • Supporting management to check feasibility of capex projects working collaboratively with Quality, Safety, Manufacturing, Marketing, R&D and plant personnel to clarify the brief, understand work scope, estimate costs and create viable timelines. • Participating and contributing to factory OT governance activities. • Develop Project Execution Plan and schedules. • Execute projects ensuring adherence to schedule and budget. Manage security solution deployments and improvements, contractors, and OEM's ensuring Unilever Security and Safety Standards are applied. • Assist factory with non-capital improvements, identifying enhancements in ways of working to improve line or infrastructure efficiencies. • Assist with the complex controls related cyber troubleshooting, while working with multiple stakeholders to improve OT security skill sets within the factory workforce. • Assist wider projects to ensure legal compliance such as NIS2 • Organize Cyber Awareness- & Training campaigns including Cyber Crisis exercises (Table-Top) What Skills and Experience do I need? • Engineering degree or equivalent experience and recognised peer reviewed cyber security certification. • Project management skills. • Strong communication (verbal and written) and networking skills (interpersonal and planning) • Experience in delivering OT security in an A&C environment within a global manufacturing organisation. • Demonstrable experience of the cyber security issues facing manufacturing organisations and particularly security risk management relating to industrial control systems and Operational Technology. • Strong understanding of legacy A&C concepts and technology and digital OT and Industry 4.0 technology in terms of network infrastructure, integration with business information systems, and the challenges faced from a cyber security perspective. • Strong team focus, communication, relationship building and influencing skills. • Ability to lead teams with internal and external resources. • Strong attention to detail and the ability to deliver projects to the Unilever engineering standards. • Technical subject matter expertise in ICS/OT cyber security architecture and design, installation, configuration and management in manufacturing (preferable food, home care or personal care products). • Good knowledge in Microsoft Power Platform incl. PowerApps, PowerBI & PowerAutomate Essential Experience Required: • Experience with automation equipment and structures • Experience with industrial cyber security controls and good practice • Experience of working in a production environment in a key site role • Strong data networking skills • Strong analytical skills • Ability to work in virtual teams • Ability to build critical skills and develop key talent Areas of Relevant Experience: • Experience in Engineering and Technology with knowledge of manufacturing technologies • Knowledge or familiarity with OT security solutions and technologies such as; IP networks, firewalls, SIEM, remote access control, anti-virus / anti-malware, threat monitoring etc Company overview: Unilever is a global Fast-Moving Consumer Goods company in the UK and Ireland. We are already on target to achieve our huge ambition to double the size of our business globally whilst reducing our environmental impact. We are growing our business and also doing what is right for our consumers, community and environment. We are developing brands for people's lives today and for the changing environment tomorrow - making sustainable living commonplace. Working at Unilever means that you get to take part in this exciting journey and work with amazing people who are really passionate about our large portfolio of famous brands. We want to improve billions of lives and you too can join us in making a sustainable difference. Application process: Please note: As part of the job application, you will be asked to complete a brief online application form. Completion of the form is required in order to be considered. Please allow yourself enough time to complete the application form as when filled out partially or not at all it may adversely affect the progress of your application. Please be aware that you will have to complete the form at once as you will be unable to return to it later. NOTE: Please apply online and add your PDP & Talent Profile if possible. Your application will be reviewed against our requirements and we will be in touch to provide you with an update on the status of your application. By applying for this vacancy, you are confirming that you have made your Line Manager aware of your application and that you are at a point in your career with Unilever where it is appropriate for you to be applying for other positions. Should you require additional information, please contact Tom Baker /Anthony Nichol Unilever is an equal opportunities employer.
12/07/2026
Full time
Supply Chain Cyber Security Manager (TA2) - EuropeBewerbenlocations: Kingston Head Officetime type: Vollzeitposted on: Heute ausgeschriebentime left to apply: Enddatum: 23. Juli 2026 (Noch 13 Tage Zeit für Bewerbung)job requisition id: R- Supply Chain Cyber Security Manager (TA2) - Europe Are you inspired to secure automation in manufacturing? Are you looking for a new opportunity? Would you relish the opportunity to work for a global FMCG organisation? Then look no further we are currently on the hunt for a Supply Chain Cyber Security Manager (TA2) to join our dynamic and forward-thinking Global Factory Security team. This is an exciting new role in Supply Chain which is tasked to deliver maximum value by securing automation and driving cyber security across Unilever's global production sites. The Global Factory Security team covers Operational Technology (OT) deployed within factory sites including, automation and control systems, safety systems, engineering IT assets, factory and engineering data networks. We have a strategy to secure automation across Unilever's global production sites. We are poised to deliver a range of core cyber security controls to reduce the cyber security risk across our global manufacturing estate. This role will be a member of the Business Information Security Officer's team responsible for the cyber security of OT across the regional factory estate. Reporting into the BISO for Europe, PTAB & Finance, the successful candidate will work on Factory Cyber Security to deliver and maintain the OT security strategy and a variety of Digital Factory and Industry 4.0 projects, encompassing: • Safety • Quality • Cost Savings • Capacity • Innovation • Infrastructure The above would be within A&C, primarily for Batch, Continuous Processes and Packaging Systems. As Factory Security Cluster Lead (TA2), you will provide regional specialist industrial control and OT cyber security management and expertise to regional sites, including technical design, delivery and maintenance of the OT security controls and strategy. The role will ensure that the regional OT security strategy milestones and projects are delivered on time, with a strong focus on safety, quality, budget and schedule adherence. You will collaborate with the IT, Information Security, Electrical and Mechanical Maintenance, Operations, Safety and Quality Assurance personnel to support the delivery of the OT cyber strategy, in-line with business objectives and utilising your regional management and site-based technical IT skills. What would my key responsibilities include? This role will be responsible for managing, scheduling and delivering a range of OT cyber security controls to global production sites. You will be knowledgeable about IP networks and cyber security architecture and controls and able to respond to a broad range of technical queries and issues. You will be required to work closely with both the Factory Cyber Security Core Team and Supply Chain Engineering globally. Responsibilities and activities include: • Building relationships with multi-discipline factory and management stakeholders. • Presenting to multi-discipline management stakeholders. • Working knowledge and understanding of OT and IT cyber security technologies. • Working knowledge and understanding of OT and IT cyber security standards and guidelines such as: ISA62443, ISO27001, NIST800-82. • Ability to identify OT security risks and issues and design mitigating controls and solutions. • Proactive management and delivery of OT security workstreams and projects to ensure the following are carried out: o Design and approach of cyber solutions or services to meet requirements. o OT security standards compliance. o Scoping and production of deliverables. o Monitoring OT security KPI's. o Project management. o Review of team deliverables for quality and risk purposes. o Liaising with stakeholders on delivery and implementation issues. o Identifying cyber improvement opportunities. • Developing excellent relationships with colleagues in other areas of the business. • Communicating effectively, in a way that is open, honest, consistent and clear. • Working to deliver an agreed portfolio of projects under the leadership of the Supply Chain, Information Security, and Global Factory Security Lead. • Ensuring professional project execution with strong stakeholder engagement along with a high level of communication to various levels of the organization. • Supporting management to check feasibility of capex projects working collaboratively with Quality, Safety, Manufacturing, Marketing, R&D and plant personnel to clarify the brief, understand work scope, estimate costs and create viable timelines. • Participating and contributing to factory OT governance activities. • Develop Project Execution Plan and schedules. • Execute projects ensuring adherence to schedule and budget. Manage security solution deployments and improvements, contractors, and OEM's ensuring Unilever Security and Safety Standards are applied. • Assist factory with non-capital improvements, identifying enhancements in ways of working to improve line or infrastructure efficiencies. • Assist with the complex controls related cyber troubleshooting, while working with multiple stakeholders to improve OT security skill sets within the factory workforce. • Assist wider projects to ensure legal compliance such as NIS2 • Organize Cyber Awareness- & Training campaigns including Cyber Crisis exercises (Table-Top) What Skills and Experience do I need? • Engineering degree or equivalent experience and recognised peer reviewed cyber security certification. • Project management skills. • Strong communication (verbal and written) and networking skills (interpersonal and planning) • Experience in delivering OT security in an A&C environment within a global manufacturing organisation. • Demonstrable experience of the cyber security issues facing manufacturing organisations and particularly security risk management relating to industrial control systems and Operational Technology. • Strong understanding of legacy A&C concepts and technology and digital OT and Industry 4.0 technology in terms of network infrastructure, integration with business information systems, and the challenges faced from a cyber security perspective. • Strong team focus, communication, relationship building and influencing skills. • Ability to lead teams with internal and external resources. • Strong attention to detail and the ability to deliver projects to the Unilever engineering standards. • Technical subject matter expertise in ICS/OT cyber security architecture and design, installation, configuration and management in manufacturing (preferable food, home care or personal care products). • Good knowledge in Microsoft Power Platform incl. PowerApps, PowerBI & PowerAutomate Essential Experience Required: • Experience with automation equipment and structures • Experience with industrial cyber security controls and good practice • Experience of working in a production environment in a key site role • Strong data networking skills • Strong analytical skills • Ability to work in virtual teams • Ability to build critical skills and develop key talent Areas of Relevant Experience: • Experience in Engineering and Technology with knowledge of manufacturing technologies • Knowledge or familiarity with OT security solutions and technologies such as; IP networks, firewalls, SIEM, remote access control, anti-virus / anti-malware, threat monitoring etc Company overview: Unilever is a global Fast-Moving Consumer Goods company in the UK and Ireland. We are already on target to achieve our huge ambition to double the size of our business globally whilst reducing our environmental impact. We are growing our business and also doing what is right for our consumers, community and environment. We are developing brands for people's lives today and for the changing environment tomorrow - making sustainable living commonplace. Working at Unilever means that you get to take part in this exciting journey and work with amazing people who are really passionate about our large portfolio of famous brands. We want to improve billions of lives and you too can join us in making a sustainable difference. Application process: Please note: As part of the job application, you will be asked to complete a brief online application form. Completion of the form is required in order to be considered. Please allow yourself enough time to complete the application form as when filled out partially or not at all it may adversely affect the progress of your application. Please be aware that you will have to complete the form at once as you will be unable to return to it later. NOTE: Please apply online and add your PDP & Talent Profile if possible. Your application will be reviewed against our requirements and we will be in touch to provide you with an update on the status of your application. By applying for this vacancy, you are confirming that you have made your Line Manager aware of your application and that you are at a point in your career with Unilever where it is appropriate for you to be applying for other positions. Should you require additional information, please contact Tom Baker /Anthony Nichol Unilever is an equal opportunities employer.
Elsevier
Cyber Security BISO: Strategic Risk Partner for Growth
Elsevier
Elsevier is hiring a Cyber Security Business Information Officer (BISO) in the Greater London area. This role focuses on managing security risk, providing expertise in security initiatives, and fostering strong partnerships across business units. Candidates should have extensive experience in cloud security, knowledge of various security tools, and excellent stakeholder management skills. The BISO will oversee security assessments and translate technical findings into actionable plans to ensure cybersecurity maturity. Work involves close collaboration with teams during technology delivery.
10/07/2026
Full time
Elsevier is hiring a Cyber Security Business Information Officer (BISO) in the Greater London area. This role focuses on managing security risk, providing expertise in security initiatives, and fostering strong partnerships across business units. Candidates should have extensive experience in cloud security, knowledge of various security tools, and excellent stakeholder management skills. The BISO will oversee security assessments and translate technical findings into actionable plans to ensure cybersecurity maturity. Work involves close collaboration with teams during technology delivery.
Elsevier
Cyber Security Business Information Officer (BISO)
Elsevier
.Cyber Security Business Information Officer (BISO) page is loaded Cyber Security Business Information Officer (BISO)locations: Oxford: Londontime type: Full timeposted on: Posted Todayjob requisition id: R112581 About Our Team The Business Information Security Office (BISO) team partners with business, product, and technology leaders to deliver measurable security outcomes that support enterprise objectives. We focus on managing complex risk, embedding secure by design practices, and driving long term cybersecurity maturity. Our work enables trusted innovation, operational resilience, and informed risk decision making across the organization. About the Role As a Business Information Security Officer (BISO), you act as the primary security partner for assigned business units, bridging business strategy and enterprise cybersecurity. You are accountable for planning and executing security initiatives that reduce risk, strengthen cyber defenses, and enable delivery at scale. The role is highly collaborative, advisory, and outcome focused-ensuring security is embedded early and pragmatically across products, platforms, and major initiatives. Responsibilities: Act as the primary security partner for assigned business units, building trusted senior stakeholder relationships. Embed security early into business initiatives, product development, and technology delivery. Sponsor and support enterprise and business aligned security initiatives end to end. Provide expert security guidance across concurrent IT, engineering, and business projects. Oversee security assessments including vulnerability management, penetration testing, and third party risk. Translate security findings into prioritized, actionable remediation plans with clear ownership. Provide security input into solution architecture and major technology decisions. Serve as the security point of contact for customer facing inquiries, audits, and due diligence. Identify, document, and govern cyber risks, supporting risk acceptance and escalation processes. Develop and report meaningful security metrics to inform leadership decisions and continuous improvement. Requirements: Several years' experience in a BISO or senior security leadership / advisory role. Strong cloud and application security experience (AWS, Azure, GCP; secure SDLC). Hands on knowledge of security tooling (SIEM, SOAR, EDR/XDR, CSPM, SAST/DAST). Experience embedding security into CI/CD pipelines and DevSecOps practices. Proven capability in risk assessments, threat modeling, and control gap analysis. Experience collaborating with SOC and Incident Response teams during security events. Working knowledge of security frameworks and regulations (NIST, ISO 27001, CIS, GDPR, etc.). Ability to translate technical risk into clear, business relevant language. Strong stakeholder management skills with the ability to influence without authority. Bachelor's degree in Engineering, Computer Science, or equivalent experience, plus relevant certifications (CISSP, CISM, GIAC, or similar). We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click to access benefits specific to your location. We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our or please contact 1-. Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams . Please read our .We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law. USA Job Seekers: .Elsevier is a global leader in advanced information and decision support for science and healthcare. We believe that by working together with the communities we serve, we can shape human progress to go further, happen faster, and benefit all.We support continuous discovery and uphold the highest standards of content integrity, reliability, and reproducibility so the communities we serve can advance their field of science, healthcare or innovation with confidence. By combining high-quality content with powerful analytics, we transform complexity into clarity and deliver mission-critical insights that help professionals make better decisions when it matters most.We deliver insights that help research institutions, governments, and funders achieve their goals. We help researchers discover and share knowledge, collaborate, and accelerate innovation. We help librarians provide verified, quality information to universities. We help innovators turn knowledge into new products. We help health professionals improve patient care and educators train the next generation of doctors and nurses. Connecting quality content and innovative technologies, we make progress go further and happen faster. And by championing inclusion and sustainability, we ensure progress benefits all.With 9,500 employees, over 2,300 technologists in 5 major tech hubs, and more than 60 locations across the globe, we are committed to supporting the scientific and healthcare communities around the world. We offer a diverse range of opportunities across technology, commercial, business, and early career jobs. If you are looking for a career that inspires progress in science, innovation and health, and allows you to grow every day, find your team at Elsevier.Elsevier is part of RELX Group.Let's shape progress together. Join
10/07/2026
Full time
.Cyber Security Business Information Officer (BISO) page is loaded Cyber Security Business Information Officer (BISO)locations: Oxford: Londontime type: Full timeposted on: Posted Todayjob requisition id: R112581 About Our Team The Business Information Security Office (BISO) team partners with business, product, and technology leaders to deliver measurable security outcomes that support enterprise objectives. We focus on managing complex risk, embedding secure by design practices, and driving long term cybersecurity maturity. Our work enables trusted innovation, operational resilience, and informed risk decision making across the organization. About the Role As a Business Information Security Officer (BISO), you act as the primary security partner for assigned business units, bridging business strategy and enterprise cybersecurity. You are accountable for planning and executing security initiatives that reduce risk, strengthen cyber defenses, and enable delivery at scale. The role is highly collaborative, advisory, and outcome focused-ensuring security is embedded early and pragmatically across products, platforms, and major initiatives. Responsibilities: Act as the primary security partner for assigned business units, building trusted senior stakeholder relationships. Embed security early into business initiatives, product development, and technology delivery. Sponsor and support enterprise and business aligned security initiatives end to end. Provide expert security guidance across concurrent IT, engineering, and business projects. Oversee security assessments including vulnerability management, penetration testing, and third party risk. Translate security findings into prioritized, actionable remediation plans with clear ownership. Provide security input into solution architecture and major technology decisions. Serve as the security point of contact for customer facing inquiries, audits, and due diligence. Identify, document, and govern cyber risks, supporting risk acceptance and escalation processes. Develop and report meaningful security metrics to inform leadership decisions and continuous improvement. Requirements: Several years' experience in a BISO or senior security leadership / advisory role. Strong cloud and application security experience (AWS, Azure, GCP; secure SDLC). Hands on knowledge of security tooling (SIEM, SOAR, EDR/XDR, CSPM, SAST/DAST). Experience embedding security into CI/CD pipelines and DevSecOps practices. Proven capability in risk assessments, threat modeling, and control gap analysis. Experience collaborating with SOC and Incident Response teams during security events. Working knowledge of security frameworks and regulations (NIST, ISO 27001, CIS, GDPR, etc.). Ability to translate technical risk into clear, business relevant language. Strong stakeholder management skills with the ability to influence without authority. Bachelor's degree in Engineering, Computer Science, or equivalent experience, plus relevant certifications (CISSP, CISM, GIAC, or similar). We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click to access benefits specific to your location. We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our or please contact 1-. Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams . Please read our .We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law. USA Job Seekers: .Elsevier is a global leader in advanced information and decision support for science and healthcare. We believe that by working together with the communities we serve, we can shape human progress to go further, happen faster, and benefit all.We support continuous discovery and uphold the highest standards of content integrity, reliability, and reproducibility so the communities we serve can advance their field of science, healthcare or innovation with confidence. By combining high-quality content with powerful analytics, we transform complexity into clarity and deliver mission-critical insights that help professionals make better decisions when it matters most.We deliver insights that help research institutions, governments, and funders achieve their goals. We help researchers discover and share knowledge, collaborate, and accelerate innovation. We help librarians provide verified, quality information to universities. We help innovators turn knowledge into new products. We help health professionals improve patient care and educators train the next generation of doctors and nurses. Connecting quality content and innovative technologies, we make progress go further and happen faster. And by championing inclusion and sustainability, we ensure progress benefits all.With 9,500 employees, over 2,300 technologists in 5 major tech hubs, and more than 60 locations across the globe, we are committed to supporting the scientific and healthcare communities around the world. We offer a diverse range of opportunities across technology, commercial, business, and early career jobs. If you are looking for a career that inspires progress in science, innovation and health, and allows you to grow every day, find your team at Elsevier.Elsevier is part of RELX Group.Let's shape progress together. Join
Vice President, Business Information Security Officer
MUFG Bank, Ltd
Vice President, Business Information Security OfficerApplylocations: Londontime type: Full timeposted on: Posted Todayjob requisition id: -WD Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.Corporate Technology is accountable for the operation, development and support of all applications across all areas of the business. Corporate Technology ensures IT strategy, architecture and solutions are aligned to business requirements. The BISO role is part of the IT Security team. IT Security are collectively responsible for the following areas: Cyber Support and Engineering, Security Operations Centre covering pen tests, red and blue teams, Cyber and Risk Change portfolio, Threat Intelligence and Vulnerability Management for the Group and Identity and Access Management. NUMBER OF DIRECT REPORTS 2 MAIN PURPOSE OF THE ROLE Responsible for providing strategic information security leadership and oversight across all business units in the region. This role bridges global security strategy and regional business execution, ensuring that security, risk, and compliance objectives are effectively implemented, measured, and governed.The position partners closely with regional executives, technology leadership, and global security functions to embed a culture of security, drive control adoption, and maintain regulatory confidence.This role will work alongside the EMEA regional CISO on supporting the strategy, initiatives and roadmap for information security in MUFG EMEA. Working with key stakeholders internally to help embed security into the culture, whilst embedding technical controls into the mission critical business systems:Risk Advisory & Control Adoption Serve as the trusted advisor to business and technology units on security risks and control implementation. Support adoption of global security controls and standards within regional operations. Provide security input on new business initiatives, digital transformation, and third-party relationships.2. Security Training & Awareness Develop, tailor, and oversee delivery of security awareness programs by business line. Drive execution of phishing simulations and targeted learning interventions. Measure awareness effectiveness and report to management.3. Security Champion Network Establish and maintain a regional security champion community within business and operations teams. Promote local ownership of security best practices and risk reduction initiatives. Provide ongoing engagement, training, and recognition programs for champions.4. Security Strategy, Planning & Reporting Translate global and regional security objectives into actionable EMEA programs. Develop strategic plans, key risk metrics (KRIs/KPIs), and executive dashboards. Contribute to quarterly and annual reporting cycles for CISO and business leadership.5. Finance, Budgeting & Resourcing Support regional security budgeting, forecasting, and resource allocation. Track spend against plan and provide variance analysis. Assist in developing business cases for new initiatives or investments.6. Security Program Governance Oversee the implementation and governance of global security programs in EMEA. Ensure adherence to enterprise security policies and frameworks. Coordinate across multiple stakeholders to maintain governance and accountability.7. Risk, Compliance & Audit Coordination Act as the single point of contact for IT Security related audits and compliance engagements. Manage audit readiness, evidence coordination, and remediation tracking. Maintain strong relationships with internal audit, compliance, and regulatory teams.8. Reporting & Global/Regional Coordination Coordinate EMEA security reporting and represent the region in global BISO forums. Ensure consistency of risk posture and alignment with global metrics and governance. Provide regional input into global policy updates and program design. KEY RESPONSIBILITIES Communication & Training Manage the Cyber & Risk training program. Ensuring Cyber integration with the business and technology. Communicating Risk & Cyber information across Bank EMEA and Securities. Be an escalation point for concerns about IT Security. Be a positive collaborator. People Management Ensure that the function is appropriately organised and adequately resourced by staff with appropriate skillsets to achieve its strategic objectives. Lead, direct and manage staff within the function to ensure that they: + Understand the responsibilities applicable to their roles + Comply with the firm's policies and procedures + Conduct themselves in a manner commensurate with the firm's values Actively manage performance, develop talent, identify key positions and persons and create sustainable success plans. Oversee appropriate training is in place to fulfil current and future skill requirements. Culture and Leadership Actively lead the integration of Bank and Securities technology functions. Promote the MUFG values-led culture which is inclusive and diverse. Promote a dynamic, delivery driven culture that works alongside business units to provide responsive resolutions and value driven solutions. Collective leadership by example on staff cyber education and awareness to embed a proactive cyber culture. Find ways to strengthen working relationships with stakeholders, including business teams. Lead by example in building relationships across the bank, establishing a stronger peer network and helping to strengthen collaboration. Build strong relationships with internal and external stakeholders to understand industry best practice, influence change and promote technical credibility. WORK EXPERIENCE Experienced in information security, technology risk, or related disciplines within financial services sector. Experienced in IT security and control policy with specific experience of FFEIC, SOX, COBIT, NIST, CRI Profile and ISO standards. Conversant in the security & risk trends across banking and other industries. Experienced with the Defence in Depth approach Strong track record of managing teams and building effective partnerships with peers. Strong experience in delivering training Professional information security certifications (i.e. CISSP, CISM, CRISC or similar experience). Cloud Security experience and a good understanding of privacy legislation (Data Protection Act 2018 / GDPR). SKILLS AND EXPERIENCE Functional / Technical Competencies: Strong strategic and analytical thinking. Excellent communication and stakeholder management. Proven ability to balance technical, business, and regulatory priorities. Collaborative, pragmatic, and outcomes-driven leadership style. A deep understanding of IT and Cyber Security: + Defence in Depth model. + Network defence, IDS and DMZ + Network protocols and firewall standards + Detective monitoring - SIEM + Vulnerability Management + Access and Privileged Access Management Experienced in writing and maintaining IT documents, such as standards and procedures. Demonstrates an understanding of strategic business and IT issues impacting the financial services market. Strong understanding of risk and its application across technology and the business. Good understanding of project lifecycles. Education / Qualifications: Degree educated and / or equivalent experience. PERSONAL REQUIREMENTS Excellent Leadership skills Excellent communication skills Ability to manage constructive conflict effectively Strong facilitation skills Ability to build strong and lasting relationships across the bank Results driven, with a strong sense of accountability, focused on business outcomes A proactive, motivated approach. The ability to operate with urgency and prioritise work accordingly Strong decision-making skills, the ability to demonstrate sound judgement A structured and logical approach to work Strong problem-solving skills A creative and innovative approach to work Excellent interpersonal skills Excellent attention to detail and accuracy Strong numerical skills A confident approach, with the ability to provide clear direction to your team Excellent managerial/leadership experience The ability to articulate and implement the vision/strategy for the planning departmentWe are open to considering flexible working requests in line with organisational requirements.
02/07/2026
Full time
Vice President, Business Information Security OfficerApplylocations: Londontime type: Full timeposted on: Posted Todayjob requisition id: -WD Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.Corporate Technology is accountable for the operation, development and support of all applications across all areas of the business. Corporate Technology ensures IT strategy, architecture and solutions are aligned to business requirements. The BISO role is part of the IT Security team. IT Security are collectively responsible for the following areas: Cyber Support and Engineering, Security Operations Centre covering pen tests, red and blue teams, Cyber and Risk Change portfolio, Threat Intelligence and Vulnerability Management for the Group and Identity and Access Management. NUMBER OF DIRECT REPORTS 2 MAIN PURPOSE OF THE ROLE Responsible for providing strategic information security leadership and oversight across all business units in the region. This role bridges global security strategy and regional business execution, ensuring that security, risk, and compliance objectives are effectively implemented, measured, and governed.The position partners closely with regional executives, technology leadership, and global security functions to embed a culture of security, drive control adoption, and maintain regulatory confidence.This role will work alongside the EMEA regional CISO on supporting the strategy, initiatives and roadmap for information security in MUFG EMEA. Working with key stakeholders internally to help embed security into the culture, whilst embedding technical controls into the mission critical business systems:Risk Advisory & Control Adoption Serve as the trusted advisor to business and technology units on security risks and control implementation. Support adoption of global security controls and standards within regional operations. Provide security input on new business initiatives, digital transformation, and third-party relationships.2. Security Training & Awareness Develop, tailor, and oversee delivery of security awareness programs by business line. Drive execution of phishing simulations and targeted learning interventions. Measure awareness effectiveness and report to management.3. Security Champion Network Establish and maintain a regional security champion community within business and operations teams. Promote local ownership of security best practices and risk reduction initiatives. Provide ongoing engagement, training, and recognition programs for champions.4. Security Strategy, Planning & Reporting Translate global and regional security objectives into actionable EMEA programs. Develop strategic plans, key risk metrics (KRIs/KPIs), and executive dashboards. Contribute to quarterly and annual reporting cycles for CISO and business leadership.5. Finance, Budgeting & Resourcing Support regional security budgeting, forecasting, and resource allocation. Track spend against plan and provide variance analysis. Assist in developing business cases for new initiatives or investments.6. Security Program Governance Oversee the implementation and governance of global security programs in EMEA. Ensure adherence to enterprise security policies and frameworks. Coordinate across multiple stakeholders to maintain governance and accountability.7. Risk, Compliance & Audit Coordination Act as the single point of contact for IT Security related audits and compliance engagements. Manage audit readiness, evidence coordination, and remediation tracking. Maintain strong relationships with internal audit, compliance, and regulatory teams.8. Reporting & Global/Regional Coordination Coordinate EMEA security reporting and represent the region in global BISO forums. Ensure consistency of risk posture and alignment with global metrics and governance. Provide regional input into global policy updates and program design. KEY RESPONSIBILITIES Communication & Training Manage the Cyber & Risk training program. Ensuring Cyber integration with the business and technology. Communicating Risk & Cyber information across Bank EMEA and Securities. Be an escalation point for concerns about IT Security. Be a positive collaborator. People Management Ensure that the function is appropriately organised and adequately resourced by staff with appropriate skillsets to achieve its strategic objectives. Lead, direct and manage staff within the function to ensure that they: + Understand the responsibilities applicable to their roles + Comply with the firm's policies and procedures + Conduct themselves in a manner commensurate with the firm's values Actively manage performance, develop talent, identify key positions and persons and create sustainable success plans. Oversee appropriate training is in place to fulfil current and future skill requirements. Culture and Leadership Actively lead the integration of Bank and Securities technology functions. Promote the MUFG values-led culture which is inclusive and diverse. Promote a dynamic, delivery driven culture that works alongside business units to provide responsive resolutions and value driven solutions. Collective leadership by example on staff cyber education and awareness to embed a proactive cyber culture. Find ways to strengthen working relationships with stakeholders, including business teams. Lead by example in building relationships across the bank, establishing a stronger peer network and helping to strengthen collaboration. Build strong relationships with internal and external stakeholders to understand industry best practice, influence change and promote technical credibility. WORK EXPERIENCE Experienced in information security, technology risk, or related disciplines within financial services sector. Experienced in IT security and control policy with specific experience of FFEIC, SOX, COBIT, NIST, CRI Profile and ISO standards. Conversant in the security & risk trends across banking and other industries. Experienced with the Defence in Depth approach Strong track record of managing teams and building effective partnerships with peers. Strong experience in delivering training Professional information security certifications (i.e. CISSP, CISM, CRISC or similar experience). Cloud Security experience and a good understanding of privacy legislation (Data Protection Act 2018 / GDPR). SKILLS AND EXPERIENCE Functional / Technical Competencies: Strong strategic and analytical thinking. Excellent communication and stakeholder management. Proven ability to balance technical, business, and regulatory priorities. Collaborative, pragmatic, and outcomes-driven leadership style. A deep understanding of IT and Cyber Security: + Defence in Depth model. + Network defence, IDS and DMZ + Network protocols and firewall standards + Detective monitoring - SIEM + Vulnerability Management + Access and Privileged Access Management Experienced in writing and maintaining IT documents, such as standards and procedures. Demonstrates an understanding of strategic business and IT issues impacting the financial services market. Strong understanding of risk and its application across technology and the business. Good understanding of project lifecycles. Education / Qualifications: Degree educated and / or equivalent experience. PERSONAL REQUIREMENTS Excellent Leadership skills Excellent communication skills Ability to manage constructive conflict effectively Strong facilitation skills Ability to build strong and lasting relationships across the bank Results driven, with a strong sense of accountability, focused on business outcomes A proactive, motivated approach. The ability to operate with urgency and prioritise work accordingly Strong decision-making skills, the ability to demonstrate sound judgement A structured and logical approach to work Strong problem-solving skills A creative and innovative approach to work Excellent interpersonal skills Excellent attention to detail and accuracy Strong numerical skills A confident approach, with the ability to provide clear direction to your team Excellent managerial/leadership experience The ability to articulate and implement the vision/strategy for the planning departmentWe are open to considering flexible working requests in line with organisational requirements.
Business Information Security Officer (BISO) - Cyber GRC Associate London, GBR Posted yesterday
BLOOMBERG L.P.
Business Information Security Officer (BISO) - Cyber GRC Associate Location London Business Area Legal, Compliance, and Risk Ref # Description & Requirements Our Team We protect Bloomberg. The Bloomberg Information Security Office team is dedicated to making our products and technologies as secure as possible through design, development, and operation. We report into the Chief Information Security Office while working closely with regulated businesses, key lines of business, and development/engineering across Bloomberg L.P. Our colleagues depend on us to help design, run, and improve our most important security programs - strengthening our cyber resilience and security posture across an evolving threat landscape. What's in it for you The Bloomberg BISO team focuses on identifying opportunities to improve the security of Bloomberg, our products and services, and the security of our customers' data. In this role, you will contribute to the development and execution of multiple security and cyber GRC programs, each with unique challenges and in a global setting. You will play a key role in supporting cyber risk governance, evangelizing security and compliance efforts, and helping to shape the direction of Bloomberg L.P.'s business efforts - all in a day's work. We'll trust you to Build a strong understanding of your business domains, staying current with new technologies, the evolving threat landscape, regulatory changes, and industry best practices as you support and contribute to the information security and cyber GRC programs for your lines of business. Work with stakeholders to effectively manage cyber risk including supporting the assessment of security controls, risk identification, mitigation strategies, and incident response planning. Build cross-functional relationships between teams to improve all aspects of our security program, contributing to a culture of security by design and continuous compliance. Support the development of management information, including key risk indicators, program maturity indicators, and key performance indicators to enable data-driven risk reporting. Contribute to the review and maintenance of information security policies, standards, and procedures in your line of business - ensuring alignment with the firm's risk appetite and regulatory obligations. Develop into a trusted advisor to management, supporting the reporting of information security programs, cyber risk posture, and GRC maturity to governance forums. Support the development and delivery of scenario testing such as Tabletop Exercises and Threat Led Penetration Testing to validate our cyber resilience. Support remediation efforts and contribute to transformational change initiatives across the broader organization, including zero trust adoption, third-party risk management, and operational resilience programs. We'd love to see 3-5 years of experience in information security, cyber GRC, cyber security risk management, data security, or cyber security regulation. Demonstrated ability to work effectively with stakeholders across a complex, global, and highly regulated environment. Experience contributing to cross-functional projects with a strong attention to detail and follow-through. Ability to identify and elevate cyber security risks - including third-party and supply chain risk - and support the delivery of services in a secure and compliant way. Solid foundational knowledge across key cyber security domains such as cloud security, network security and architecture, application security, secure software development lifecycle (SSDLC), or vulnerability management. Familiarity with Threat Led Penetration Testing (TLPT) frameworks such as CBEST or equivalent TLPT regimes. Familiarity with key technologies such as Operating Systems, Software Development Build Pipelines and Processes, Security Tooling, O365 Suite, and Business Intelligence Tools. Exposure to industry standards and frameworks such as NIST CSF, ISO 27001, or cyber risk quantification methodologies. Awareness of regulation pertaining to Information Security such as DORA, Operational Resilience, UK CTP Regime, and GDPR. Strong written and oral communication skills, with a desire to develop the ability to translate cyber risk into clear business language. Demonstrated ability to perform under pressure and consistently meet deadlines. An industry recognized certification such as CISSP, CISM, CRISC, CompTIA Security+, or ISO 27001 Lead Implementor/Auditor - or working towards one. If This Sounds Like You Apply if you think we're a good match. We'll get in touch to let you know what the next steps are, but in the meantime feel free to have a look at: If indicated, please note that years of experience are a guide; we will consider applications from all candidates who can demonstrate the skills necessary for the role. Discover what makes Bloomberg unique - watch our podcast series for an inside look at our culture, values, and the people behind our success. Bloomberg is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy or parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law. Bloomberg is a disability inclusive employer. Please let us know if you require any reasonable adjustments to be made for the recruitment process. If you would prefer to discuss this confidentially, please email
02/07/2026
Full time
Business Information Security Officer (BISO) - Cyber GRC Associate Location London Business Area Legal, Compliance, and Risk Ref # Description & Requirements Our Team We protect Bloomberg. The Bloomberg Information Security Office team is dedicated to making our products and technologies as secure as possible through design, development, and operation. We report into the Chief Information Security Office while working closely with regulated businesses, key lines of business, and development/engineering across Bloomberg L.P. Our colleagues depend on us to help design, run, and improve our most important security programs - strengthening our cyber resilience and security posture across an evolving threat landscape. What's in it for you The Bloomberg BISO team focuses on identifying opportunities to improve the security of Bloomberg, our products and services, and the security of our customers' data. In this role, you will contribute to the development and execution of multiple security and cyber GRC programs, each with unique challenges and in a global setting. You will play a key role in supporting cyber risk governance, evangelizing security and compliance efforts, and helping to shape the direction of Bloomberg L.P.'s business efforts - all in a day's work. We'll trust you to Build a strong understanding of your business domains, staying current with new technologies, the evolving threat landscape, regulatory changes, and industry best practices as you support and contribute to the information security and cyber GRC programs for your lines of business. Work with stakeholders to effectively manage cyber risk including supporting the assessment of security controls, risk identification, mitigation strategies, and incident response planning. Build cross-functional relationships between teams to improve all aspects of our security program, contributing to a culture of security by design and continuous compliance. Support the development of management information, including key risk indicators, program maturity indicators, and key performance indicators to enable data-driven risk reporting. Contribute to the review and maintenance of information security policies, standards, and procedures in your line of business - ensuring alignment with the firm's risk appetite and regulatory obligations. Develop into a trusted advisor to management, supporting the reporting of information security programs, cyber risk posture, and GRC maturity to governance forums. Support the development and delivery of scenario testing such as Tabletop Exercises and Threat Led Penetration Testing to validate our cyber resilience. Support remediation efforts and contribute to transformational change initiatives across the broader organization, including zero trust adoption, third-party risk management, and operational resilience programs. We'd love to see 3-5 years of experience in information security, cyber GRC, cyber security risk management, data security, or cyber security regulation. Demonstrated ability to work effectively with stakeholders across a complex, global, and highly regulated environment. Experience contributing to cross-functional projects with a strong attention to detail and follow-through. Ability to identify and elevate cyber security risks - including third-party and supply chain risk - and support the delivery of services in a secure and compliant way. Solid foundational knowledge across key cyber security domains such as cloud security, network security and architecture, application security, secure software development lifecycle (SSDLC), or vulnerability management. Familiarity with Threat Led Penetration Testing (TLPT) frameworks such as CBEST or equivalent TLPT regimes. Familiarity with key technologies such as Operating Systems, Software Development Build Pipelines and Processes, Security Tooling, O365 Suite, and Business Intelligence Tools. Exposure to industry standards and frameworks such as NIST CSF, ISO 27001, or cyber risk quantification methodologies. Awareness of regulation pertaining to Information Security such as DORA, Operational Resilience, UK CTP Regime, and GDPR. Strong written and oral communication skills, with a desire to develop the ability to translate cyber risk into clear business language. Demonstrated ability to perform under pressure and consistently meet deadlines. An industry recognized certification such as CISSP, CISM, CRISC, CompTIA Security+, or ISO 27001 Lead Implementor/Auditor - or working towards one. If This Sounds Like You Apply if you think we're a good match. We'll get in touch to let you know what the next steps are, but in the meantime feel free to have a look at: If indicated, please note that years of experience are a guide; we will consider applications from all candidates who can demonstrate the skills necessary for the role. Discover what makes Bloomberg unique - watch our podcast series for an inside look at our culture, values, and the people behind our success. Bloomberg is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy or parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law. Bloomberg is a disability inclusive employer. Please let us know if you require any reasonable adjustments to be made for the recruitment process. If you would prefer to discuss this confidentially, please email
Cyber GRC BISO Associate - Security Risk & Compliance
BLOOMBERG L.P.
Bloomberg L.P. is seeking a Business Information Security Officer (BISO) - Cyber GRC Associate in London. In this role, you will help develop and execute security programs vital for protecting Bloomberg's data and resources while enhancing our compliance posture. Your responsibilities will include managing cyber risks, developing security policies, and building strong cross-functional relationships. Ideal candidates will have 3-5 years of experience in information security, solid cybersecurity knowledge, and industry-recognized certifications.
02/07/2026
Full time
Bloomberg L.P. is seeking a Business Information Security Officer (BISO) - Cyber GRC Associate in London. In this role, you will help develop and execute security programs vital for protecting Bloomberg's data and resources while enhancing our compliance posture. Your responsibilities will include managing cyber risks, developing security policies, and building strong cross-functional relationships. Ideal candidates will have 3-5 years of experience in information security, solid cybersecurity knowledge, and industry-recognized certifications.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board