Talent.com
Bloomberg
Business Information Security Officer (BISO) Cyber GRC AssociateBloomberg • London, England, UK
Business Information Security Officer (BISO) Cyber GRC Associate

Business Information Security Officer (BISO) Cyber GRC Associate

Bloomberg • London, England, UK
27 days ago
Job type
  • Full-time
Job description
Business Information Security Officer (BISO) - Cyber GRC Associate Location London Business Area Legal Compliance and Risk Ref #

Description & Requirements

Our Team:

We protect Bloomberg. The Bloomberg Information Security Office team is dedicated to making our products and technologies as secure as possible through design development and operation. We report into the Chief Information Security Office while working closely with regulated businesses key lines of business and development/engineering across Bloomberg L.P. Our colleagues depend on us to help design run and improve our most important security programs strengthening our cyber resilience and security posture across an evolving threat landscape.

Whatsin it for you:

The Bloomberg BISO team focuses onidentifyingopportunities to improve the security of Bloomberg our products and services and the security of our customers this role you will contribute to the development and execution of multiple security and cyber GRC programs each with unique challenges and in a global setting. You will play a key role in supporting cyber risk governance evangelizingsecurityand compliance efforts and helping to shape the direction of Bloomberg L.P.s business efforts - all in a days work.

Welltrust you to:

  • Build a strong understanding of your business domains staying current withnew technologies the evolving threat landscape regulatory changes and industry best practices as you support and contribute to the information security and cyber GRC programs for your lines of business.
  • Work with stakeholders to effectively manage cyberriskincluding supporting the assessment of security controls risk identification mitigation strategies and incident response planning.
  • Build cross-functional relationships between teams to improve all aspects of our security program contributing to a culture of security by design and continuous compliance.
  • Support the development of management information including key risk indicators program maturity indicators and key performance indicators to enable data-driven risk reporting.
  • Contribute to the review and maintenance of information security policies standards and procedures in your line of business - ensuring alignment with the firms risk appetite and regulatory obligations.
  • Develop into a trusted advisor to management supporting the reporting of information security programs cyber risk posture and GRC maturity to governance forums.
  • Support the development and delivery of scenario testing such as Tabletop Exercises and Threat Led Penetration Testing tovalidateour cyber resilience.
  • Support remediation efforts and contribute to transformational change initiatives across the broader organization including zero trust adoption third-party risk management and operational resilience programs.

Wedlove to see:

  • 3-5 years of experience in information security cyber GRC cyber security risk management data security or cyber security regulation.
  • Demonstrated ability to work effectively with stakeholders across a complex global and highly regulated environment.
  • Experience contributing to cross-functional projects with a strong attention to detail and follow-through.
  • Ability toidentifyand escalate cyber security risks including third-party and supply chain risk and support the delivery of services in a secure and compliant way.
  • Solid foundational knowledge across key cyber security domains such as cloud security network security and architecture application security secure software development lifecycle (SSDLC) or vulnerability management.
  • Familiarity with Threat Led Penetration Testing (TLPT) frameworks such as CBEST or equivalent TLPT regimes.
  • Familiarity with key technologies such as Operating Systems Software Development Build Pipelines and Processes Security Tooling O365 Suite and Business Intelligence Tools.
  • Exposure toindustry standards and frameworks such as NIST CSF ISO 27001 or cyber risk quantification methodologies.
  • Awareness ofregulationpertaining toInformation Security such as DORA Operational Resilience UK CTP Regime and GDPR.
  • Strong written and oral communication skills with a desire to develop the ability to translate cyber risk into clear business language.
  • Demonstrated ability to perform under pressure and consistently meet deadlines.
  • An industry recognized certification such as CISSP CISM CRISC CompTIA Security or ISO 27001 Lead Implementor/Auditor or working towards one.

If This Sounds Like You:

Apply if you thinkwerea good in touch to let you know what the next steps are but in the meantime feel free to have a look at:

Ifindicated please note that years of experience are a guide; we will consider applications from all candidates who candemonstratethe skills necessary for the role.

Discover what makes Bloomberg unique watch our podcast series for an inside look at our culture values and the people behind our success.



If indicated please note that years of experience are a guide; we will consider applications from all candidates who can demonstrate the skills necessary for the role. Discover what makes Bloomberg unique - watch our podcast series for an inside look at our culture values and the people behind our success.

Required Experience:

IC


Employment Type : Full Time
Experience: years
Vacancy: 1
Create a job alert for this search

Business Information Security Officer (BISO) Cyber GRC Associate • London, England, UK

Similar jobs

Information Security & GRC Lead (Hybrid)

AppyWayGreater London, England, GB
Full-time

AppyWay is seeking a seasoned Information Security leader to drive the implementation and governance of security across the business.You will manage ISO27001, PCI DSS, Cyber Essentials, and related... Show more

 • Promoted

Cyber Security Auditor

DGH RecruitmentCity, London, GB
Full-time

DGH Recruitment are currently recruiting on behalf of a leading client in the Accountancy industry who require a Cyber Security Auditor to join the firm in London.Lead and support the delivery of c... Show more

 • Promoted

Information Security GRC Engineering Consultant

VisaGreater London, England, GB
Full-time

Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories,... Show more

 • Promoted

SC Cleared Cyber Security Roles – Public Sector Opportunities

Solirius ReplyGreater London, England, GB
Full-time

A leading technology consulting firm in the UK is seeking candidates passionate about cyber security for roles in the Public Sector.Applicants should have SC Clearance and can include Business Anal... Show more

 • Promoted

Information Security Engineer - GRC

ICEGreater London, England, GB
Full-time

The Engineer, Information Security GRC (Governance, Risk, and Compliance) is part of a team responsible for the global Information Security program.The role would gain exposure to the full suite of... Show more

 • Promoted

Director, Information Cyber Security - Business Management

CLS-GroupGreater London, England, United Kingdom
Full-time

CLS is the trusted party at the centre of the global FX ecosystem.Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective.Trillions of dollars' worth of curren... Show more

 • Promoted

BISO | Security Strategy & Risk Lead (Hybrid)

RSM UK Deal ServicesGreater London, England, GB
Full-time

RSM UK Deal Services is searching for a Business Information Security Officer in Greater London to oversee the Information Security Management System (ISMS) and implement essential security protoco... Show more

 • Promoted

SAP Security & GRC Lead

PRIMA PartnersGreater London, England, GB
Full-time

ESSENTIAL SKILLS | SAP Security & GRC Lead.Fluent English language skills (Written & Verbal).Proven expertise in SAP Security architecture and GRC solutions (SAP Access Control, Identity Access Gov... Show more

 • Promoted

Cyber Security Consulting Lead: NIST & Cloud Risk

慨正橡扯Greater London, England, GB
Full-time

QBE Europe is seeking a Cyber Security Consulting Lead to join our London office.You will provide security technology assessments and integration guidance for IT change projects, using a Secure Des... Show more

 • Promoted

Cyber Security Business Information Officer (BISO)

LexisNexis Risk SolutionsGreater London, England, GB
Full-time

Cyber Security Business Information Officer (BISO) page is loaded## Cyber Security Business Information Officer (BISO)locations: Oxford: Londontime type: Full timeposted on: Posted Todayjob... Show more

 • Promoted

Information Security GRC Analyst - Hybrid

RSM UKGreater London, England, GB
Full-time

RSM UK is seeking an experienced Information Security GRC Analyst to join the National Technology team.The role supports governance, risk, and compliance across the organisation, developing and mai... Show more

 • Promoted

InfoSec GRC Analyst — ISO 27001 & Risk Management

Description ThisGreater London, England, GB
Full-time

Description This is seeking an Information Security GRC professional in Greater London.This full-time role offers a salary range of £40,000 to £42,500 and requires a Bachelor’s degree along with pr... Show more

 • Promoted

BISO Lead: Cyber Risk & Business Security Partner (Hybrid)

La FosseGreater London, England, GB
Full-time

A leading global telecom company is seeking a Business Information Security Offer (BISO) based in the UK.The successful candidate will play a crucial role in driving information security and managi... Show more

 • Promoted

GRC Information Security Analyst II - Risk & Compliance Lead

Checkout LtdGreater London, England, GB
Full-time

Checkout Ltd is seeking an Information Security Analyst II to lead governance, risk, and compliance activities.You will manage GRC programmes including PCI DSS, ISO 27001, and SOC 2, ensuring robus... Show more

 • Promoted

Security & Compliance Lead - GRC, ISO 27001 & TPRM

PEI GroupGreater London, England, GB
Full-time

PEI Group is seeking an Information Security & Compliance Officer based in Greater London.This role is pivotal in coordinating security activities, supporting compliance initiatives, and managing t... Show more

 • Promoted

Manager, Cyber Security, Identity, TC UKI

EYGreater London, England, GB
Full-time

At EY, we’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.Cyber security and its related challenges are a rapidly growing fie... Show more

 • Promoted

Cyber Security & Trust, Vice President

CapgeminiGreater London, England, United Kingdom
Permanent

Cyber Security & Trust, Vice President.At Capgemini Invent, we believe difference drives change.As inventive transformation consultants, we blend our strategic, creative and scientific capabilities... Show more

 • Promoted

BISO: Shape Cyber Resilience & Risk Governance

Harrington StarrGreater London, England, GB
Full-time

Harrington Starr is seeking a Business Information Security Officer (BISO) located in the City of London with a hybrid work model.This role involves collaborating with the Head of Information Secur... Show more

 • Promoted

Engineer, Information Security GRC

ICE Clear Europe LimitedGreater London, England, GB
Full-time

The Engineer, Information Security GRC (Governance, Risk, and Compliance) is part of a team responsible for the global Information Security program.The role would gain exposure to the full suite of... Show more

 • Promoted

DV Cleared – Cyber GRC Manager – Inside IR36

Cyber UKGreater London, England, GB
Full-time

Initial 6 months (High likelihood of extension).Cyber Security Governance & Risk Management specialist, accountable for ensuring cyber security governance and risk management is embedded across the... Show more