×
Register Here to Apply for Jobs or Post Jobs. X

Business Information Security Officer; BISO) Cyber GRC Associate

Job in London, Greater London, W1B, England, UK
Listing for: Bloomberg
Full Time position
Listed on 2026-09-01
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Job Description & How to Apply Below
Position: Business Information Security Officer (BISO) Cyber GRC Associate

Business Information Security Officer (BISO) - Cyber GRC Associate

Location

London

Business Area

Legal Compliance and Risk

#

Description & Requirements

Our Team:

We protect Bloomberg. The Bloomberg Information Security Office team is dedicated to making our products and technologies as secure as possible through design development and operation. We report into the Chief Information Security Office while working closely with regulated businesses key lines of business and development/engineering across Bloomberg L.P. Our colleagues depend on us to help design run and improve our most important security programs strengthening our cyber resilience and security posture across an evolving threat landscape.

Whatsin it for you:

The Bloomberg BISO team focuses onidentifyingopportunities to improve the security of Bloomberg our products and services and the security of our customers this role you will contribute to the development and execution of multiple security and cyber GRC programs each with unique challenges and in a global setting. You will play a key role in supporting cyber risk governance evangelizingsecurityand compliance efforts and helping to shape the direction of Bloomberg L.P.s business efforts - all in a days work.

Welltrust you to:

  • Build a strong understanding of your business domains staying current withnew technologies the evolving threat landscape regulatory changes and industry best practices as you support and contribute to the information security and cyber GRC programs for your lines of business.
  • Work with stakeholders to effectively manage cyberriskincluding supporting the assessment of security controls risk identification mitigation strategies and incident response planning.
  • Build cross-functional relationships between teams to improve all aspects of our security program contributing to a culture of security by design and continuous compliance.
  • Support the development of management information including key risk indicators program maturity indicators and key performance indicators to enable data-driven risk reporting.
  • Contribute to the review and maintenance of information security policies standards and procedures in your line of business - ensuring alignment with the firms risk appetite and regulatory obligations.
  • Develop into a trusted advisor to management supporting the reporting of information security programs cyber risk posture and GRC maturity to governance forums.
  • Support the development and delivery of scenario testing such as Tabletop Exercises and Threat Led Penetration Testing tovalidateour cyber resilience.
  • Support remediation efforts and contribute to transformational change initiatives across the broader organization including zero trust adoption third-party risk management and operational resilience programs.

Wedlove to see:

  • 3-5 years of experience in information security cyber GRC cyber security risk management data security or cyber security regulation.
  • Demonstrated ability to work effectively with stakeholders across a complex global and highly regulated environment.
  • Experience contributing to cross-functional projects with a strong attention to detail and follow-through.
  • Ability toidentifyand escalate cyber security risks including third-party and supply chain risk and support the delivery of services in a secure and compliant way.
  • Solid foundational knowledge across key cyber security domains such as cloud security network security and architecture application security secure software development lifecycle (SSDLC) or vulnerability management.
  • Familiarity with Threat Led Penetration Testing (TLPT) frameworks such as CBEST or equivalent TLPT regimes.
  • Familiarity with key technologies such as Operating Systems Software Development Build Pipelines and Processes Security Tooling O365 Suite and Business Intelligence Tools.
  • Exposure to industry standards and frameworks such as NIST CSF ISO 27001 or cyber risk quantification methodologies.
  • Awareness ofregulationpertaining to Information Security such as DORA Operational Resilience UK CTP Regime and GDPR.
  • Strong written and oral communication skills with a desire to develop the ability to translate cyber risk into clear business…
Position Requirements
10+ Years work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary