At a Glance
- Tasks: Support cyber risk governance and improve Bloomberg's security programs.
- Company: Join Bloomberg, a leader in information security and technology.
- Benefits: Competitive salary, diverse culture, and opportunities for professional growth.
- Other info: Dynamic work environment with a focus on innovation and collaboration.
- Why this job: Make a real impact on global security initiatives and enhance your skills.
- Qualifications: 3-5 years in information security or related fields; strong communication skills.
The predicted salary is between 60000 - 80000 £ per year.
Our Team
The Bloomberg Information Security Office team is dedicated to making our products and technologies as secure as possible through design, development, and operation. We report into the Chief Information Security Office while working closely with regulated businesses, key lines of business, and development/engineering across Bloomberg L.P. Our colleagues depend on us to help design, run, and improve our most important security programs — strengthening our cyber resilience and security posture across an evolving threat landscape.
What’s in it for you
The Bloomberg BISO team focuses on identifying opportunities to improve the security of Bloomberg, our products and services, and the security of our customers’ data. In this role, you will contribute to the development and execution of multiple security and cyber GRC programs, each with unique challenges and in a global setting. You will play a key role in supporting cyber risk governance, evangelizing security and compliance efforts, and helping to shape the direction of Bloomberg L.P.’s business efforts - all in a day’s work.
We’ll trust you to:
- Build a strong understanding of your business domains, staying current with new technologies, the evolving threat landscape, regulatory changes, and industry best practices as you support and contribute to the information security and cyber GRC programs for your lines of business.
- Work with stakeholders to effectively manage cyber risk including supporting the assessment of security controls, risk identification, mitigation strategies, and incident response planning.
- Build cross-functional relationships between teams to improve all aspects of our security program, contributing to a culture of security by design and continuous compliance.
- Support the development of management information, including key risk indicators, program maturity indicators, and key performance indicators to enable data-driven risk reporting.
- Contribute to the review and maintenance of information security policies, standards, and procedures in your line of business - ensuring alignment with the firm’s risk appetite and regulatory obligations.
- Develop into a trusted advisor to management, supporting the reporting of information security programs, cyber risk posture, and GRC maturity to governance forums.
- Support the development and delivery of scenario testing such as Tabletop Exercises and Threat Led Penetration Testing to validate our cyber resilience.
- Support remediation efforts and contribute to transformational change initiatives across the broader organization, including zero trust adoption, third-party risk management, and operational resilience programs.
We’d love to see:
- 3-5 years of experience in information security, cyber GRC, cyber security risk management, data security, or cyber security regulation.
- Demonstrated ability to work effectively with stakeholders across a complex, global, and highly regulated environment.
- Experience contributing to cross-functional projects with a strong attention to detail and follow-through.
- Ability to identify and elevate cyber security risks — including third-party and supply chain risk — and support the delivery of services in a secure and compliant way.
- Solid foundational knowledge across key cyber security domains such as cloud security, network security and architecture, application security, secure software development lifecycle (SSDLC), or vulnerability management.
- Familiarity with Threat Led Penetration Testing (TLPT) frameworks such as CBEST or equivalent TLPT regimes.
- Familiarity with key technologies such as Operating Systems, Software Development Build Pipelines and Processes, Security Tooling, O365 Suite, and Business Intelligence Tools.
- Exposure to industry standards and frameworks such as NIST CSF, ISO 27001, or cyber risk quantification methodologies.
- Awareness of regulation pertaining to Information Security such as DORA, Operational Resilience, UK CTP Regime, and GDPR.
- Strong written and oral communication skills, with a desire to develop the ability to translate cyber risk into clear business language.
- Demonstrated ability to perform under pressure and consistently meet deadlines.
- An industry recognized certification such as CISSP, CISM, CRISC, CompTIA Security+, or ISO 27001 Lead Implementor/Auditor — or working towards one.
If This Sounds Like You
Apply if you think we’re a good match. We’ll get in touch to let you know what the next steps are.
Bloomberg is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy or parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law. Bloomberg is a disability inclusive employer. Please let us know if you require any reasonable adjustments to be made for the recruitment process.
Business Information Security Officer (BISO) - Cyber GRC Associate London, GBR Posted yesterday employer: Bloomberg L.P.
Bloomberg is an exceptional employer, offering a dynamic work environment in the heart of London where innovation meets security. With a strong commitment to employee growth, we provide opportunities for professional development and cross-functional collaboration, fostering a culture that values diversity and inclusion. Our focus on cyber resilience and compliance ensures that you will be at the forefront of industry advancements while contributing to meaningful projects that protect our clients and enhance our services.
StudySmarter Expert Advice🤫
We think this is how you could land Business Information Security Officer (BISO) - Cyber GRC Associate London, GBR Posted yesterday
✨Tip Number 1
Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their security programs and be ready to discuss how your skills align with their needs. Show them you’re not just another candidate!
✨Tip Number 3
Practice your responses to common interview questions, especially those related to cyber risk management and compliance. The more comfortable you are, the better you’ll perform when it counts.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who take that extra step to engage with us directly.
We think you need these skills to ace Business Information Security Officer (BISO) - Cyber GRC Associate London, GBR Posted yesterday
Some tips for your application 🫡
Know Your Stuff:Before you start writing, make sure you understand the role and its requirements. Dive into the job description and highlight the key skills and experiences they’re looking for. This will help you tailor your application to show that you’re the perfect fit!
Be Authentic:When writing your application, let your personality shine through! We want to see the real you, so don’t be afraid to share your passion for information security and how it aligns with our mission at StudySmarter. Authenticity goes a long way!
Showcase Relevant Experience:Make sure to highlight your relevant experience in information security and cyber GRC. Use specific examples to demonstrate how you've tackled challenges in the past and how those experiences have prepared you for this role. We love seeing concrete achievements!
Check Your Work:Before hitting send, take a moment to proofread your application. Spelling and grammar mistakes can distract from your message. A polished application shows attention to detail, which is super important in our field. And remember, apply through our website for the best chance!
How to prepare for a job interview at Bloomberg L.P.
✨Know Your Cyber Security Basics
Make sure you brush up on key cyber security concepts like cloud security, network security, and the secure software development lifecycle. Being able to discuss these topics confidently will show that you have a solid foundational knowledge, which is crucial for the role.
✨Understand the Regulatory Landscape
Familiarise yourself with regulations such as GDPR, DORA, and the UK CTP Regime. Being able to articulate how these regulations impact information security will demonstrate your awareness of compliance requirements and your ability to navigate a highly regulated environment.
✨Prepare for Scenario-Based Questions
Expect questions that require you to think critically about cyber risk management and incident response planning. Practise articulating your thought process in scenarios, such as how you would handle a data breach or assess third-party risks, to showcase your problem-solving skills.
✨Build Cross-Functional Relationship Skills
Since this role involves working with various stakeholders, be ready to discuss your experience in building relationships across teams. Share examples of how you've collaborated on projects and contributed to a culture of security by design, as this will highlight your teamwork abilities.