At a Glance
- Tasks: Support and enhance Bloomberg's security programs while managing cyber risks.
- Company: Join Bloomberg's dynamic Information Security Office team.
- Benefits: Competitive salary, health benefits, and opportunities for professional growth.
- Other info: Collaborative environment with a focus on continuous improvement and innovation.
- Why this job: Make a real impact on cybersecurity in a global setting.
- Qualifications: 3-5 years in information security or related fields; strong communication skills.
The predicted salary is between 60000 - 80000 £ per year.
Our Team: We protect Bloomberg. The Bloomberg Information Security Office team is dedicated to making our products and technologies as secure as possible through design, development, and operation. We report into the Chief Information Security Office while working closely with regulated businesses, key lines of business, and development/engineering across Bloomberg L.P. Our colleagues depend on us to help design, run, and improve our most important security programs — strengthening our cyber resilience and security posture across an evolving threat landscape.
What’s in it for you: The Bloomberg BISO team focuses on identifying opportunities to improve the security of Bloomberg, our products and services, and the security of our customers’ data. In this role, you will contribute to the development and execution of multiple security and cyber GRC programs, each with unique challenges and in a global setting. You will play a key role in supporting cyber risk governance, evangelizing security and compliance efforts, and helping to shape the direction of Bloomberg L.P.’s business efforts - all in a day’s work.
We’ll trust you to:
- Build a strong understanding of your business domains, staying current with new technologies, the evolving threat landscape, regulatory changes, and industry best practices as you support and contribute to the information security and cyber GRC programs for your lines of business.
- Work with stakeholders to effectively manage cyber risk including supporting the assessment of security controls, risk identification, mitigation strategies, and incident response planning.
- Build cross-functional relationships between teams to improve all aspects of our security program, contributing to a culture of security by design and continuous compliance.
- Support the development of management information, including key risk indicators, program maturity indicators, and key performance indicators to enable data-driven risk reporting.
- Contribute to the review and maintenance of information security policies, standards, and procedures in your line of business - ensuring alignment with the firm’s risk appetite and regulatory obligations.
- Develop into a trusted advisor to management, supporting the reporting of information security programs, cyber risk posture, and GRC maturity to governance forums.
- Support the development and delivery of scenario testing such as Tabletop Exercises and Threat Led Penetration Testing to validate our cyber resilience.
- Support remediation efforts and contribute to transformational change initiatives across the broader organization, including zero trust adoption, third-party risk management, and operational resilience programs.
We’d love to see:
- 3-5 years of experience in information security, cyber GRC, cyber security risk management, data security, or cyber security regulation.
- Demonstrated ability to work effectively with stakeholders across a complex, global, and highly regulated environment.
- Experience contributing to cross-functional projects with a strong attention to detail and follow-through.
- Ability to identify and escape cyber security risks — including third-party and supply chain risk — and support the delivery of services in a secure and compliant way.
- Solid foundational knowledge across key cyber security domains such as cloud security, network security and architecture, application security, secure software development lifecycle (SSDLC), or vulnerability management.
- Familiarity with Threat Led Penetration Testing (TLPT) frameworks such as CBEST or equivalent TLPT regimes.
- Familiarity with key technologies such as Operating Systems, Software Development Build Pipelines and Processes, Security Tooling, O365 Suite, and Business Intelligence Tools.
- Exposure to industry standards and frameworks such as NIST CSF, ISO 27001, or cyber risk quantification methodologies.
- Awareness of regulation pertaining to Information Security such as DORA, Operational Resilience, UK CTP Regime, and GDPR.
- Strong written and oral communication skills, with a desire to develop the ability to translate cyber risk into clear business language.
- Demonstrated ability to perform under pressure and consistently meet deadlines.
- An industry-recognized certification such as CISSP, CISM, CRISC, CompTIA Security+, or ISO 27001 Lead Implementor/Auditor — or working towards one.
If indicated, please note that years of experience are a guide; we will consider applications from all candidates who can demonstrate the skills necessary for the role.
Business Information Security Officer (BISO) - Cyber GRC Associate employer: Bloomberg
Bloomberg is an exceptional employer, offering a dynamic work environment in the heart of London where innovation meets security. Our culture fosters collaboration and continuous learning, providing employees with ample opportunities for professional growth while contributing to critical cyber resilience initiatives. With a commitment to employee well-being and a focus on cutting-edge technology, Bloomberg empowers its team members to thrive in their careers and make a meaningful impact in the world of information security.
StudySmarter Expert Advice🤫
We think this is how you could land Business Information Security Officer (BISO) - Cyber GRC Associate
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend events, join online forums, or even hit up LinkedIn. The more people you know, the better your chances of landing that BISO role.
✨Tip Number 2
Show off your skills! Prepare for interviews by brushing up on your knowledge of cyber security and GRC. Be ready to discuss how you've tackled challenges in the past and how you can contribute to Bloomberg's security programs.
✨Tip Number 3
Tailor your approach! When you get an interview, make sure to highlight your experience with cross-functional projects and your understanding of regulatory frameworks. This will show you're the perfect fit for the team.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re serious about joining the Bloomberg family and contributing to our mission of enhancing cyber resilience.
We think you need these skills to ace Business Information Security Officer (BISO) - Cyber GRC Associate
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Business Information Security Officer role. Highlight your experience in information security and cyber GRC, and don’t forget to mention any relevant certifications you have!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your skills align with our mission at Bloomberg. Keep it concise but impactful.
Showcase Your Communication Skills:Since strong written communication is key for this role, ensure your application is clear and free of jargon. We want to see how well you can translate complex cyber risks into business language.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands and shows us you’re serious about joining our team!
How to prepare for a job interview at Bloomberg
✨Know Your Stuff
Make sure you have a solid understanding of the key cyber security domains mentioned in the job description. Brush up on cloud security, network security, and the latest regulatory changes. Being able to discuss these topics confidently will show that you're serious about the role.
✨Showcase Your Experience
Prepare specific examples from your past work that demonstrate your ability to manage cyber risks and contribute to cross-functional projects. Use the STAR method (Situation, Task, Action, Result) to structure your answers and highlight your attention to detail and follow-through.
✨Build Relationships
Since this role involves working with various stakeholders, think about how you can demonstrate your relationship-building skills. Be ready to discuss how you've successfully collaborated with different teams in the past and how you plan to foster those relationships at Bloomberg.
✨Communicate Clearly
Practice translating complex cyber risk concepts into clear business language. During the interview, focus on your communication skills, as they are crucial for this role. You might even want to prepare a few scenarios where you had to explain technical issues to non-technical stakeholders.