Business Information Security Officer (BISO)

Business Information Security Officer (BISO)

Full-Time 43200 - 72000 Β£ / year (est.) Home office (partial)
Dr Jobs

At a Glance

  • Tasks: Lead cybersecurity efforts, advising on risk management and incident response for Risk and Brokering.
  • Company: WTW is a global leader in risk management and insurance brokerage, committed to inclusivity.
  • Benefits: Enjoy a dynamic work environment with opportunities for growth and a strong focus on diversity.
  • Other info: We embrace diversity and provide support throughout the application process.
  • Why this job: Join a team that values innovation and collaboration while making a real impact on cybersecurity.
  • Qualifications: Strong understanding of cybersecurity standards; experience in strategic planning and stakeholder engagement required.

The predicted salary is between 43200 - 72000 Β£ per year.

DescriptionAs the Business Information Security Officer for Risk and Brokering (R&B) you will be a crucial asset to WTWs cyber security efforts ensuing robust cyber security practices are embedded across the business unit and are aligned with the organisations overall security strategy.This role is to serve as the global trusted information security partner to the business and technology teams supporting them to ensure security items are appropriately managed.This role is part of the extended Information & Cyber Security Leadership Team and resides within Corporate IT reporting to the Lead Business Information Security Officer.The RolePrimary responsibly is the BISO for Risk and Brokering (R&B):Serve as a leader within the Information & Cyber Security Team as the trusted advisor to R&B leadership providing strategic cybersecurity insights and recommendations to ensure a cohesive approach to cyber risk management.Ensure cybersecurity practices and security by design are integrated into business unit initiatives motivating business units to adopt efficient security controls throughout their lifecycle.Oversight of R&Bs response to Incident integrating cyber incident response policies with business operations to improve agility and effectiveness in cyber incident management.Work with R&B leaders to advise on disaster recovery and business continuity planning for business and cyber security resiliency.Key stakeholder representing information security to support the business and technology teams delivery of the security change programme.Provide support to the business and technology teams to understand and address vulnerabilities within SLA identified through penetration testing vulnerability scanning and red team exercisesFoster relationships with internal business units to enhance cyber security communication including knowledge of threats vulnerabilities and mitigation strategies.Provide strategic insights to senior management on cyber incident response readiness and effectiveness.Collaborate with security leadership to enforce cyber security policies and practices addressing operations and incident response.Provide expertise and knowledge to the business with responses to client questions.Enforce the strong security culture set by the CISO ensuing uniformity across R&B leadership business units and employees.Support in the Identification of technology and cyber security risks.Ensure the technology teams are updated with changes to information security policy & standards and support them in adherence to changes.Lead the information security updates at business and technology governance forums.QualificationsThe RequirementsTechnical skills:A comprehensive understanding of information security services (security operations and offensive security testing)Experience of strategic planning and oversight of cyber incident response and crisis managementStrong understanding of cybersecurity standards and frameworks (e.g. ISO27001 NIST CIS) and their application in strategic planning and policy developmentAbility to collaborate business leadership to operationalise strategic decisions ensuring alignment with organizational resilience goals.Understanding of regulatory requirements and their impact on security.Additionally the following are desirable but not essential:Degree in a relevant Information Technology or Information Security areaInformation security specific qualifications are desirable (such as CISM CISSP)Leadership specific training or qualifications (such as Strategic Leadership and Management)Expert understanding of technical information security.Non-technical skills:Exceptional skills in managing and engaging stakeholders at both technical and non-technical levels to foster strong relationships.Highly developed influencing abilities and communication skills capable of articulating complex security concepts to diverse audiences.Proven ability to lead and motivate teams with the ability to inspire and drive strategic initiatives forward.Able to manage multiple conflicting priorities and tasks in a dynamic and high-pressure environment.Effective in leading change with the agility to adjust strategies and approaches in response to evolving cybersecurity landscapes.Politically aware with outstanding influencing ability and the ability to work with senior management.Demonstrated ability to work collaboratively within and across teams promoting an inclusive and innovative work environment.Outstanding problem-solving skills committed to ensuring issues are resolved and enhancing the security framework continuously.Excellent strategic and operational business awareness with insights into the key drivers challenges constraints and opportunities.At WTW we believe difference makes us stronger. We want our workforce to reflect the different and varied markets we operate in and to build a culture of inclusivity that makes colleagues feel welcome valued and empowered to bring their whole selves to work every day. We are an equal opportunity employer committed to fostering an inclusive work environment throughout our organisation. We embrace all types of diversity.Were committed to equal employment opportunity and provide application interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers from the application process through to joining WTW please email Required Experience:Unclear Seniority Key Skills International Development,Information Systems,Community,Information Technology Sales,Corporate Recruitment Employment Type : Full-Time Experience: years Vacancy: 1

Business Information Security Officer (BISO) employer: Dr Jobs

WTW is an exceptional employer that prioritises a culture of inclusivity and empowerment, making it an ideal workplace for the Business Information Security Officer role. With a strong commitment to employee growth, WTW offers opportunities for professional development and strategic leadership training, ensuring that team members are equipped to navigate the evolving cybersecurity landscape. Located in a dynamic environment, employees benefit from robust support systems and a collaborative atmosphere that fosters innovation and effective communication across all levels of the organisation.

Dr Jobs

Contact Details:

Dr Jobs Recruitment Team

StudySmarter Expert Advice🀫

We think this is how you could land Business Information Security Officer (BISO)

✨Tip Number 1

Network with professionals in the cybersecurity field, especially those who have experience as Business Information Security Officers. Attend industry events or webinars to connect with potential colleagues and learn about the latest trends in cybersecurity.

✨Tip Number 2

Familiarise yourself with the specific cybersecurity frameworks mentioned in the job description, such as ISO27001 and NIST. Being able to discuss these frameworks in detail during your conversations will demonstrate your expertise and alignment with the role.

✨Tip Number 3

Prepare to showcase your leadership skills by gathering examples of how you've successfully managed teams or projects in high-pressure environments. Highlighting your ability to influence and engage stakeholders will be crucial in this role.

✨Tip Number 4

Stay updated on the latest cybersecurity threats and incident response strategies. Being knowledgeable about current challenges in the field will allow you to engage in meaningful discussions with the hiring team and show that you're proactive about security.

We think you need these skills to ace Business Information Security Officer (BISO)

Information Security Management
Cybersecurity Standards and Frameworks (e.g. ISO27001, NIST, CIS)
Incident Response and Crisis Management
Stakeholder Engagement
Strategic Planning
Risk Management
Disaster Recovery and Business Continuity Planning

Some tips for your application 🫑

Tailor Your CV:Make sure your CV highlights relevant experience in information security, particularly in risk management and cyber incident response. Use keywords from the job description to demonstrate your fit for the role.

Craft a Compelling Cover Letter:In your cover letter, explain why you are passionate about cybersecurity and how your skills align with the responsibilities of the Business Information Security Officer. Mention specific experiences that showcase your ability to manage stakeholders and lead teams.

Showcase Technical Knowledge:Demonstrate your understanding of cybersecurity standards and frameworks like ISO27001 and NIST in your application. Provide examples of how you've applied these in previous roles to enhance security practices.

Highlight Soft Skills:Emphasise your communication and influencing abilities in your application. Provide examples of how you've successfully engaged with both technical and non-technical stakeholders to foster strong relationships and drive strategic initiatives.

How to prepare for a job interview at Dr Jobs

✨Understand the Role Thoroughly

Before your interview, make sure you have a solid grasp of the responsibilities and expectations of a Business Information Security Officer. Familiarise yourself with the specific cybersecurity practices and frameworks mentioned in the job description, such as ISO27001 and NIST.

✨Prepare for Scenario-Based Questions

Expect to be asked about how you would handle specific cybersecurity incidents or challenges. Prepare examples from your past experience where you successfully managed cyber risks or led incident response efforts, showcasing your strategic thinking and problem-solving skills.

✨Showcase Your Stakeholder Management Skills

This role requires exceptional stakeholder engagement abilities. Be ready to discuss how you've built relationships with both technical and non-technical teams in previous roles, and how you can influence and communicate complex security concepts effectively.

✨Demonstrate Your Leadership Qualities

As a BISO, you'll need to lead and motivate teams. Prepare to share examples of how you've inspired others, driven strategic initiatives, and managed multiple priorities in high-pressure environments. Highlight your ability to adapt to changing circumstances in the cybersecurity landscape.