Cyber Security Business Information Officer (BISO) in London

Cyber Security Business Information Officer (BISO) in London

London Full-Time 60000 - 80000 € / year (est.) No home office possible
Elsevier

At a Glance

  • Tasks: Act as a security partner, embedding security in business initiatives and technology delivery.
  • Company: Join a global leader in advanced information and decision support for science and healthcare.
  • Benefits: Enjoy competitive benefits tailored to your location and a supportive work environment.
  • Other info: Dynamic career growth opportunities in a collaborative and innovative culture.
  • Why this job: Make a real impact on cybersecurity while collaborating with diverse teams.
  • Qualifications: Experience in security leadership, cloud security, and risk assessments required.

The predicted salary is between 60000 - 80000 € per year.

About Our Team

The Business Information Security Office (BISO) team partners with business, product, and technology leaders to deliver measurable security outcomes that support enterprise objectives. We focus on managing complex risk, embedding secure‐by‐design practices, and driving long‐term cybersecurity maturity. Our work enables trusted innovation, operational resilience, and informed risk decision‐making across the organization.

About the Role

As a Business Information Security Officer (BISO), you act as the primary security partner for assigned business units, bridging business strategy and enterprise cybersecurity. You are accountable for planning and executing security initiatives that reduce risk, strengthen cyber defenses, and enable delivery at scale. The role is highly collaborative, advisory, and outcome‐focused—ensuring security is embedded early and pragmatically across products, platforms, and major initiatives.

Responsibilities:

  • Act as the primary security partner for assigned business units, building trusted senior stakeholder relationships.
  • Embed security early into business initiatives, product development, and technology delivery.
  • Sponsor and support enterprise and business‐aligned security initiatives end‐to‐end.
  • Provide expert security guidance across concurrent IT, engineering, and business projects.
  • Oversee security assessments including vulnerability management, penetration testing, and third‐party risk.
  • Translate security findings into prioritized, actionable remediation plans with clear ownership.
  • Provide security input into solution architecture and major technology decisions.
  • Serve as the security point of contact for customer‐facing inquiries, audits, and due‐diligence.
  • Identify, document, and govern cyber risks, supporting risk acceptance and escalation processes.
  • Develop and report meaningful security metrics to inform leadership decisions and continuous improvement.

Requirements:

  • Several years’ experience in a BISO or senior security leadership/advisory role.
  • Strong cloud and application security experience (AWS, Azure, GCP; secure SDLC).
  • Hands‐on knowledge of security tooling (SIEM, SOAR, EDR/XDR, CSPM, SAST/DAST).
  • Experience embedding security into CI/CD pipelines and DevSecOps practices.
  • Proven capability in risk assessments, threat modeling, and control gap analysis.
  • Experience collaborating with SOC and Incident Response teams during security events.
  • Working knowledge of security frameworks and regulations (NIST, ISO 27001, CIS, GDPR, etc.).
  • Ability to translate technical risk into clear, business‐relevant language.
  • Strong stakeholder management skills with the ability to influence without authority.
  • Bachelor’s degree in Engineering, Computer Science, or equivalent experience, plus relevant certifications (CISSP, CISM, GIAC, or similar).

We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know.

We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.

Cyber Security Business Information Officer (BISO) in London employer: Elsevier

At Elsevier, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation in the field of cybersecurity. Our commitment to employee growth is evident through continuous learning opportunities and a supportive environment that values diversity and inclusion. Located in Oxford and London, our teams benefit from a vibrant community and access to cutting-edge technology, making it an ideal place for professionals looking to make a meaningful impact in science and healthcare.

Elsevier

Contact Detail:

Elsevier Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Security Business Information Officer (BISO) in London

Tip Number 1

Network like a pro! Reach out to folks in the cybersecurity field, especially those who work at companies you're interested in. A friendly chat can open doors and give you insider info that could help you stand out.

Tip Number 2

Prepare for interviews by brushing up on your technical knowledge and soft skills. Be ready to discuss how you've tackled security challenges in the past and how you can bring value to the team. Practice makes perfect!

Tip Number 3

Showcase your passion for cybersecurity! Share your thoughts on recent trends or news in the industry during interviews. This not only demonstrates your knowledge but also your enthusiasm for the role.

Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining our team.

We think you need these skills to ace Cyber Security Business Information Officer (BISO) in London

Cloud Security
Application Security
Security Tooling (SIEM, SOAR, EDR/XDR, CSPM, SAST/DAST)
CI/CD Pipeline Security
DevSecOps Practices
Risk Assessments
Threat Modelling

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the BISO role. Highlight your experience in cybersecurity, especially in areas like cloud security and risk assessments. We want to see how your skills align with what we’re looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re passionate about cybersecurity and how you can contribute to our team. Be sure to mention specific projects or experiences that relate to the responsibilities outlined in the job description.

Showcase Your Stakeholder Management Skills:Since this role involves building relationships with senior stakeholders, make sure to highlight any relevant experience you have in managing relationships and influencing decisions. We love seeing examples of collaboration and communication!

Apply Through Our Website:Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows us you’re serious about joining our team at StudySmarter!

How to prepare for a job interview at Elsevier

Know Your Cyber Security Stuff

Make sure you brush up on your knowledge of cloud and application security, especially with platforms like AWS, Azure, and GCP. Be ready to discuss how you've embedded security into CI/CD pipelines and your experience with security tooling. This will show that you're not just familiar with the concepts but have practical experience too.

Showcase Your Stakeholder Skills

As a BISO, you'll need to build trusted relationships with senior stakeholders. Prepare examples of how you've influenced decisions without direct authority in past roles. Think about times when you successfully communicated complex security risks in a way that was relevant to business objectives.

Prepare for Technical Questions

Expect to dive deep into technical discussions during your interview. Brush up on risk assessments, threat modelling, and control gap analysis. Be ready to explain how you've handled security assessments and what remediation plans you've implemented in previous roles.

Understand the Business Context

It's crucial to connect security initiatives with business outcomes. Research the company’s goals and think about how your role as a BISO can support those objectives. Be prepared to discuss how you would align security practices with their business strategy and operational resilience.