> Markdown version of [/jobs/ext/1287057-cyber-security-business-information-officer-biso](https://www.wearedevelopers.com/jobs/ext/1287057-cyber-security-business-information-officer-biso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Business Information Officer (BISO) - **Company:** RELX Group - **Location:** Manchester, UK - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cyber Security, Systems Development Life Cycle, Security Information and Event Management, Software Vulnerability Management, Google Cloud, Software Security, Information Technology, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 16, 2026 - **Apply:** https://jobs.theguardian.com/job/10151302/cyber-security-business-information-officer-biso-/ ## About the Role * Several years' experience in a BISO or senior security leadership / advisory role. * Strong cloud and application security experience (AWS, Azure, GCP; secure SDLC). * Hands-on knowledge of security tooling (SIEM, SOAR, EDR/XDR, CSPM, SAST/DAST). * Experience embedding security into CI/CD pipelines and DevSecOps practices. * Proven capability in risk assessments, threat modeling, and control gap analysis. * Experience collaborating with SOC and Incident Response teams during security events. * Working knowledge of security frameworks and regulations (NIST, ISO 27001, CIS, GDPR, etc.). * Ability to translate technical risk into clear, business-relevant language. * Strong stakeholder management skills with the ability to influence without authority. * Bachelor's degree in Engineering, Computer Science, or equivalent experience, plus relevant certifications (CISSP, CISM, GIAC, or similar). ## Description As a Business Information Security Officer (BISO), you act as the primary security partner for assigned business units, bridging business strategy and enterprise cybersecurity. You are accountable for planning and executing security initiatives that reduce risk, strengthen cyber defenses, and enable delivery at scale. The role is highly collaborative, advisory, and outcome-focused-ensuring security is embedded early and pragmatically across products, platforms, and major initiatives., * Act as the primary security partner for assigned business units, building trusted senior stakeholder relationships. * Embed security early into business initiatives, product development, and technology delivery. * Sponsor and support enterprise and business-aligned security initiatives end-to-end. * Provide expert security guidance across concurrent IT, engineering, and business projects. * Oversee security assessments including vulnerability management, penetration testing, and third-party risk. * Translate security findings into prioritized, actionable remediation plans with clear ownership. * Provide security input into solution architecture and major technology decisions. * Serve as the security point of contact for customer-facing inquiries, audits, and due-diligence. * Identify, document, and govern cyber risks, supporting risk acceptance and escalation processes. * Develop and report meaningful security metrics to inform leadership decisions and continuous improvement. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)