> Markdown version of [/jobs/ext/340043-business-information-security-officer](https://www.wearedevelopers.com/jobs/ext/340043-business-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Business Information Security Officer - **Company:** Peabody - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, Cyber Security, Data Security, Elearning - **Published:** June 11, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=e28a0f6fa8b16f63 ## About the Role Do you have experience in NIST standards?, * Experience in information security, risk management, technology or related disciplines * Experience implementing or aligning to frameworks such as NIST CSF, ISO27001, NCSC CAF, NHS Data Security Toolkit * Proven ability to build strong partnerships across technical and non-technical teams * Experience designing or delivering security awareness and training * Professional security qualifications (e.g. CISSP, CRISC or equivalent experience) * Understanding of cloud security concepts, shared responsibility models and cloud-native threats * Strong understanding of GDPR and the Data Protection Act 2018 Who you are You will be: * A persuasive and articulate communicator able to explain security concepts to any audience * Collaborative, positive and skilled at building trust with stakeholders * Confident using a range of communication channels including blogs, online training and social media * Proactive - always thinking ahead about future risks and opportunities * Detail-oriented and able to work within a fast-paced, agile environment * Flexible, solution-focused and able to plan and organise your own workload * A strong problem solver with excellent written and verbal communication skills * Able to negotiate and influence to resolve conflicting requirements * Someone committed to supporting a secure, resilient and customer-focused organisation ## Description Are you a strong communicator who understands how security enables business success? As a Business Information Security Officer (BISO) at Peabody, you'll work closely with teams across the organisation to identify risks, strengthen controls, and embed a culture of security and resilience. You'll act as the primary link between the business, technology, information security and resilience, ensuring that risks are understood and managed in a way that protects colleagues, residents, data and Peabody's reputation. This is a role where your expertise, collaboration and influence will make a significant impact every day. You'll partner with stakeholders, shape security controls, support audits, manage supplier risks and help Peabody stay ahead of emerging threats. What you'll do Business Partnering & Advisory * Work with business partners to conduct risk assessments and identify priority threats * Recommend security controls that reduce business, financial, reputational and customer harm * Collaborate with teams to implement, monitor and improve security policies, procedures and standards * Plan and deliver testing and ongoing monitoring of security controls * Identify emerging threats, regulatory changes and propose appropriate mitigations Governance & Reporting * Co-chair (or chair when required) the Information Security Working Group * Produce and manage KRIs, KPIs and reports for stakeholders and committees * Manage security exceptions, waivers and time-bound risk acceptances * Escalate breaches of security policies or standards * Work closely with Data Protection on GDPR compliance, DPIAs and risk reviews * Support preparation for internal/external audits including NHS Data Toolkit & Cyber Essentials Policies, Standards & Frameworks * Support or lead the development and improvement of security policies, procedures and standards * Align security frameworks to ISO27001, NIST CSF, NCSC CAF or other relevant guidance Supplier & Third-Party Risk Management * Conduct tiered due diligence before contract awards * Ensure appropriate security and resilience clauses are included in contracts * Coordinate external assurance where needed (e.g. penetration testing, audit reports) * Manage supplier security findings with business owners Awareness & Culture * Develop and deliver targeted training and awareness campaigns * Use multiple channels (blogs, training modules, in-person sessions) to build a positive security culture * Measure awareness success and adjust programmes based on behaviours and outcomes * Build and maintain a security champion network Incident Readiness & Response * Maintain incident response playbooks and coordinate responses to security incidents * Support post-incident reviews and track remedial actions across departments Resilience & Continuity * Partner with Business Continuity & Resilience to assess risks to critical services * Validate cyber recovery objectives and support exercising of response scenarios Horizon Scanning * Track emerging threats, technologies and regulatory changes * Recommend improvements to security controls and investment priorities * Contribute to multi-year maturity roadmaps ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk)