Cyber Security Business Information Officer (BISO)

RELX Group
London, UK
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Software System Penetration Testing Microsoft Azure Cyber Security Systems Development Life Cycle Security Information and Event Management Software Vulnerability Management Google Cloud Software Security Information Technology Devsecops Security Orchestration, Automation & Response
+2 more
Static Application Security Testing Dynamic Application Security Testing

Job description

As a Business Information Security Officer (BISO), you act as the primary security partner for assigned business units, bridging business strategy and enterprise cybersecurity. You are accountable for planning and executing security initiatives that reduce risk, strengthen cyber defenses, and enable delivery at scale.The role is highly collaborative, advisory, and outcome-focused-ensuring security is embedded early and pragmatically across products, platforms, and major initiatives., * Act as the primary security partner for assigned business units, building trusted senior stakeholder relationships.

  • Embed security early into business initiatives, product development, and technology delivery.
  • Sponsor and support enterprise and business-aligned security initiatives end-to-end.
  • Provide expert security guidance across concurrent IT, engineering, and business projects.
  • Oversee security assessments including vulnerability management, penetration testing, and third-party risk.
  • Translate security findings into prioritized, actionable remediation plans with clear ownership.
  • Provide security input into solution architecture and major technology decisions.
  • Serve as the security point of contact for customer-facing inquiries, audits, and due-diligence.
  • Identify, document, and govern cyber risks, supporting risk acceptance and escalation processes.
  • Develop and report meaningful security metrics to inform leadership decisions and continuous improvement.

Requirements

  • Several years’ experience in a BISO or senior security leadership / advisory role.
  • Strong cloud and application security experience (AWS, Azure, GCP; secure SDLC).
  • Hands-on knowledge of security tooling (SIEM, SOAR, EDR/XDR, CSPM, SAST/DAST).
  • Experience embedding security into CI/CD pipelines and DevSecOps practices.
  • Proven capability in risk assessments, threat modeling, and control gap analysis.
  • Experience collaborating with SOC and Incident Response teams during security events.
  • Working knowledge of security frameworks and regulations (NIST, ISO 27001, CIS, GDPR, etc.).
  • Ability to translate technical risk into clear, business-relevant language.
  • Strong stakeholder management skills with the ability to influence without authority.
  • Bachelor’s degree in Engineering, Computer Science, or equivalent experience, plus relevant certifications (CISSP, CISM, GIAC, or similar).

About the company

RELX is a global provider of information-based analytics and decision tools for professional and business customers, enabling them to make better decisions, get better results and be more productive.

Our purpose is to benefit society by developing products that help researchers advance scientific knowledge; doctors and nurses improve the lives of patients; lawyers promote the rule of law and achieve justice and fair results for their clients; businesses and governments prevent fraud; consumers access financial services and get fair prices on insurance; and customers learn about markets and complete transactions.

Our purpose guides our actions beyond the products that we develop. It defines us as a company. Every day across RELX our employees are inspired to undertake initiatives that make unique contributions to society and the communities in which we operate.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all