Rodeo
Get started

Kingfisher plc

Business Information Security Officer (BISO)

Southampton
Posted about 23 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

We’re Kingfisher, A team made up of over 74,000 passionate people who bring Kingfisher - and all our other brands: B&Q, Screwfix, Brico Depot, Castorama and Koctas to life. Guided by our purpose Better Homes. Better Lives. For Everyone. We believe a better world starts with better homes, and we work every day to make that a reality. Join us and help shape the future of home improvement.

Role purpose

As a senior cybersecurity leader, the Business Information Security Officer (BISO), known internally as Banner Information Security Officer, acts as the key link between the Information Security team and assigned business functions. The role is responsible for aligning security strategy with business objectives, providing trusted security guidance, and ensuring cybersecurity considerations are embedded within business operations, projects, and decision-making. The BISO works closely with stakeholders across the organisation to strengthen security posture, manage risk, and support the delivery of business goals in a secure and compliant manner.

Please note that this role can be based in Southampton or London Paddington with an expectation of 12 days per month in the office.

What's the job?

  • Serve as the primary cybersecurity advisor and key liaison between the Security Function and business stakeholders, balancing operational needs with security requirements.
  • Build trusted relationships across the Banner/Group Functions, providing expert guidance and promoting a strong culture of cybersecurity awareness.
  • Own and maintain the cyber risk register, supporting risk-based decision making, prioritisation, reporting, and remediation tracking.
  • Ensure all projects, solutions, and business changes are delivered using Secure by Design principles, identifying control weaknesses and managing associated risks.
  • Lead security incident and breach response activities between Technology and the business, participating in the Cyber Security Incident Response Team (CSIRT) where required.
  • Drive assurance and governance activities by reviewing systems, applications, platforms, suppliers, and processes against security frameworks, policies, and standards.
  • Provide regular reporting and strategic insight to senior stakeholders, ensuring security strategy, vulnerability management, and business roadmaps are aligned with organisational goals and compliance requirements.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

What You'll Bring

  • Extensive experience in Information Security or a related field, including leadership or management experience within IT or Cyber Security teams.
  • Strong knowledge of industry security frameworks and standards, including ISO 27001, NIST, OWASP, PCI DSS and NIS2.
  • Excellent communication skills, with the ability to translate complex technical concepts into clear, actionable guidance for both technical and non-technical audiences.
  • Deep understanding of cybersecurity risks, emerging threats, and their impact on business operations, with the ability to influence decision-making at all levels.
  • Proven ability to build trusted relationships with stakeholders, drive positive outcomes, and effectively challenge and influence behaviours when required.
  • Strong analytical, organisational and decision-making skills, with the ability to prioritise competing demands and balance risk against business objectives.
  • A proactive and collaborative leader who demonstrates integrity, sound judgement, regulatory awareness, customer focus and a commitment to fostering a positive team culture.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

How We Work

We believe in flexibility and balance. Our hybrid model blends home working for focus with time spent connecting and collaborating - whether in our offices or at offsite locations. On average, around 60% of your time will involve in-person collaboration.

We value the perspectives new team members bring and encourage you to apply - even if you don’t meet 100% of the requirements.

What We Offer

An inclusive environment where your potential is limited only by your imagination. We encourage new ideas, support experimentation, and strive to create a workplace where everyone can be their best self. Find out more about Diversity & Inclusion at Kingfisher here.

We also offer a competitive benefits package and plenty of opportunities to stretch and grow your career.

Diversity & Inclusion

Our customers come from all walks of life - and so do we. We’re committed to ensuring all colleagues, future colleagues, and applicants are treated equally, regardless of age, gender, marital or civil partnership status, ethnicity, culture, religion, belief, political opinion, disability, gender identity, gender expression, or sexual orientation.

Interested? Great, apply now and help us to Power the Possible.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Information Security
Cybersecurity Leadership
Risk Management
Secure by Design
Incident Response
Governance
ISO 27001
NIST
OWASP
PCI DSS
NIS2
Stakeholder Management
Vulnerability Management
Cyber Risk Register
Compliance

Location

Southampton, England, United Kingdom

Sign up to applySee more jobs like this