Bloomberg
Business Information Security Officer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Location
London
Business Area
Legal, Compliance, and Risk
Ref #
10052852
Description & Requirements
Our Team:
We protect Bloomberg. The Bloomberg Information Security Office team is dedicated to making our products and technologies as secure as possible through design, development, and operation. We report into the Chief Information Security Office while working closely with regulated businesses, key lines of business, and development/engineering across Bloomberg L.P. Our colleagues depend on us to help design, run, and improve our most important security programs.
What's In It For You
The Bloomberg BISO team focuses on identifying opportunities to improve the security of Bloomberg, our products and services, and the security of our customers’ data. In this role, you will be the owner, manager, and developer of multiple security programs, each with unique challenges and in a global setting. You will be responsible for setting strategic direction, evangelizing security and compliance efforts, and influencing the direction of Bloomberg L.P.’s business efforts all in a day’s work.
We'll Trust You To
- Develop a deep understanding of your business domains, keeping abreast of new technologies, regulatory changes, and industry best practices as you design, lead, and oversee the information security programs for your lines of business.
- Work with stakeholders to effectively manage cyber risk including consulting on security controls, mitigation strategies, and incident response planning and management.
- Foster cross-functional relationships between teams to improve all aspects of our security program.
- Define and develop management information, including key risk indicators, program maturity indicators, and key performance indicators for use in reporting.
- Establish and review information security policies and procedures in your line of business.
- Become a trusted voice to senior management, report on the status of information security programs to boards and various governance forums.
- Lead in the development and delivery of scenario testing such as Tabletop Exercises and Threat Led Penetration Testing.
- Lead remediation efforts and support transformational change initiatives across the broader organization.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
We'd Love To See
- 7+ years of experience in information security, cyber security risk management, data security and cyber security regulation.
- Demonstrated ability to influence internal and external stakeholders to achieve success in a complex global setting.
- Proven delivery of complex projects involving cross-functional teams.
- Ability to proactively identify and manage cyber security risks to deliver services and meet business objectives in a secure and compliant way.
- Strong technical knowledge in key cyber security domains such as cloud security, network security and architecture, application security, secure software development lifecycle (SSDLC) and vulnerability management.
- Proven experience in delivering Threat Led Penetration Tests such as CBEST or equivalent TLPT regimes.
- Good knowledge of key technologies such as Operating Systems, Software Development Build Pipelines and Processes, Security Tooling, O365 Suite, and Business Intelligence Tools.
- Experience with industry standards such as NIST CSF and ISO 27001.
- Knowledge and experience with Regulation pertaining to Information Security such as DORA, Operational Resilience, UK CTP Regime, GDPR.
- Excellent written and oral communication skills.
- Demonstrated ability to perform under pressure and consistently meet program deadlines.
- An industry recognized certifications such as CISSP, GIAC, CISM, ISO 27001 Lead Implementor/Auditor.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
If indicated, please note that years of experience are a guide; we will consider applications from all candidates who can demonstrate the skills necessary for the role.
Discover what makes Bloomberg unique - watch our for an inside look at our culture, values, and the people behind our success.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location