Business Information Risk Officer

2 weeks ago


London, United Kingdom BDO UK Full time

An accountancy and business advisory firm, providing the advice and solutions entrepreneurial organisations need to navigate today’s changing world.
We work with the companies that are Britain’s economic engine – ambitious, entrepreneurially-spirited and high‐growth businesses that fuel the economy – and directly advise the owners and management teams leading them.
The Quality and Risk Management Team (QRM) provides leadership, guidance, and tools to help partners and staff manage quality and risk matters. The team is comprised of an Advisory and Compliance Team, a Chief Information Security Office Team, an Economic Crime Team, a Legal Team including a Commercial & Contracts Team, the Independence and Ethics Team and the Regulatory Supervisory Team, plus the Quality Monitoring Team. We’ll help you succeed
Leading organisations trust us because of the quality of our advice. That quality grows from a thorough understanding of their business, and that understanding comes from working closely with them and building long-lasting relationships.
You’ll be someone who is both comfortable working proactively and managing your own tasks, as well as confident collaborating with others and communicating regularly with senior managers, directors, and BDO’s partners to help businesses effectively. You’ll be encouraged to identify and draw attention to opportunities for enhancing our delivery and providing additional services to organisations we work with.
The Business Information Risk Officer’s (BIRO) (Manager grade) role is responsible for leading the Chief Information Security Office (CISO) service to BDO’s business streams to effectively manage information security risk. This role will play a key part in ensuring the effectiveness of BDO’s information security risk management framework, procedures, and information security control framework.
The BIRO role is the focal point for effective engagement between business streams and the CISO team. This role will be a trusted adviser to business stakeholders and provide broad knowledge of the firm’s security strategies, policies, standards, processes, and road maps to enable streams to understand and meet information security requirements.
Leading a team of Business Information Risk Analysts and working with nominated information security risk leads in the business, the BIRO will take responsibility for assessing information security risk with the business and ensure that those risks are being managed by the risk owners. The BIRO will also oversee the prioritisation of activities to support business requests and the delivery of other resources supporting risk assessments always ensuring a consistent and high-quality service is being delivered to each business area.

This role reports to the Cyber Security Manager.
Lead CISO’s risk management service to the relevant streams, including responsibility for the performance management of the service and a team of Business Information Risk Analysts
Utilising BDO’s information security risk management tools, procedures and control framework ensure an accurate risk posture is understood and defined for each business stream
Support the CISO team in maintaining ‘information security risk communities’ in the business to drive risk awareness and effective risk management
Support the business streams to identify, and maintain registers of information assets including infrastructure, systems, software, devices and data
Build and maintain effective relationships with the risk partners, risk owners, risk managers and other stream stakeholders. Be the voice of information security in the stream and the voice of the business within CISO and committees
Develop collateral and appropriate materials to support engagement with business stakeholders, to explain CISO’s role, key information security concepts and build awareness of information security risk and BDO’s control framework
Identify information security responsibilities and controls ownership of third parties, streams, CISO and IT security teams
Proactively identify and support risk owners and managers to manage and regularly review IS risks and issues for streams
Support the business to assess criticality of assets and services
Lead information security aspects of business change and maturity improvements
Gap analysis with BDO standards and policies
Risk identification leading to clear business ownership and treatment actions
Technical point of contact for business and 3rd parties service providers to ensure clarity on meeting expectations or alternate approaches for managing risks
Preparation of papers and supporting business attendees for committee attendance
Reporting maturity, risk posture and trends to stream quality and risk partners
Targeted security awareness, education, and risk briefings
Contribution to development and implementation of security policies and standards, and the design of security services and processes
Ensure that BDO policy and contractual obligations, and in turn compliance, is understood for each business stream
Creation and maintenance of a “security toolkit” with templates of key processes and controls, communicated in language that is relevant and understandable to all audiences
Support on security incidents by bringing together business and technical knowledge to aid impact analysis and response
People and performance management of Business Information Risk Analysts

Knowledge and experience of information security risk management frameworks and procedures
Experience of formal risk identification, assessment, and quantification methods
Experience of service, performance, and people management to achieve defined outcomes
A good understanding of security frameworks including ISO27001/2, Cyber Essentials Plus, CIS Top 20, Data Protection Act 2018, OWASP Top 10.
we’ll recognise and value you for who you are and celebrate and reward your contributions to the business. We’re committed to agile working, and we offer every colleague the opportunity to work in ways that suit you, your teams, and the task at hand.
At BDO, we’ll help you achieve your personal goals and career ambitions, and we have programmes, resources, and frameworks that provide clarity and structure around career development.
Our agile working framework helps us stay connected, bringing teams together where and when it counts so they can share ideas and help one another. BDO’s people represent a wealth of knowledge and expertise, and we’ll encourage you to build your network, work alongside others, and share your skills and experiences. At BDO, we help entrepreneurial businesses to succeed, fuelling the UK economy. Across the UK thousands of unique minds continue to come together to help companies we work with to achieve their ambitions



  • London, United Kingdom Information Security Solutions Full time

    Company: Financial Services Location: Hybrid - City of London Reports to Information Risk Manager **Salary**: £80,000 Benefits: Generous No. Required: 1 Start Date: ASAP **The Role** As the Information Security Risk Specialist, you shall support the Information Risk Manager which has responsibility for all Governance Risk and Compliance activities...


  • London, United Kingdom Hays Specialist Recruitment Limited Full time

    Business Information Risk Officer - London (Hybrid) Principal Accountabilities: - Lead CISO's risk management service to the relevant streams, including responsibility for the performance management of the service and a team of Business Information Risk Analysts - Utilising client information security risk management tools, procedures and control framework...


  • London, United Kingdom Bench IT Full time

    Business Information Risk Officer (BIRO) - London - £58,000 - 68,000 Leading professional services company is actively recruiting for an experienced Business Information Risk Officer (BIRO) to assist the CISO manage information security risk. This role will play a key part in ensuring the effectiveness of the informationsecurity risk management framework,...


  • London, United Kingdom LT Harper Full time

    **Business I**nformation Security Officer BIRO** **A newly Created Role - A new opportunity!** **Location - Hybrid - Home / London (1 every 2 weeks)** **Salary £70 - 85k** The emergence of the BISO role is a **huge step towards InfoSec being accepted as an integral part of business** and realising the potential for the revenue enhancing benefits of...


  • London, Greater London, United Kingdom Rewardgateway Full time

    Reward Gateway Seeks Chief Information Risk OfficerWe offer a salary range of £145,000 - £155,000 per year for our Chief Information Risk Officer position. In this role, you will lead the charge in identifying and mitigating risks to Reward Gateway's information assets, ensuring the organization remains resilient in an ever-evolving threat landscape.As a...


  • London, Greater London, United Kingdom Deutsche Bank Full time

    About Us: Deutsche Bank is a leading German bank with strong European roots and a global network. We strive for a culture in which we empower each other to excel every day. Job Summary: We are seeking a Chief Information Risk Officer to join our team at Deutsche Bank. The successful candidate will have significant experience in cybersecurity and risk...


  • London, United Kingdom Paritas Recruitment - Risk Full time

    A major bank are currently seeking a Senior Data Risk Officer to join their London based Risk Department. This specific role will focus on Data Risk and Information Risk, as well as managing BCBS239 PERDARR implementation in the UK Bank. The Senior Data Risk Officer will improve Risk Reporting in the UK Bank to drive Data Compliance across Data Governance,...


  • London, United Kingdom Barclays Full time

    **Business Information Security Officer - BISO Digital** **London, Canary Wharf** As a Barclays Business Information Security Officer you will deliver the CISO/CSO (Chief Information Security Office) goals and cyber security agenda within the business. You will be responsible for security posture communication, business security awareness, governance and...


  • London, Greater London, United Kingdom Boston Hale Full time

    Job Title: Chief Information Risk OfficerLocation: London, UKSalary: £95,000 - £115,000 per annum (plus benefits)Company Overview:Boston Hale is a leading provider of recruitment services, helping businesses find the best talent for their teams.Job Description:We are seeking an experienced Chief Information Risk Officer to join our team. As the Global Head...


  • London, United Kingdom Hays Specialist Recruitment Limited Full time

    Exciting Opportunity - Business Information Risk Analyst - London In this role you will: - Utilise the client's information security risk management tools, procedures and control framework to ensure an accurate risk posture is understood and defined for each business stream. - Support the CISO team in maintaining 'information security risk communities' in...


  • London, Greater London, United Kingdom Audit & Risk Recruitment Full time

    Cybersecurity threats are increasingly prevalent, making it essential for organisations to have robust IT risk management and control frameworks in place. As a Cybersecurity Risk Officer, you will play a critical role in identifying, assessing, and mitigating IT-related risks within our client organisation.You will be responsible for developing and...


  • London, United Kingdom Quantum Group Full time

    **We have an urgent open position for Business Information Security Officer role into a International Bank in Moorgate.** **Key Responsibilities for Business Information Security Officer** - Ensure compliance with the information security policies, directives and guidelines - User access rights management, including annual review of access management -...


  • London, United Kingdom Business Smart Solutions Full time

    Business Smart Solutions are please to be working with a Local Authority in East London, seeking an experienced 'Information Governance and Data Protection' professional. - Advising on Data Protection Impact Assessments - Undertaking and advising on Information Risk Assessments - Advising on Disclosures (including FOIs, SARs, EIRs) - Managing data breaches -...

  • Risk Officer

    7 months ago


    London, United Kingdom Department for Business, Energy & Industrial Strategy Full time

    **Details**: **Reference number**: - 288381**Salary**: - £37,470 - £45,565- National: £37,470 - £41,925; London: £41,055 - £45,565**Job grade**: - Senior Executive Officer**Contract type**: - Permanent**Business area**: - BEIS - Market Frameworks - Market Frameworks - Office for Product Safety and Standards Directorate**Type of role**: -...


  • London, United Kingdom eFinancial Careers Full time

    ** Information Security Officer - GRC - Risk and Controls - Cloud Technology - Cyber Security Information Security Officer is required to join a leading Financial Services organization to work on the review and implementation of cyber security technologies, risk and controls. Based in London (hybrid working), this is a permanent role offering between£85,000...


  • London, United Kingdom Canada Life Full time

    We’ve been supporting the financial, physical and mental wellbeing of Canadians for 175 years. We are looking for an AVP, Business Information Security. In today’s dynamic business and technology landscape, information security needs to be a strategic partner of the business that actively supports and enables the organizational goals. The AVP,...

  • Risk & Control Officer

    6 months ago


    London, United Kingdom Paritas Recruitment - Risk Full time

    K- Posted by - Keith Jones- Manager - Risk Management & Quantitative Analytics Operational Risk and Control professional who has strong corporate / commercial banking experience is sought by a leading bank based in the City. Risk & Control Officer A European Bank in the City is seeking a Risk and Control Officer to join their expanding risk management...


  • London, Greater London, United Kingdom Deutsche Bank Full time

    Key Responsibilities:Lead Conduct Risk and Control Assessments across business portfoliosDevelop and implement effective risk management frameworks and proceduresCollaborate with 2nd Line of Defence (2LoD) and Non-Financial Risk Management (NFRM) teams to ensure alignment with Group-wide minimum control standards and risk appetite frameworkPartner with...


  • London, Greater London, United Kingdom Bestmansolutions Full time

    About the RoleAs a Chief Information Risk Officer at Bestman Solutions, you will be responsible for identifying and mitigating potential security risks that could impact our clients' information assets.Your primary focus will be on developing and implementing effective information security management practices, working closely with the CISO and other key...


  • London, United Kingdom Simply Business Full time

    **We’re Simply Business** We insure small businesses and enable big dreams - not just for our customers, but for our people and communities too. With over 850,000 active insurance policies, we protect builders, bakers, landlords, and more than 1,000 other trades. We harness cutting-edge data ability, believe in experimentation, and build our own...