Skip to main content
AfterDuty

Business Information Security Officer

Bloomberg · London, Greater London

Type
Full-time
Posted
Yesterday

Overview

This role focuses on information security management, risk assessment, and incident response — areas where your experience in operational policing, threat assessment, and managing critical incidents translates directly. Your background in following strict procedures, handling sensitive information, and coordinating multi-agency responses aligns well with the security governance and compliance aspects of the job. While the role requires specific technical cyber security knowledge, your investigative mindset and ability to work under pressure are strong foundations that employers in this sector

About this role

Our Team

We protect Bloomberg. The Bloomberg Information Security Office team is dedicated to making our products and technologies as secure as possible through design, development, and operation. We report into the Chief Information Security Office while working closely with regulated businesses, key lines of business, and development/engineering across Bloomberg L.P. Our colleagues depend on us to help design, run, and improve our most important security programs.

What's in it for you

The Bloomberg BISO team focuses on identifying opportunities to improve the security of Bloomberg, our products and services, and the security of our customers’ data. In this role, you will be the owner, manager, and developer of multiple security programs, each with unique challenges and in a global setting. You will be responsible for setting strategic direction, evangelizing security and compliance efforts, and influencing the direction of Bloomberg L.P.’s business efforts all in a day’s work.

We'll trust you to

  • Develop a deep understanding of your business domains, keeping abreast of new technologies, regulatory changes, and industry best practices as you design, lead, and oversee the information security programs for your lines of business.
  • Work with stakeholders to effectively manage cyber risk including consulting on security controls, mitigation strategies, and incident response planning and management.
  • Foster cross-functional relationships between teams to improve all aspects of our security program.
  • Define and develop management information, including key risk indicators, program maturity indicators, and key performance indicators for use in reporting.
  • Establish and review information security policies and procedures in your line of business.
  • Become a trusted voice to senior management, report on the status of information security programs to boards and various governance forums.
  • Lead in the development and delivery of scenario testing such as Tabletop Exercises and Threat Led Penetration Testing.
  • Lead remediation efforts and support transformational change initiatives across the broader organization.

We'd love to see

  • 7+ years of experience in information security, cyber security risk management, data security and cyber security regulation.
  • Demonstrated ability to influence internal and external stakeholders to achieve success in a complex global setting.
  • Proven delivery of complex projects involving cross-functional teams.
  • Ability to proactively identify and manage cyber security risks to deliver services and meet business objectives in a secure and compliant way.
  • Strong technical knowledge in key cyber security domains such as cloud security, network security and architecture, application security, secure software development lifecycle (SSDLC) and vulnerability management.
  • Proven experience in delivering Threat Led Penetration Tests such as CBEST or equivalent TLPT regimes.
  • Good knowledge of key technologies such as Operating Systems, Software Development Build Pipelines and Processes, Security Tooling, O365 Suite, and Business Intelligence Tools.
  • Experience with industry standards such as NIST CSF and ISO 27001.
  • Knowledge and experience with Regulation pertaining to Information Security such as DORA, Operational Resilience, UK CTP Regime, GDPR.
  • Excellent written and oral communication skills.
  • Demonstrated ability to perform under pressure and consistently meet program deadlines.
  • An industry recognized certifications such as CISSP, GIAC, CISM, ISO 27001 Lead Implementor/Auditor.

If indicated, please note that years of experience are a guide; we will consider applications from all candidates who can demonstrate the skills necessary for the role.

Discover what makes Bloomberg unique - watch our podcast series for an inside look at our culture, values, and the people behind our success.

Accommodations

Bloomberg provides reasonable adjustment/accommodation to individuals with disabilities. Please tell us if you require a reasonable adjustment/accommodation to apply for a job. Examples of reasonable adjustment/accommodation include but are not limited to making a change to the application process or work procedures, providing documents in an alternate format or using specialized equipment. To request an adjustment/accommodation to apply for a job, please email AMER_recruit@bloomberg.net (Americas), EMEA_recruit@bloomberg.net (Europe, the Middle East and Africa), or APAC_recruit@bloomberg.net (Asia-Pacific), based on the region you are submitting an application for. We may share your information with a third party provider of accommodations services who may use this information to reach out to you for the purposes of accommodating your application.

Equal Opportunity

Bloomberg is an equal opportunity employer and prohibits discrimination in employment. It is Bloomberg’s policy to provide equal opportunity and access for all persons, and the Company is committed to attracting, retaining, developing, and promoting the most qualified individuals without regard to age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, self-identified or perceived sex, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy, childbirth or related medical conditions, or parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law (each, a “Protected Characteristic”). Bloomberg prohibits treating applicants or employees less favorably in connection with the terms and conditions of employment, in all phases of the employment process, because of one or more Protected Characteristics.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 75/100

  • Incident command & response
  • Working to legislation & regulation

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your experience in policing has given you a strong foundation in risk assessment, threat identification, and incident management, which are directly applicable to IT risk management. You are used to working under pressure, making decisions based on incomplete information, and communicating complex risks to senior stakeholders. While you may need to develop specific technical knowledge of IT frameworks like ISO 31000 or NIST, your core skills in evaluating threats, implementing controls, and ensuring compliance are highly transferable to this role.

    Posted Yesterday

  • Privacy Operations Manager

    Thomson Reuters · London

    Full-time

    Your experience managing sensitive information under strict legal frameworks like PACE, RIPA, and CPIA gives you a strong foundation for privacy compliance and data protection. The incident command and risk assessment skills you developed in policing translate directly to coordinating cyber incident response and conducting privacy impact assessments. Your ability to lead operational teams and work across agencies prepares you to embed privacy-by-design principles and manage global privacy operations.

    Posted 2 days ago

  • Your experience managing complex incidents, assessing threats, and coordinating multi-agency responses in policing directly prepares you for leading cyber security engagements and advising clients on risk and resilience. The role's focus on stakeholder management, conducting assessments, and developing security strategies mirrors the analytical and command skills you've honed, and your security clearance eligibility is a strong asset in this defence and security consultancy.

    Posted 5 days ago

  • Director - Business Audit

    Mastercard · London

    Full-time

    Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper.

    Posted 6 days ago