Business Information Security Officer (BISO)

Company: Kingfisher
Apply for the Business Information Security Officer (BISO)
Location: Southampton
Job Description:

Overview

In this senior cybersecurity leadership role, you will align security strategy with business objectives and act as the main link between Security and Banner/Group Functions. You will embed cybersecurity considerations into operations, projects and decision-making, while strengthening the organisation’s security posture. You will manage risk, lead governance and provide trusted security guidance to stakeholders across the business. This role offers exposure to enterprise-scale security challenges within a large, multis-brand retailer. You will shape secure delivery, incident response, and strategic planning to enable safe business growth.

Pay / Benefits

  • competitive benefits package
  • hybrid working model
  • flexible office/remote balance
  • opportunities to grow and stretch career
  • inclusive and diverse environment

Responsibilities

  • Act as primary cybersecurity advisor to business stakeholders, balancing operational needs with security requirements
  • Build trusted relationships and promote a culture of cybersecurity awareness
  • Own and maintain the cyber risk register, supporting risk-based decisions, prioritisation, reporting and remediation
  • Ensure Secure by Design across projects, solutions and changes, identifying control weaknesses and risks
  • Lead security incident and breach response activities and participate in CSIRT when required
  • Drive assurance and governance by reviewing systems, applications, suppliers and processes against standards
  • Provide regular reporting and strategic insights to senior stakeholders, aligning security with business roadmaps and compliance

Key requirements

  • Extensive experience in Information Security or related field with leadership/management experience
  • Strong knowledge of ISO 27001, NIST, OWASP, PCI DSS and NIS2
  • Excellent communication to translate complex concepts for technical and non-technical audiences
  • Ability to influence decision-making and manage cybersecurity risk affecting business operations
  • Proven stakeholder relationship building and ability to drive positive outcomes
  • Analytical, organisational and decision-making skills with prioritisation capability
  • Proactive, collaborative leadership with integrity and regulatory awareness
  • strong communication
  • stakeholder management
  • collaboration
  • ISO 27001
  • NIST
  • OWASP

Posted: September 14th, 2026