Overview
In this role you own and lead multiple security programs across Bloomberg’s lines of business, shaping strategic security and compliance direction in a global setting. You’ll collaborate with stakeholders to manage cyber risk, design controls, and drive incident response activities. You will report on risk, program maturity, and KPIs to senior leadership and boards, while evangelizing security across teams. This is a chance to influence secure product development and protect customer data at scale in a dynamic, regulated environment.
Responsibilities
- Develop and oversee information security programs for multiple business lines in a global context
- Consult stakeholders on security controls, risk mitigation, and incident response planning
- Foster cross-functional relationships to improve the security program
- Define and report on management information such as KRIs, maturity indicators, and KPIs
- Establish and review information security policies and procedures within business lines
- Provide status updates on security programs to senior management and governance forums
- Lead scenario testing activities (Tabletop Exercises, Threat Led Penetration Testing)
- Drive remediation efforts and support transformational security initiatives across the organization
Key requirements
- 7+ years in information security, cyber risk management, data security, and relevant regulations
- Ability to influence diverse stakeholders in a complex global setting
- Proven track record delivering complex cross-functional projects
- Proactive risk identification and management to meet business objectives securely
- Strong knowledge across cloud security, network and architecture, app security, SSDLC, and vulnerability management
- Experience delivering Threat Led Penetration Tests (e.g., CBEST)
- Knowledge of OS, build pipelines, security tooling, O365 Suite, and BI tools
- Experience with NIST CSF and ISO 27001; familiarity with GDPR, DORA, UK CTP Regime, Operational Resilience
- Excellent written and oral communication; ability to perform under pressure and meet deadlines
- Industry certifications such as CISSP, GIAC, CISM, ISO 27001 Lead Implementor/Auditor
- Influence and stakeholder management
- Clear communication (written and spoken)
- Resilience under pressure
- Cloud security
- Network security and architecture
- Application security and SSDLC
…
