We are seeking a seasoned Business Information Security Officer (BISO) to serve as the strategic security partner to business and technology stakeholders. This role will bridge cybersecurity, technology risk, and business functions, ensuring that security is embedded into business initiatives, digital transformation, and technology delivery.The BISO will play a critical role in translating enterprise security strategy into actionable initiatives aligned with business priorities, while proactively managing cyber risk in a complex, fast-paced banking environment. ResponsibilitiesBusiness Engagement & AdvisoryAct as the primary security advisor to business units, providing guidance on cyber risk, security architecture, and secure solution designPartner with business, product, and engineering teams to embed security into digital initiatives, platforms, and application development lifecyclesTranslate technical risks into business impact and actionable insights for senior stakeholdersSecurity Risk ManagementIdentify, assess, and manage technology and cyber risks across business-aligned portfoliosPerform and oversee application security risk assessments, ensuring risks are identified early in the development lifecycleDrive risk-based decision-making, including risk prioritisation, mitigation planning, and tracking of remediation effortsThreat Modelling & Application SecurityLead and facilitate threat modelling exercises for critical applications, systems, and digital platformsCollaborate with engineering teams to identify attack surfaces, abuse cases, and potential vulnerabilitiesEnsure secure design principles are embedded across APIs, cloud-native applications, and distributed architecturesPromote and integrate secure SDLC and DevSecOps practices, including code scanning, dependency management, and security testingSecurity Strategy & ImplementationDrive the implementation of enterprise security strategy within assigned business domainsCollaborate with central security teams (e.g., Security Engineering, SOC, GRC) to ensure consistent and scalable security controlsSupport adoption of Zero Trust, cloud security, and modern application security practicesStakeholder Management & ReportingProvide regular updates to senior leadership on cyber risk posture, key threats, and mitigation progressInfluence decision-making at senior management and executive levelsDrive security awareness and secure-by-design culture across the business
RequirementsMinimum 15+ years of experience in cybersecurity, technology risk, or information security, preferably within banking or financial servicesProven experience in a BISO, Application Security, or senior security advisory role, working closely with business and engineering stakeholdersStrong hands-on experience in threat modelling and application security risk assessmentsSolid understanding of modern application architectures, including cloud-native, microservices, and APIsExperience implementing DevSecOps practices and secure SDLC frameworksBroad knowledge across security domains, including IAM, data protection, cloud security, and incident responseDemonstrated ability to translate technical security risks into business outcomes and influence senior stakeholders
To apply: If you're interested to apply or find out more, please share across your CV or reach out to Chen Yi at cy@kerryconsulting.com for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified. Reg: R1876389 Lic: 16S8060