← All jobs

Business Information Security Officer (BISO)

Southampton, United Kingdom Full-time
Information Security LeaderCyber Assurance ManagerCompliance ManagerCompliance OfficerSecurity AnalystSecurity EngineerCyber Security EngineerRisk Analyst

Archer is matching candidates to this role at Kingfisher. Create a free profile and Archer will check you against this role and every other live role, showing you exactly where you match.

We’re Kingfisher, A team made up of over 74,000 passionate people who bring Kingfisher - and all our other brands: B&Q, Screwfix, Brico Depot, Castorama and Koctas to life. Guided by our purpose Better Homes. Better Lives. For Everyone. We believe a better world starts with better homes, and we work every day to make that a reality. Join us and help shape the future of home improvement.

Role purpose 

As a senior cybersecurity leader, the Business Information Security Officer (BISO), known internally as Banner Information Security Officer, acts as the key link between the Information Security team and assigned business functions. The role is responsible for aligning security strategy with business objectives, providing trusted security guidance, and ensuring cybersecurity considerations are embedded within business operations, projects, and decision-making. The BISO works closely with stakeholders across the organisation to strengthen security posture, manage risk, and support the delivery of business goals in a secure and compliant manner.

Please note that this role can be based in Southampton or London Paddington with an expectation of 12 days per month in the office. 

  • Serve as the primary cybersecurity advisor and key liaison between the Security Function and business stakeholders, balancing operational needs with security requirements.
  • Build trusted relationships across the Banner/Group Functions, providing expert guidance and promoting a strong culture of cybersecurity awareness.
  • Own and maintain the cyber risk register, supporting risk-based decision making, prioritisation, reporting, and remediation tracking.
  • Ensure all projects, solutions, and business changes are delivered using Secure by Design principles, identifying control weaknesses and managing associated risks.
  • Lead security incident and breach response activities between Technology and the business, participating in the Cyber Security Incident Response Team (CSIRT) where required.
  • Drive assurance and governance activities by reviewing systems, applications, platforms, suppliers, and processes against security frameworks, policies, and standards.
  • Provide regular reporting and strategic insight to senior stakeholders, ensuring security strategy, vulnerability management, and business roadmaps are aligned with organisational goals and compliance requirements.
  • Extensive experience in Information Security or a related field, including leadership or management experience within IT or Cyber Security teams.
  • Strong knowledge of industry security frameworks and standards, including ISO 27001, NIST, OWASP, PCI DSS and NIS2.
  • Excellent communication skills, with the ability to translate complex technical concepts into clear, actionable guidance for both technical and non-technical audiences.
  • Deep understanding of cybersecurity risks, emerging threats, and their impact on business operations, with the ability to influence decision-making at all levels.
  • Proven ability to build trusted relationships with stakeholders, drive positive outcomes, and effectively challenge and influence behaviours when required.
  • Strong analytical, organisational and decision-making skills, with the ability to prioritise competing demands and balance risk against business objectives.
  • A proactive and collaborative leader who demonstrates integrity, sound judgement, regulatory awareness, customer focus and a commitment to fostering a positive team culture.

How We Work
We believe in flexibility and balance. Our hybrid model blends home working for focus with time spent connecting and collaborating - whether in our offices or at offsite locations. On average, around 60% of your time will involve in-person collaboration.

We value the perspectives new team members bring and encourage you to apply - even if you don’t meet 100% of the requirements.

What We Offer
An inclusive environment where your potential is limited only by your imagination. We encourage new ideas, support experimentation, and strive to create a workplace where everyone can be their best self. Find out more about Diversity & Inclusion at Kingfisher here.  

We also offer a competitive benefits package and plenty of opportunities to stretch and grow your career. 

Diversity & Inclusion
Our customers come from all walks of life - and so do we. We’re committed to ensuring all colleagues, future colleagues, and applicants are treated equally, regardless of age, gender, marital or civil partnership status, ethnicity, culture, religion, belief, political opinion, disability, gender identity, gender expression, or sexual orientation.

Interested? Great, apply now and help us to Power the Possible.

#LI-AK1

Apply knowing you're qualified

One free profile is all it takes. Archer checks you against this role and every other live role we list, and shows you exactly which requirements you meet before you apply.

Not quite the right role?

Archer scans thousands of live roles and surfaces the ones you genuinely match, each with a clear explanation of why. It keeps working after you apply, so you hear about roles you would never have found by searching.

Create your free profile