Business Information Security Officer (BISO)
Core
Lead the CISO office's work on internal control, audit readiness, and the implementation of security frameworks (ISO 27001, SOC 2, NIS2, DORA) and AI governance for a professional services firm.
Role type
Senior IC Business Information Security Officer (BISO)
Builds
Internal control frameworks, audit evidence, security risk assessments, and AI governance policies
Domain
Professional services / Information Security / Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Information security governance, IT risk management, internal control testing, ISO 27001 implementation, SOC 2 compliance, NIS2 compliance, DORA compliance, AI risk management, security awareness campaign management
Preferred skills
Security project management, hands-on IT or cybersecurity experience, AI governance expertise
Technologies
ISO 27001, SOC 2, NIS2, DORA
Responsibilities
Lead the CISO office's work on the internal PwC control framework and act as SME for internal audit; Drive the implementation and upkeep of ISO 27001, SOC 2, NIS2, and DORA; Lead the global and local annual security risk assessment; Implement and maintain the firm's approach to AI governance and risk management; Partner with internal committees to embed security requirements across the business
Seniority
Senior, hands-on IC
