BISO (Business Information Security Officer) (Melbourne)

BISO (Business Information Security Officer) (Melbourne)

02 Aug
|
Rea Group
|
Melbourne

02 Aug

Rea Group

Melbourne

Overview

We’re establishing a Business Information Security Officer (BISO) function to bridge our central Security team and our business units. The BISO for Financial Services (FS) will be the first role of its kind in our organisation—and you’ll help shape what this function looks like across the company.

What You’ll Do

- Serve as the trusted security leader to FS Technology and Business leadership.
- Participate on the FS Product and Technology Leadership team.
- Translate central security policies and initiatives into reasonable guidance for FS.
- Support the response to any security incidents that occur in FS.
- Advise on security implications of current products, features, and technology decisions.
- Champion security culture and awareness within the business unit.

Drive Alignment Between Security and FS

- Articulate FS's unique security and compliance requirements to the central Security team.
- Advocate for FS priorities in the security roadmap planning and resource allocation.
- Ensure central security services understand FS context when supporting the business unit.
- Provide input on enterprise security policies to ensure they are practical for regulated financial services.

Navigate Regulatory Complexity

- Develop deep understanding of the regulatory obligations relevant to FS (credit licensing, responsible lending, data retention).
- Partner with FS Compliance and Legal to ensure security controls meet regulatory expectations.
- Support regulatory engagement, audits, and examinations as the security subject‑matter expert.
- Stay current on evolving regulatory requirements and their security implications.

Drive Risk Management

- Conduct security risk assessments specific to the FS business unit.
- Work with the risk team to ensure that cyber security risks are on the FS security risk register and are appropriately identified, assessed, and communicated.




- Support risk acceptance decisions with clear articulation of residual risk.

Enable Secure Delivery

- Engage early in product and technology initiatives to embed security by design.
- Review architectural decisions and technology choices for security implications.
- Coordinate with central Product Security on application security activities for FS systems.
- Support incident response within FS, acting as the liaison to central Detection & Response.

Build Relationships and Influence

- Develop solid working relationships with FS engineering, product, and business leaders.
- Influence security outcomes through partnership rather than mandate.
- Communicate security concepts in business terms that resonate with non‑technical stakeholders.
- Build trust as someone who enables the business, not blocks it.

Experience

- 8+ years in information security, risk management, or related technical roles.
- Experience working in or supporting regulated financial services considered a positive, but not required.
- Demonstrated ability to work across organisational boundaries and influence without authority.
- Track record of translating technical security concepts for business audiences.
- Experience with security risk assessment and risk management frameworks.

Knowledge

- Broad security knowledge including app & cloud security, identity, data protection, and GRC.
- Familiarity with security frameworks (e.g. NIST CSF, ISO 27001) and how to apply them pragmatically.
- Awareness of threats and attack techniques relevant to financial services.




- Understanding of Australian financial services regulatory environment considered useful, but not required.

Skills

- Exceptional communication skills for technical and non‑technical audiences.
- Ability to build trust and credibility quickly with senior stakeholders.
- Comfort operating in ambiguity and navigating competing priorities.
- Strong analytical and problem‑solving capabilities.
- Ability to work independently while maintaining alignment with central teams.

Mindset

- Business‑first: You understand that security exists to enable the business, not the other way around.
- Pragmatic: You find ways to manage risk that work in the real world, not just on paper.
- Relationship‑oriented: You know that influence comes from trust and relationships.
- Curious: You ask questions, seek to understand context, and learn continuously.

Nice to Have

- Experience in a BISO, divisional security, or embedded security role.
- Background in mortgage broking, consumer credit, or lending technology.
- Familiarity with Australian privacy law and its application to financial services.

Benefits

- A hybrid and flexible approach to working.
- Flexible leave options including birthday leave and purchase additional leave.
- Flexible parental leave offering for primary and secondary carers.
- Because We Care program offers volunteering leave, community grants, matched payroll giving and community café donations to charity.
- Hackdays to bring big ideas to life.

Diversity, Equity, and Inclusion

We are committed to providing a working environment that embraces and values diversity, equity and inclusion. If you have the skills and dedication but don’t meet every single point on the job description, please still get in touch.

Join our Talent Neighbourhood

Perhaps the timing isn’t right for this role? You can join our Talent Neighbourhood to stay in touch for future opportunities.

#J-18808-Ljbffr

📌 BISO (Business Information Security Officer) (Melbourne)
🏢 Rea Group
📍 Melbourne

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: biso (business information security officer) (melbourne) / melbourne