Skip to content

Business Information Security Officer

  • Hybrid
    • Bucharest, București, Romania
  • IT Services

Job description

This role requires someone who is comfortable operating in a complex and evolving landscape. The environment includes a significant legacy footprint, multiple technology generations, and a diverse ecosystem of internal and external stakeholders. You will need to balance strategic thinking with pragmatic execution, helping modernize security while supporting business continuity.

Success in this role will depend not only on strong information security expertise, but also on the ability to influence, build trust, and navigate stakeholders with different priorities and varying levels of security maturity. You'll play a key role in rebuilding confidence by delivering practical, incremental improvements while contributing to the long-term security transformation of the business.

This is a highly visible opportunity for someone who understands both the technical threat landscape and the operational realities of retail, including seasonal peaks, POS infrastructure, and third-party vendor ecosystems, and who thrives in driving meaningful change within a complex enterprise environment.

Key Responsibilities

  • Act as the primary security advisor to Retail business unit leadership, aligning security priorities with merchandising, store operations, and supply chain roadmaps

  • Identify, assess, and communicate security risks in business terms, translating technical findings into revenue, brand, and operational impact for non-technical executives, IT and business leaders

  • Own security risk oversight for business projects

  • Evaluate security risk for seasonal and peak-volume events, including surge capacity and incident readiness

  • Partner with business, IT, procurement and legal on third-party and vendor risk assessments for retail suppliers, payment processors, and SaaS platforms

  • Advise on secure design for new retail technology initiatives and enterprise infrastructure changes

  • Track and report the business unit's risk posture, control gaps, and remediation progress to both business leadership and the CISO

  • Lead incident response coordination for security events affecting stores, e-commerce, or customer data, ensuring timely and clear communication to stakeholders

  • Deliver security awareness training tailored to store operations staff, corporate retail teams, and seasonal workers

  • Support budget planning and prioritization of security investments based on retail-specific risk exposure

Job requirements

Required Qualifications

  • Bachelor's degree in Information Security, Computer Science, or related field, or equivalent practical experience

  • 5–6 years of experience in information security, IT risk, or security risk advisory roles, including experience supporting a business unit or line of business directly

  • Solid understanding of retail technology environments — POS systems, supply chain systems, and third-party integrations

  • Strong grasp of security frameworks and risk methodologies (NIST CSF, ISO 27001, CIS Controls)

  • Excellent communication and stakeholder management skills, with a track record of influencing business decisions without direct authority

  • Experience conducting or overseeing third-party/vendor risk assessments

  • Experience in transformation projects at enterprise level

  • Fluent in French and English

Preferred Qualifications

  • Relevant certification such as CISSP, CISM, or CRISC

  • Prior experience in a BISO, security risk advisor, or embedded security liaison role

  • Experience supporting security during high-volume seasonal events

  • Exposure to GRC tooling and security metrics/reporting dashboards

Key Competencies

  • Business acumen paired with deep security expertise

  • Comfortable operating in ambiguity and fast-paced retail cycles

  • Strong influence and relationship-building skills across all levels of the organization

  • Risk-based, pragmatic decision-making that balances security with business velocity

  • Sound judgment under pressure, particularly during incidents or peak retail periods

or

Hybrid
  • Bucharest, București, Romania
IT Services