Overview
You will help financial services clients strengthen cyber and operational resilience, guiding risk assessments, framework implementation, and incident readiness. As part of a collaborative, innovative team, you’ll tackle complex security challenges across banking, payments, and markets. You’ll translate regulatory requirements into actionable policies and drive resilience programs. This role offers exposure to cutting-edge technologies and a clear path to grow within a global network.
Pay / Benefits
- 30 days annual leave
- Private medical insurance
- Three days volunteering leave per year
- Industry-leading learning and certifications
- Flexible and hybrid working arrangements
- Opportunities to work with leading financial institutions
Responsibilities
- Identify, assess, and manage cyber, technology, and operational resilience risks for critical services
- Develop and implement cyber resilience, operational resilience, and technology risk management frameworks
- Conduct risk assessments, control reviews, and resilience evaluations to find vulnerabilities
- Design and run scenario testing, cyber exercises, tabletop exercises, and resilience validation activities
- Evaluate security controls against regulatory requirements and industry standards
- Identify important business services, impact tolerances, and supporting assets within resilience programs
- Support third-party and supply chain risk management, including due diligence
- Assist clients in preparing for, responding to, and learning from cyber incidents
- Translate regulatory requirements into practical policies and implementation plans
- Produce risk reports and stakeholder presentations; collaborate across security, risk, compliance, and business teams
- Support workshops, assessments, maturity reviews, and transformation programs
Key requirements
- Bachelor’s degree in Cyber Security, Information Technology, Business, Risk Management, Finance, or related discipline
- Experience in cyber security, technology risk, operational resilience, or related field
- Experience in financial services or other heavily regulated industries
- Understanding of cyber risk management, operational resilience, business continuity, disaster recovery, and incident response
- Knowledge of NIST, ISO 27001, COBIT, CIS Controls, FFIEC guidance
- Familiarity with financial services regulatory requirements relating to technology risk and resilience
- Experience conducting risk assessments, audits, compliance assessments, or governance activities
- Strong analytical and problem-solving skills; ability to develop practical recommendations
- Excellent written, verbal, and stakeholder management skills
- Experience leveraging AI-enabled tools to improve efficiency or risk outcomes
- Preferred: professional certifications such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer/Auditor; regulatory program experience (PRA, FCA, DORA, NIS2, ECB, EBA)
- Understanding of cloud risk, third-party risk, and supply chain security
- Analytical mindset
- Strong communication and stakeholder management
- Collaborative, cross-functional work
- NIST
- ISO 27001
- COBIT
…
