Overview
In this role you will lead cyber risk and assurance across a large, complex organisation to strengthen cyber resilience and regulatory compliance. You’ll operate in the second line of defence, shaping the risk management framework and challenging risk and control activities across IT and OT. You will oversee assurance programmes, third‑party cyber risk, and senior‑level reporting to enable informed risk decisions. The position offers strategic influence on cybersecurity strategy within critical national infrastructure and close collaboration with regulators, auditors, and leadership.
Pay / Benefits
- Double match pension up to 10%
- Private healthcare
- 36 days annual leave
- Electric Vehicle Schemes
- Cycle to Work scheme
- Sharesave/Share Incentive Plan
Responsibilities
- Oversee risk assessments, control reviews, and assurance programmes across IT and OT
- Lead a team of cyber risk and assurance specialists
- Monitor the organisation’s cyber risk posture and assurance activities
- Provide senior stakeholders with risk insights for decision making
- Embed a strong risk culture and promote accountability for cyber risk across the business
- Influence cyber security strategy across a large, complex organisation
- Engage with regulators, auditors, and industry bodies
- Manage third‑party cyber risk management
Key requirements
- Experience in cyber risk management, governance, and assurance
- Knowledge of recognised cyber risk frameworks and industry standards
- Ability to translate complex cyber risks into business language
- Strong leadership, strategic thinking, and communication skills
- Experience developing and delivering assurance programmes in large organisations
- Understanding of regulatory landscape affecting critical national infrastructure (NIS Regulations, NCSC CAF, energy sector requirements)
- Industry certifications such as CISSP, CISM, GICSP or equivalent (desirable)
- Stakeholder engagement across all levels
- Stakeholder engagement
- Leadership
- Strategic thinking
- Cyber risk management
- Governance and assurance
- Regulatory compliance knowledge
…
