Location: Surrey, UK (Hybrid)
About the Company
A global financial services organisation with more than 50 years of history is continuing to invest in its Cyber & Information Security function.
The Cyber Effectiveness & Insight team provides the evidence and analysis needed to understand how the firm’s cyber posture is changing, where controls are performing well, where they are falling short, and where investment is needed.
The Role
This is a senior leadership role responsible for building a clear, evidence-based view of cyber effectiveness across the organisation.
You’ll lead the function responsible for cyber measurement and reporting, security data, control testing, maturity assessment, benchmarking, cyber risk quantification and executive insight.
The goal is to bring these areas together into one coherent view of cyber posture and control effectiveness, giving Security and business leaders a better understanding of where risk is changing and where action is required.
You’ll be responsible for turning technical and security data into insight that can be used by senior leadership and the board to make decisions around risk, priorities and investment.
The role covers:
This is a first-line role, rather than a second-line Enterprise Technology Risk position. You won’t own risk appetite or independent oversight. Instead, you’ll build the evidence, transparency and analysis that allow accountable risk owners to understand their position and make better decisions.
What They’re Looking For
Why Join
This is an opportunity to build out a function that sits close to the CISO and has a direct influence on how cyber investment and priorities are decided.
Rather than owning a traditional GRC or second-line risk function, you’ll be responsible for answering a more practical question: how effective is our security, where are the gaps, and what should we do about them?
You’ll have broad ownership across cyber data, control effectiveness, assurance and risk insight, with visibility at executive and board level.
Consultant












