Talent.com
Crown Agents Bank
Cyber Security ManagerCrown Agents Bank • London, England, UK
Cyber Security Manager

Cyber Security Manager

Crown Agents Bank • London, England, UK
30+ days ago
Job type
  • Full-time
Job description

Role Purpose

This is a specialist dual-focus role at the intersection of secure delivery and security assurance. You will own two primary programmes of work for Crown Agents Bank:

Security in Change: Acting as the security voice in project delivery conducting risk assessments reviewing architecture maintaining the Secure SDLC framework and providing formal security sign-off on material changes.

Security Assurance: Running the Banks security testing and vulnerability management programme commissioning and managing penetration tests owning vulnerability reporting and trend analysis managing attack surface visibility and working collaboratively across the business to drive remediation.

You will be technically credible enough to challenge architects and developers and clear and persuasive enough to land risk decisions with senior stakeholders. As part of a small high-trust CISO team you will also flex across the wider service catalogue beyond your primary accountabilities this provides variety genuine career breadth and direct visibility of the firms full security posture that a siloed role in a larger team would not.

Role Responsibilities

PILLAR 1 Security in Change

Primary accountability: own security throughout the project and change lifecycle

Own and maintain the Secure SDLC framework ensuring security requirements controls and standards are embedded across all material change programmes and project deliveries.

Conduct security risk assessments on new projects significant changes architecture proposals and new technology initiatives producing clear risk documentation and recommendations.

Provide architecture review and formal security sign-off for project delivery acting as the gating authority for security acceptance of changes into production.

Define and maintain application security standards including OWASP-aligned secure coding guidelines security requirements and application security testing criteria.

Act as the embedded security adviser to project and engineering teams providing practical timely guidance that enables secure delivery without impeding pace.

Contribute to third-party and vendor risk assessments for new solutions and integrations ensuring security due diligence is conducted as part of onboarding.

PILLAR 2 Security Testing & Vulnerability Management

Primary accountability: own the firms assurance and vulnerability posture

Own the vulnerability management programme end-to-end: aggregate and analyse data from Tenable and other scanning tooling maintain prioritisation logic based on exploitability asset criticality and business context and produce governance-ready reporting for ORC and senior stakeholders.

Commission scope and manage penetration tests (infrastructure application and where appropriate red team/social engineering) tracking findings through to remediation closure.

Own attack surface management maintain visibility of the firms externally exposed assets and services identify unmanaged or unexpected exposure and feed findings into the vulnerability management and pentest scoping pipeline.

Conduct technical analysis of vulnerability and assessment data to produce actionable prioritisation recommendations distinguishing between critical risk and noise.

Work collaboratively with Production Services engineering and infrastructure teams to promote and track remediation owning the reporting and assurance of remediation progress not the delivery of fixes.

Maintain and continuously improve vulnerability management tooling processes and SLA frameworks in line with the firms risk appetite.

Contributing Responsibilities

As part of a lean CISO team this role is expected to contribute across the following service areas as capacity and business need require:

Support ISO 27001 Cyber Essentials SWIFT CSP DORA and NYDFS Part 500 compliance activities within areas of ownership including evidence collection and control testing.

Contribute to security incident response where technical expertise in vulnerability exploitation application security or network threat analysis is relevant.

Support security awareness activities including specialist training content and targeted communiRole Purpose


Qualifications :

Qualifications Degree or equivalent professional experience in a relevant technical or security discipline. Professional certification one or more of the following is desirable:

Governance/management-oriented: CISSP CISM or equivalent

Offensive/technical-oriented: OSCP CEH GPEN GWAPT or equivalent

Additional certifications (AWS Security AZ-500 SC-200) are a plus Candidates with strong hands-on experience and demonstrable technical capability will be considered regardless of formal certification.

Experience Minimum 78 years experience in information security roles ideally with exposure to both technical delivery and governance functions.

Required:

Demonstrable experience owning or managing a vulnerability management programme including use of Tenable Qualys or equivalent scanning platforms.

Experience commissioning scoping and managing penetration tests and tracking remediation to closure.

Strong understanding of Secure SDLC frameworks (OWASP SAMM BSIMM or equivalent) and practical application security knowledge (OWASP Top 10 secure coding security requirements).

Experience conducting security risk assessments on projects changes or third-party integrations.

Excellent communication skills able to engage technical teams project managers and senior stakeholders with equal clarity.

Desirable:

Experience in or with a PRA/FCA dual-regulated financial institution.

Working knowledge of ISO 27001 SWIFT CSP DORA NYDFS Part 500 or Cyber Essentials.

Familiarity with attack surface management tooling or methodology.

Hands-on experience with Microsoft Defender for Endpoint Sentinel or equivalent security tooling.

Innovative mindset with a genuine interest in the evolving threat landscape including AI-driven threats and offensive tooling developments.


Additional Information :

Why Join Us

Be part of a small agile and collaborative team where your impact is direct and visible.

Opportunity to work on cutting-edge financial services and security projects.

Competitive salary and benefits including training and development support.

Hybrid working arrangements and a culture that values innovation and initiative.

Benefits include:

  • Hybrid working
  • Contributory personal pension plan: - Minimum: Employee 2% and Employer 7%. Employer matches contributions in 1% increments to a maximum of: Employee 5% and Employer 10%
  • Life Assurance 4 times annual salary
  • Group Income Protection
  • Private Medical Insurance this may include cover for partner and or children at company cost. Cover includes Optical Dental and Audiology
  • Discretionary Bonus
  • Competitive Annual Leave
  • 2 Volunteering Days
  • Benefit Hub


Remote Work :

No


Employment Type :

Full-time


Experience: years
Vacancy: 1
Create a job alert for this search

Cyber Security Manager • London, England, UK

Similar jobs

Head of Cyber Security and Productivity Solutions

M+C Saatchi UKGreater London, England, United Kingdom
Full-time

We are seeking an experienced Head of Cyber Security and Productivity Solutions to lead the protection of the company’s information, systems, and users across all global environments.This senior le... Show more

 • Promoted

Cybersecurity & Digital Trust VP — UK Growth Leader

CapgeminiGreater London, England, United Kingdom
Full-time

A global consulting firm is seeking a Vice President in Cyber Security to drive consulting offerings in the UK.This role involves leading sales, developing strategies, and nurturing client relation... Show more

 • Promoted

Security-Focused Network Engineer (Hybrid, London)

Hunter BondGreater London, England, United Kingdom
Full-time

Hunter Bond is seeking a Network Engineer (Security Focused) to join their elite tech firm based in London with a hybrid working model.Ideal candidates have 5+ years of experience and a strong inte... Show more

 • Promoted

Cyber Architecture Manager

Information Security SolutionsGreater London, England, GB
Permanent

Location: London/Peterborough, with potential travel to divisional sites as required by advisory engagements (hybrid working arrangements in place).Car allowance, Bupa, Matched pension contribution... Show more

 • Promoted

Cyber Risk & Security Manager

Spirit UK LtdGreater London, England, GB
Full-time

We are seeking an experienced Cyber Risk & Security Manager to lead the delivery of cyber risk assessments, governance advisory services, security maturity programmes, and SOC strategy engagements.... Show more

 • Promoted

Lead Cyber Security Analyst | Asset Manager | £200k - £200,000 A Year

Orbis GroupBethnal Green, United Kingdom Of Great Britain And Northern Ireland, UK
Full-time

Lead Cyber Security Analyst role with end-to-end InfoSec responsibility, including policies, vendor management, and risk advising. Show more

 • Promoted

Cyber Security Lead

QBE InsuranceLondon, England, GB
Full-time +2

Cyber Security Lead             .Hybrid role, happy to talk flexible working.QBE Europe is recruiting a Cyber Security Lead to join our European Cyber Security team in our London office.The role ha... Show more

 • Promoted

Senior Manager, Application Security & Secure SDLC

MiroGreater London, England, United Kingdom
Full-time

Miro in Greater London is looking for a Senior Manager of Application Security to lead their global security team and ensure security is integrated throughout the software development lifecycle.Thi... Show more

 • Promoted

Director, IT Security Third Party Monitor & Compliance

CLS GroupGreater London, England, United Kingdom
Full-time

Functional Title: IT Security Third Party Monitor & Compliance.Reports To: Executive Director, Head of IT Sec Transformation.Lead the set‑up, development and management of the new Third‑Party Secur... Show more

 • Promoted

Cyber Security Manager

Top RecruitGreater London, England, GB
Full-time

Join a leading Corporate Management Business.Lead on Cyber Security across the business.Top Recruit has partnered with a leading corporate travel management business.They are seeking an experienced... Show more

 • Promoted

Head of Telecoms, OT & Cyber Security

Future of LondonGreater London, England, United Kingdom
Full-time

TfL is seeking a Head of Profession – Telecoms & OT Cyber Security to provide enterprise-wide leadership for telecoms, connected systems and OT cyber security.You will shape technical strategy, est... Show more

 • Promoted

Chief Cyber Defence Centre | Lead Security Operations

Lloyds Banking GroupGreater London, England, United Kingdom
Full-time

Lloyds Banking Group is seeking a Head of Cyber Defence Centre to lead an engineering‑first Cyber Defence Lab responsible for designing, building and operating resilient security capabilities acros... Show more

 • Promoted

Sr Director Product Security – Cybersecurity

Nielseniq-Greater London, England, United Kingdom
Full-time

Sr Director Product Security – Cybersecurity.Full-time • Compensation: GBP 99,700 - GBP 160,000 yearly.The Product Security team at NielsenIQ is dedicated to enhancing business application security... Show more

 • Promoted

Sr Director Product Security – Cybersecurity

NielsenIQGreater London, England, United Kingdom
Full-time

Sr Director Product Security – Cybersecurity.Full-time • Compensation: GBP 99,700 - GBP 160,000 yearly.The Product Security team at NielsenIQ is dedicated to enhancing business application security... Show more

 • Promoted

Cyber Security Operations Manager

jobr.proGreater London, England, GB
Full-time

We are seeking a Security Operations Manager to lead and strengthen Frasers Group’s internal Security Operations Center (SOC), ensuring robust monitoring, detection, and response capabilities acros... Show more

 • Promoted

Sr Director Product Security - Cybersecurity

NablaGreater London, England, United Kingdom
Full-time

The Product Security team at NielsenIQ is dedicated to enhancing business application security and making product teams accountable throughout the software development lifecycle.It not only protect... Show more

 • Promoted

Cyber Security Manager

ElixirrGreater London, England, GB
Full-time

Elixirr International plc is a global consulting firm with a bold ambition: to become the best consulting firm in the world.Founded in 2009 to challenge a declining industry standard, we’ve grown f... Show more

 • Promoted

Cybersecurity Manager

Yolk Recruitment LtdLondon, England, GB
Permanent

This range is provided by Yolk Recruitment Ltd.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.Cyber Security Manager - £63,000 – Hybrid (London... Show more

 • Promoted

Cyber Risk Manager - Active Security Clearance Required

Solirius ReplyLondon, England, GB
Permanent

Solirius Reply, part of the Reply Group, is a technology consultancy and digital transformation partner that helps organisations solve complex challenges through strategy, design, engineering, and ... Show more

 • Promoted

Cyber Security Associate Director

RSM UKGreater London, England, United Kingdom
Permanent

We are searching for an experienced Cyber Security Associate Director.As an Associate Director within Technology and Cyber Risk Assurance, you’ll be responsible for advising our clients on cyber se... Show more