A leading financial services organisation is seeking a Director of Cyber Security to provide strategic leadership across its cyber security function. This role carries enterprise-wide accountability for cyber risk, security strategy, and regulatory compliance, partnering closely with technology, risk, and business leadership.
You will be responsible for setting the cyber vision, strengthening security maturity, and ensuring the organisation remains resilient against an evolving threat landscape while meeting stringent regulatory expectations.
Key Responsibilities
-
Define and execute the enterprise cyber security strategy, aligned to business, technology, and risk objectives
-
Provide executive leadership across all cyber domains, including:
-
Security operations (SOC, detection & response)
-
Cloud, infrastructure, and application security
-
Identity & access management
-
Vulnerability management and threat intelligence
-
-
Act as a senior advisor to the Board and Executive on cyber risk, incidents, and control effectiveness
-
Own the organisation’s cyber risk framework, policies, and standards
-
Ensure compliance with financial services regulations and frameworks (e.g. DORA, NIST, ISO 27001, FCA/EU requirements)
-
Lead major cyber transformation initiatives, including tooling, operating model, and capability uplift
-
Oversee incident response and crisis management, including executive and regulator engagement
-
Build, mentor, and retain high-performing cyber security teams
-
Manage strategic vendor relationships, MSSPs, and security tooling partners
-
Own cyber security budgets, investment cases, and prioritisation
Required Experience & Skills
-
Extensive experience in a senior cyber security leadership role within financial services or another highly regulated sector
-
Strong background across cyber security domains, including operations, governance, and architecture
-
Proven experience engaging with Boards, regulators, and senior executives
-
Deep understanding of cyber risk management, operational resilience, and third-party risk
-
Track record of delivering enterprise-scale cyber programmes
-
Strong people leadership, influencing, and communication skills
-
Ability to translate complex cyber risks into clear business impact
