Head of Business Continuity and Cyber Resilience - SC Cleared

Code IT Recruitment Ltd
Glasgow, UK
1 day ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
Ā£208,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Cybercrime

Job description

Are you a strategic leader capable of steering an organisation through its most challenging moments?

As the Head of Business Continuity and Cyber Resilience, you will lead our capability across the entire Business Continuity Management and Cyber Incident Lifecycles. This is a high-profile role where you will design, implement, and embed robust policies, strategies, and readiness programmes to safeguard our critical regulatory services.

From shaping strategic response mechanisms to navigating complex cyber threats, you will provide the ā€œhelicopter viewā€ and senior leadership necessary to strengthen our preparedness, response, and recovery arrangements across DDSS and wider business teams., In this role, you will lead a dedicated team of specialists to champion resilience across government security. Your core responsibilities will include:

  • Strategic Leadership: Champion business continuity and cyber resilience across the organisation and wider government, driving a culture of continuous improvement and lessons learned.
  • Team & Standards Management: Lead a team of resilience specialists to ensure full compliance and delivery against CAF, DHSC, ISO22301, and ISO27031 standards.
  • Exercise & Training Delivery: Design and execute major/minor cyber exercise programmes, crisis simulations, and technical recovery walkthroughs alongside training and awareness campaigns.
  • Incident & Threat Analysis: Lead the delivery of incident management policies, investigate the source and nature of breaches to support threat intelligence, and manage the rapid, accurate sharing of critical information.
  • Stakeholder Coordination: Act as an ā€œintelligent customerā€ for business units, keeping senior stakeholders and Executive Directors informed with strategic risk insights.

Key Outputs and Deliverables

  • Deliver and maintain the organisational Business Impact Analysis (BIA), dependency map, and criticality register.
  • Maintain all business continuity, recovery, and cyber incident response plans in alignment with NCSC and ISO frameworks (ensuring compliance with RPO/RTO/MTPD thresholds).
  • Produce regular, data-driven Board dashboards providing insight into our resilience posture, risk, and maturity.
  • Provide expert assurance and resilience input into major corporate programmes, system changes, and supplier engagements.
  • Lead the function through CAF submissions, remediation activities, and the roadmap to formal ISO22301/27031 compliance.

Key Stakeholder Relationships

  • Internal: Executive and Deputy Directors; DDSS leadership, Cyber Security, and DPO teams; Tech Operations, Engineering, and Service Management; Corporate Service Owners.
  • External: NCSC CIR providers and cyber incident partners; third-party technology suppliers; cross-government resilience and BCM communities; sector regulators.

Requirements

  • Resilience Expertise: Proven experience delivering robust business continuity, organizational resilience, or cyber incident management at scale. (
  • Senior Stakeholder Engagement: Demonstrated experience influencing senior leaders and driving complex organizational planning.
  • Cyber Security & Risk: Strong background in Cyber Security and Risk Management with a distinct focus on organizational resilience.
  • Command Structure Experience: Practical experience designing or participating in exercises at Bronze, Silver, and Gold command levels.
  • Professional Certifications: Must hold a CISM certification alongside AMBCI/MBCI/DBCI accreditation.

Desirable

  • Experience working within highly regulated or central government environments.
  • Experience designing and delivering cross-organisational training and awareness campaigns.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerboard.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder Ā· LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman Ā· World Congress 2022

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa Ā· LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin Ā· World Congress 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger Ā· LIVE

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 Ā· World Congress 2026 Europe

Videos

See all

Related articles

See all