Head of Cyber Resilience and Cloud

Cyber UK
Reading, UK
1 day ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£195,000.0 - £221,000.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cloud Computing Cloud Computing Security Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Leak Prevention Information Systems Security Architecture Professional Security Information and Event Management Strategies of Testing Software Vulnerability Management Cyber Threat Analysis Cyber Warfare
+1 more
Devsecops

Job description

We are supporting a major Financial Services organisation in the search for a Head of Cyber Resilience and Cloud to join its cyber leadership team.Reporting directly to the CISO, this role will lead cyber operations, threat reduction and resilience capabilities across both cloud and on premises environments. You will act as a trusted advisor to senior leaders, driving strategic initiatives that strengthen the organisation’s ability to prevent, detect, respond to and recover from cyber threats.This is a highly visible leadership role with responsibility for managing a specialist team, influencing senior stakeholders across a complex matrix environment and leading major cyber incidents when they arise., * Leading cyber resilience strategy across cloud and enterprise technology environments.

  • Overseeing cyber operations including SOC, SIEM, threat intelligence, vulnerability management, attack surface management and incident response.
  • Working closely with the CISO to develop and implement strategic initiatives that improve operational resilience and cyber maturity.
  • Acting as the senior lead during cyber incidents, ensuring effective assessment, containment, recovery and lessons learned activities.
  • Leading governance and strategy across cloud security, cyber recovery, data loss prevention and vulnerability management.
  • Developing and operationalising threat intelligence capabilities, working with industry partners and external security communities.
  • Defining and delivering cyber resilience testing strategies through penetration testing, red teaming and crisis simulation exercises.
  • Building and maintaining cyber scenario libraries based on severe but plausible threat scenarios.
  • Working with internal teams, third party providers and senior stakeholders to identify control gaps and implement effective security improvements.
  • Supporting regulatory compliance and engagement across relevant cyber, technology and operational resilience requirements.

Requirements

  • Proven experience in a senior cyber security leadership role within a large and complex organisation.
  • Strong technical background covering cyber operations, SOC, SIEM, threat intelligence, incident response, penetration testing and red teaming.
  • Extensive experience leading cyber incidents and crisis management activities across enterprise environments and supply chains.
  • Strong understanding of cloud technologies, on premises infrastructure, DevSecOps and modern security architectures.
  • Experience developing cyber resilience, business continuity and recovery strategies.
  • Deep knowledge of vulnerability management, attack surface management and security monitoring.
  • Experience working within highly regulated Financial Services environments.
  • Strong stakeholder management skills with the ability to influence at executive level within matrix organisations.
  • Familiarity with frameworks and regulations including NIST, NIST 800-53, COBIT, DORA and operational resilience requirements.
  • Certifications such as CISM, CCSP or equivalent would be advantageous.

Reasonable Adjustments

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all