> Markdown version of [/jobs/ext/3026577-director-cybersecurity-cyber-resilience-tc-uki](https://www.wearedevelopers.com/jobs/ext/3026577-director-cybersecurity-cyber-resilience-tc-uki). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director, Cybersecurity, Cyber Resilience, TC, UKI - **Company:** Ernst & Young - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Cyber Security, Disaster Recovery - **Published:** September 22, 2026 - **Apply:** https://careers.ey.com/talentcommunity/apply/1287664401/?locale=en_GB ## About the Role * Exceptional facilitator and communicator-able to run engaging, high-impact workshops and crisis simulations, influencing senior audiences across business, technology, and risk. * Deep understanding of the cyber threat landscape and attacker behaviours, with the ability to convert threat insight into relevant scenarios, decision points, and resilience improvements. * Strong resilience practitioner mindset: comfortable operating in ambiguity, steering complex stakeholder groups, and driving structured outcomes under time pressure. * Strategic problem solver-able to diagnose resilience gaps, design pragmatic target-state capabilities, and secure executive buy-in by linking cyber resilience to business continuity and critical service delivery. * Experienced programme and engagement leader-able to structure and manage large, complex initiatives and deliver measurable resilience outcomes. * Commercially astute and quality-driven-balancing pace with rigour, managing delivery risk, and protecting client and firm reputation. * Collaborative leader-builds trusted relationships, develops talent through coaching and mentoring, and fosters a culture of continuous learning and accountability. * Confident advisor at board/exec level-able to discuss governance, risk appetite, crisis communications, regulatory considerations, and operational resilience expectations. * Strong market access and trusted relationships, leveraging established sector networks and senior-level contacts to originate opportunities, shape market conversations, and strengthen the firm's position with key decision-makers. To Qualify for the Role, You Must Have * Proven experience leading cyber resilience, incident readiness, and/or crisis management programmes-demonstrating tangible improvements in preparedness, response effectiveness, and recovery capability. * Strong track record designing and facilitating cyber crisis simulations and tabletop exercises for senior stakeholders, including scenario development, exercise delivery, and after-action reporting with actionable remediation plans. * Experience building or enhancing incident response and recovery operating models: governance, roles, processes, playbooks, communications, and integration with ITDR/BCP. * Demonstrable ability to embed cyber into wider business resilience frameworks (e.g., business continuity, operational resilience, third-party resilience) and align cyber capabilities to critical business services and impact tolerances. * Ability to develop compelling investment cases and prioritised roadmaps for resilience capability uplift, aligned to organisational goals and risk appetite. * Robust knowledge of relevant security and resilience frameworks and regulations (e.g., NIST CSF, NIS/NIS2, sector-specific resilience expectations), and practical experience translating these into implementable capabilities and controls. * Strong stakeholder management experience across C-suite, technology, operations, legal, risk, and communications-ensuring coherent decision-making before, during, and after incidents. Ideally, You'll Also Have: * Security-related qualifications such as CISSP, CISM, CISMP, CIISEC. * Experience operating within an NCSC Assured Cyber Consultancy. * Sector experience in one or more of the following: Government & Public Sector, Energy & Utilities, Retail and Consumer Products, Life Sciences, Telecoms, Media and Technology, or Transport. * Professional services experience with market-leading organisations in delivering cybersecurity solutions. ## Description * Lead and deliver cyber resilience transformation programmes, owning end-to-end engagement delivery (scope, quality, timeline, budget) and ensuring outcomes measurably improve preparedness, response, and recovery. * Design, run, and continuously enhance cyber crisis simulations and tabletop exercises for executives and operational teams-ensuring scenarios reflect the current threat landscape, sector trends, and the client's critical business services. * Act as an outstanding facilitator and "crisis conductor": guide senior leaders through high-pressure decision making, inject realistic developments, challenge assumptions, and drive clear actions, owners, and lessons learned. * Translate threat intelligence and emerging attacker tactics into practical resilience improvements-linking likely threats to business impact, critical dependencies, and control or capability gaps. * Integrate cyber response and recovery into wider enterprise resilience plans, including business continuity, IT disaster recovery, operational resilience, third-party resilience, and enterprise risk management-ensuring cyber is embedded, not bolted on. * Partner with C-suite and functional leaders (CIO, CISO, COO, Risk, Legal, Comms, HR, Ops) to strengthen organisational readiness, clarify risk appetite, and improve cross-functional coordination during incidents. * Build capability roadmaps and investment cases for resilience (people/process/technology), prioritising initiatives that reduce time-to-detect, time-to-respond, and time-to-recover for critical services. * Shape and grow a cyber resilience offering: originate opportunities, develop proposals, create market-facing materials, and contribute thought leadership aligned to evolving resilience and regulatory expectations. * Lead, coach, and inspire a high-performing cyber resilience team-developing facilitation skills, incident leadership, scenario design expertise, and client advisory confidence. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Convincing Product teams to Adopt Gitops in a Large Org](https://www.wearedevelopers.com/videos/1936-convincing-product-teams-to-adopt-gitops-in-a-large-org) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [System Resilience: Surviving the Software Storm](https://www.wearedevelopers.com/videos/874-system-resilience-surviving-the-software-storm) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette)