FCA

Finance / FinServ

CyberPolicyLead

£59–70k london, england, united kingdom FULL TIME Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior Associate candidates.

The Brief

“Cyber Policy Lead at FCA. Skills: Cyber Policy, Policy Framework Management, Risk Management, Stakeholder Management. Maintain and refresh the cyber policy framework by managing policy and standards updates in line with agreed review/refresh cycles and making out-of-cycle updates where material changes are required. Modernise and simplify the policy & standards suite, exploring improved formats (e.g., “standards on a page”) to increase usability and adoption across the organisation”

Industry & Context.

Finance / FinServ
Problems you'll solve

policy gap analysis

What They're Looking For.

Must Have

Experience in designing, drafting and maintaining policies, standards and procedures across their full lifecycle., Solid working knowledge of industry standards such as ISO 27001, NIST Cybersecurity Framework (CIS), CIS Controls, Understanding of technical security controls, including network security, cloud security, identity and access management and vulnerability management., Working knowledge of Information Management practices and Data Privacy legislation, proven record in dealing with stakeholders at all levels (including Director level), Experience in delivering organisational change, Risk identification, articulation and management

What You'll Do.

Maintain and refresh the cyber policy framework by managing policy and standards updates in line with agreed review/refresh cycles and making out-of-cycle updates where material changes are required

Modernise and simplify the policy & standards suite

exploring improved formats (e.g.

“standards on a page”) to increase usability and adoption across the organisation

Serve as the FCA-wide point of contact for policy requirements

handling BAU and project-related queries and providing clear

consistent interpretations of published requirements

Manage and track policy non-compliance and exceptions

including owning and modernising the Policy Waiver process and ensuring issues are surfaced and understood by relevant stakeholders

Conduct policy gap analysis and horizon scanning

identifying emerging risks

regulatory/industry changes and required updates to keep the framework current and effective

Support articulation of the organisation’s Cyber Risk Appetite through the policy framework

ensuring requirements align to risk tolerance and are understood across the business

Enable a new self-service policy model for low-risk projects

helping define requirements and controls that balance agility with the FCA’s risk appetite

Provide reporting and governance support by assisting the Risk lead with controls performance measurement and supporting the GHR Manager/CISO with reporting on cyber issues

audit/risk engagements and organisational non-compliance; additionally supporting specialist investigation teams and HR with policy interpretation where needed

How You'll Work.

Team & Collaboration

Serve as the FCA-wide point of contact for policy requirements; ensuring issues are surfaced and understood by relevant stakeholders; supporting specialist investigation teams and HR with policy interpretation where needed

Communication Scope

providing clear, consistent interpretations of published requirements

Full Job Description

**Cyber Policy Lead** **Division: Operations** **Department: Cyber and Information Resilience** * **Salary:** National (Edinburgh and Leeds) ranging from £53,800 to £65,000 and London from £59,200 to £70,000 (salary offered will be based on skills and experience) * **This role is graded as:** Senior Associate, Regularity * **Your external recruitment contact is** Raimonda via [email protected] * **Your internal recruitment contact is** Fizah via [[email protected]](mailto:[email protected]). * Applications must be submitted through our online portal. Applications sent via social media or email will not be accepted. **_About the FCA and team_** We regulate financial services firms in the UK, to keep financial markets fair, thriving and effective. By joining us, you’ll play a key part in protecting consumers, driving economic growth and shaping the future of UK finance services. The Cyber and Operational Resilience directorate enables secure and resilient regulation across the FCA and PSR, supporting the protection of UK consumers and financial markets. This Senior Associate sits within the Policy & Risk team, part of the wider Governance and Human Risk function. The role focuses on the management and maintenance of the Cyber & Information Resilience Policy Framework, including associated standards, procedures and guidance. **_Role responsibilities_** * Maintain and refresh the cyber policy framework by managing policy and standards updates in line with agreed review/refresh cycles and making out-of-cycle updates where material changes are required * Modernise and simplify the policy & standards suite, exploring improved formats (e.g., “standards on a page”) to increase usability and adoption across the organisation * Serve as the FCA-wide point of contact for policy requirements, handling BAU and project-related queries and providing clear, consistent interpretations of published requirements * Manage and track policy non-complian

Free ATS check

Applying for this Cyber Policy Lead role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Workday

  • Workday has a multi-step form — save your progress after every section.
  • "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
  • Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
  • Job requisition numbers are useful when following up with HR by email.

ANONYMOUS · UNFILTERED

What do employees actually say about FCA?

Real rants from real employees. Read before you apply.

Read Company Rants →