Senior Technical Specialist, Cyber Resilience Team – Supervisory Risk Specialists at Bank of England | City of London, England, GBR | Rezi

Senior Technical Specialist, Cyber Resilience Team – Supervisory Risk Specialists at Bank of England

Senior Technical Specialist, Cyber Resilience Team – Supervisory Risk Specialists

Bank of England · City of London, England, GBR

2 months ago

Senior Technical Specialist, Cyber Resilience Team – Supervisory Risk Specialists

Bank of England · City of London, England, GBR

2 months ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Supervisory Risk Specialist Directorate within the Prudential Regulation Authority (PRA) provides deep technical expertise and expert judgment across risk disciplines to support the PRA's coordinated supervisory approach. The Sector Resilience Division (SRD) leads the PRA's work on the resilience of the financial sector to non-financial risks, including cyber. This role is key in shaping the PRA’s cyber risk and resilience strategy within the context of Operational Resilience (OR), including ownership and evolution of the supervisory cyber approach and associated toolkits.

Responsibilities

  • Take a leading role in developing and advising on policy and supervisory recommendations aligned with Operational Resilience objectives.
  • Lead the development of the PRA’s supervisory cyber approach, including evaluation and assessment methodologies for cyber risk and resilience, working closely with Policy, Supervision and specialist teams.
  • Lead the implementation, ongoing review and continuous improvement of the PRA’s supervisory cyber toolkit, including CBEST, STAR-FS and CQUEST.
  • Define and articulate what good cyber practices look like in the context of broader Operational Resilience expectations.
  • Provide deep analytical and technical expertise, ensuring relevant industry standards and good practices are embedded in cyber resilience assessments.
  • Lead meetings with regulated firms to assess cyber risk and resilience capabilities, providing effective challenge to firms’ approaches and remediation plans.
  • Develop and maintain strong working relationships across the Bank and with external stakeholders, including the FCA, HMT, NCSC, CPNI and other domestic and international bodies.
  • Draft high-quality papers and briefings, and contribute actively to horizon scanning and Risk Committee discussions.

Requirements

  • Significant experience leading independently regulatory cyber reviews, including threat-led-penetration-testing assessments (e.g. CBEST, STAR-FS) and other technical reviews across Cyber Resilience or related disciplines.
  • Significant experience leading independently strategic cyber resilience and proven experience to engage with senior stakeholders while delivering projects.
  • Strong knowledge of the PRA’s approach to supervising cyber risk and resilience, including its application within the Operational Resilience framework.
  • Strong understanding of the evolving cyber security regulatory landscape, and the key Operational Resilience challenges facing UK financial sector firms and authorities.
  • Strong understanding of the evolving cyber security landscape, including risks associated with emerging technologies such as Artificial Intelligence and post-quantum computing.
  • Ability to synthesise complex technical cyber and resilience information and translate it into clear, well-reasoned conclusions and actionable recommendations for senior stakeholders.
  • Ability to represent the organisation’s position on key cyber and operational resilience matters internally and externally, including leading meetings, influencing senior audiences, and adapting communication style to context and audience.
  • Strong understanding of recognised cyber resilience standards and frameworks (e.g. UK NCSC CAF, NIST, ISO/IEC 27001, ISO 22301) and cyber-related regulatory and supervisory expectations (e.g. PRA Rulebook, DORA, NIS2 Directive, CPMI-IOSCO).
  • Demonstrated commitment to diversity and inclusion, with evidence of fostering inclusive working practices, valuing diverse perspectives, and contributing to an open and respectful team culture.
  • Financial sector or regulatory experience, with a sound understanding of bank operations and risk and control environments.
  • Experience in assessing and managing cyber and technology risk.

Skills

  • Cyber risk
  • Cyber resilience
  • Operational Resilience framework
  • CBEST
  • STAR-FS
  • CQUEST
  • Artificial Intelligence
  • post-quantum computing
  • UK NCSC CAF
  • NIST
  • ISO/IEC 27001
  • ISO 22301
  • PRA Rulebook
  • DORA
  • NIS2 Directive
  • CPMI-IOSCO
  • CISA
  • CISM
  • CRISC
  • CISSP
  • CSX
  • Lead Auditor certifications for ISO/IEC 27001
  • Lead Auditor certifications for ISO 22301
  • Technology risk management

Location

  • London

Work Type

  • Hybrid

Experience Level

  • Senior

Education Level

  • Relevant professional qualifications and certifications, such as CISA, CISM, CRISC, CISSP, CSX, or Lead Auditor certifications for ISO/IEC 27001 and ISO 22301.

Salary/Compensations

  • £108,800 - £122,000

Benefits

  • Non-contributory, career average pension (1/80th of annual salary per year, with option to increase to 1/65th or decrease to 1/105th)
  • Discretionary performance award
  • 8% benefits allowance (can be taken as salary or used for flexible benefits)
  • 26 days’ annual leave (option to buy up to 12 additional days)
  • Private medical insurance
  • Income protection

About the Company

  • The Bank of England is the UK’s central bank, with a mission to deliver monetary and financial stability for the British people. It is a diverse organisation with over 4,000 employees committed to public service. The Bank is known for its world-leading thinking on policy and strategy, aiming to keep prices stable and people's money safe. They foster a collaborative culture and offer flexible ways of working to support work-life balance, striving to be an inclusive place where people feel they belong and have equal access to opportunities.

Equal Opportunity

  • The Bank values diversity, equity and inclusion, believing a diverse workforce is essential for maintaining monetary and financial stability. They are committed to building an inclusive culture that supports people from all backgrounds and communities, celebrating all forms of diversity. They welcome applications from individuals who work flexibly, including job shares and part-time working patterns. They partner with external organisations to support adjustments for candidates and employees in the recruitment process. They aim for colleagues to spend half their time in the office, with a minimum of 40% per month. They are a member of the Disability Confident Scheme.