CyberSecurity Delivery Lead at Expleo | City of London, GBR | Rezi

CyberSecurity Delivery Lead at Expleo

CyberSecurity Delivery Lead

Expleo · City of London, GBR

2 months ago

CyberSecurity Delivery Lead

Expleo · City of London, GBR

2 months ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Provide technical leadership and delivery assurance across the Cyber and Security portfolio, acting as the senior technical authority and delivery lead to ensure programmes and projects are securely designed, effectively mobilised, governed, and delivered in line with organisational risk appetite and regulatory expectation. Establish initiatives for long-term technical sustainability by strengthening security architecture, maturing technical and delivery controls, aligning specialist cyber resources, and supporting the development, implementation, and ongoing operation of strategic supplier contracts and security platforms. Act as a senior technical partner to the IT leadership team, providing clear architectural direction and technical assurance, embedding delivery discipline, and ensuring appropriate governance, documentation, and evidence-based assurance mechanisms are consistently applied across the cyber and security portfolio.

Responsibilities

  • Lead and coordinate CAF and eCAF activity across the cyber portfolio, including control interpretation and mapping, remediation definition, evidence strategy, and tracking of audit and assurance actions.
  • Act as the senior technical lead for agreed AMP8 cyber initiatives, providing technical direction and assurance across design, build, and transition into BAU.
  • Ensure cyber initiatives are technically designed and implemented in line with governance, risk, and compliance requirements across CAF/eCAF and wider AMP8 obligations.
  • Provide technical oversight of suppliers and third parties supporting cyber initiatives, supporting mobilisation, validating technical deliverables and acceptance criteria, managing technical dependencies, and ensuring assurance and security obligations are met.
  • Act as a senior technical point of coordination across IT Transformation, Architecture, Operations, and business stakeholders, aligning technical priorities, managing trade-offs, and escalating design or assurance decisions where required.

Requirements

  • Provide ongoing technical input to portfolio-level risks, dependencies, and constraints, highlighting security, resilience, and regulatory impacts.
  • Provide technical input into the AMP8 cyber roadmap, including sequencing, high-risk dependencies, and critical milestones.
  • Provide a clear technical view of CAF/eCAF target state, control gaps, priority remediation items, and assurance expectations.
  • Provide technical definition and assurance input for each initiative, covering solution approach, security and control expectations, and operational readiness considerations.
  • Provide a clearly validated and prioritised cyber and security portfolio, confirming that delivery focus is on the most material risks, regulatory requirements, and agreed AMP8 outcomes.
  • Ensure cyber initiatives have well-defined, technically coherent scope, validated against organisational risk appetite and longer term architecture direction.
  • Provide technical input and assurance that cyber initiatives are correctly scoped, designed, and set up for effective delivery, with risks, dependencies, and control expectations understood early.
  • Coordinate delivery of cyber and security initiatives that strengthens organisational resilience and reduces risk in a controlled and transparent way.
  • Provide clear assurance that cyber capabilities meet regulatory, audit, and operational expectations and are embedded into business-as-usual operations.
  • Provide clear, concise insight and advice enabling senior leaders to make informed, timely decisions on cyber priorities, trade-offs, and investment.
  • Ensure structured handover of cyber capabilities into operational teams, with clearly defined ownership, support models, and processes.
  • Proactively manage organisational change, ensuring cyber initiatives are understood, adopted, and embedded across technology, process, and people.