About the Role
The Cyber Security Division (CSD) is an award-winning group of cyber security experts committed to protecting the Bank of England from cyber-attacks. You will assess the security of solutions being considered by Bank teams, including SaaS solutions, and play a key role in safeguarding the Bank and its information by collaborating with colleagues across Technology and the organisation. Staff are encouraged to develop their skills internally and externally through mentoring, training, and formal qualifications.
Responsibilities
- Reviewing responses to cyber and risk questionnaires
- Engaging with stakeholders to understand how they manage security and data
- Supporting, then performing, risk assessments and assurance activities
- Identifying control gaps and helping shape pragmatic recommendations
- Contributing to clear, concise reports for senior stakeholders
Requirements
- Excellent English reading and comprehension
- Strong analytical and problem-solving skills
- Experience of liaising with business stakeholders to reach agreement
- Experience writing clear reports and presenting them to groups
- Confidence engaging with stakeholders and suppliers
- Interest in cyber security, risk, or governance
- Ability to communicate complex choices simply and effectively
- Attention to detail and a structured approach to work
- Relevant professional qualification (e.g. CISSP, BCS Foundation Certificate in Data Protection, BCS CISMP, ISO/IEC 27001 Foundation, BCS Foundation Certificate in Cyber Security, CompTIA Security+, ISC2 Certified in Cybersecurity, BCS Foundation Certificate in IT, CompTIA ITF+, CompTIA A+, CompTIA Network+, ISO 31000 Foundation)
- Eager to learn about IT network architecture and components, software/application security, infrastructure security, cloud
- Active interest in new technical concepts and/or technologies
- Good stakeholder collaboration skills
- Proven experience in technical roles (preferably with a cyber security element)
- Experience working in cyber security consultancy or architecture roles within highly regulated sectors (e.g. financial/insurance, defence, civil nuclear, intelligence)
- Experience working in a professional/business environment
- Experience conducting technical risk assessments
- Exposure to supplier management, audit, compliance, or risk
- Awareness of cyber security concepts (e.g. threats, controls, data protection)
- Experience analysing technical problems to identify potential security concerns
- Reviewing IT architecture to identify potential security gaps and/or vulnerabilities
- Assessing compliance with IT security policies and technical standards (e.g. ISO 27001, NIST, Cyber Essentials, COBIT, etc…)
- Additional technical qualifications (e.g. CRISC, CISM, NCSC CCP, ISSAP, CompTIA SecurityX, CCSK, CCSP, GDSA, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor)
- Knowledge of well-known Frameworks (e.g., NIST, MITRE ATT&CK, ISO 27001) and how they are applied pragmatically within delivery
- Ability to work with limited supervision
Skills
- Cyber security
- Risk assessment
- Assurance activities
- Stakeholder engagement
- Reporting
- IT network architecture
- Software/application security
- Infrastructure security
- Cloud security
- Technical risk assessment
- Supplier management
- Audit
- Compliance
- Data protection
- IT architecture analysis
- Security policy assessment
- NIST
- MITRE ATT&CK
- ISO 27001
Location
- London
Work Type
- 12 month FTC
- Flexible working
- Part time working
- Job share arrangements
Experience Level
- Junior
- Professional with a few years’ experience in business, consulting, procurement, audit, risk, or operations
- Looking to transition into cyber security from a related field
- Already in a junior cyber, risk, compliance or governance role
Benefits
- A pathway into cyber security, compliance, risk, and resilience careers
- Training and support for certifications
- The opportunity to work on issues of national importance
- A collaborative, inclusive, and intellectually stimulating environment
- A strong focus on work-life balance
- Non-contributory, career average pension (1/80th of annual salary per year, option to increase to 1/65th or decrease to 1/105th)
- Discretionary performance award
- 8% benefits allowance (can be taken as salary or used for flexible benefits)
- 26 days’ annual leave with option to buy up to 12 additional days
- Private medical insurance
- Income protection
About the Company
- The Cyber Security Division (CSD) is an award-winning group of cyber security experts who are committed to keeping the Bank of England safe from cyber-attacks and incidents.
- In 2023 CSD were recognised with the Financial Services award of the year at the National Cyber Awards.
- This followed previous award wins for individuals within our team at the WeAreTechWomen and Women in IT Awards, and Central Banking’s Best Cyber Resilience Initiative.
- Within Cyber Security you will be working with people who are passionate about protecting the Bank from Cyber security incidents.
- Given the importance and complexity of technology for the Bank of England, the security challenges are rarely straightforward and often span multiple systems hosted in our own data centres, in the cloud and as SaaS, requiring cross-team working and deep technical expertise to address them effectively.
- Our teams are committed to developing their expertise in a constantly evolving environment.
- The Bank values diversity, equity and inclusion.
- We play a key role in maintaining monetary and financial stability, and to do that effectively, we believe we need a workforce that reflects the society we serve.
- At the Bank of England, we want all colleagues to feel valued and respected, so we're working hard to build an inclusive culture which supports people from all backgrounds and communities to be at their best at work.
- We celebrate all forms of diversity, including (but not limited to) age, disability, ethnicity, gender, gender identity, race, religion, sexual orientation and socioeconomic status.
- We believe that it’s by drawing on different perspectives and experiences that we’ll continue to make the best decisions for the public.
- We've also partnered with external organisations to support us in making adjustments for candidates and employees in the recruitment process where they're needed.
- From 1st October 2026, we expect all our colleagues to spend a minimum of 50% of their working time in the office per month.
- This is to capitalise on the benefits of working together in person across teams, while maintaining the flexibility offered by home working.
- Subject to that minimum requirement, individuals and managers should work together to find what works best for them and their team.
- We're proud to be a member of the Disability Confident Scheme.
- The Bank of England welcomes applications from all candidates, but as a UK Visas and Immigration (UKVI) approved sponsor, we have a responsibility to comply with the Immigration Rules and guidance.
- As such, our ability to employ individuals who require sponsorship for immigration purposes is limited.
- The Bank cannot guarantee that you and / or the role you are applying for will be eligible for sponsorship and that any application made to UKVI will be successful.
- Eligibility will therefore be considered on a case by case basis.
Equal Opportunity
- The Bank values diversity, equity and inclusion.
- We celebrate all forms of diversity, including (but not limited to) age, disability, ethnicity, gender, gender identity, race, religion, sexual orientation and socioeconomic status.
- We welcome applications from individuals who work flexibly, including job shares and part time working patterns.
- We've also partnered with external organisations to support us in making adjustments for candidates and employees in the recruitment process where they're needed.
- We're proud to be a member of the Disability Confident Scheme.
