About the Role
The Cyber Security Division advises business areas on how best to manage and mitigate the cyber security risks in one of the Bank’s most complex and fastest growing risk areas: the supply chain. As a Senior Cyber Risk and Assurance Analyst, you’ll support the assessment of suppliers, partners, software, hardware and services that underpin critical financial operations. You’ll work at the intersection of business, risk, and cyber security, gaining hands-on experience while helping ensure that organisations, equipment and processes that are essential to the UK economy meet appropriate security standards.
Responsibilities
- Reviewing responses to cyber and risk questionnaires
- Engaging with stakeholders to understand how they manage security and data
- Supporting, then performing, risk assessments and assurance activities
- Identifying control gaps and helping shape pragmatic recommendations
- Contributing to clear, concise reports for senior stakeholders
Requirements
- Experience writing clear reports and presenting them to groups, with excellent English reading and comprehension
- Strong analytical and problem-solving skills
- Experience of liaising with business stakeholders and suppliers with confidence, to reach agreement
- Interest in cyber security, risk, or governance
- Ability to communicate complex choices simply and effectively
- Attention to detail and a structured approach to work
- Eager to learn about IT network architecture and components, software/application security, infrastructure security, cloud
- Active interest in new technical concepts and/or technologies
- Good stakeholder collaboration skills
Skills
- Cyber security
- Risk assessment
- Assurance activities
- Stakeholder engagement
- Reporting
- IT network architecture
- Software/application security
- Infrastructure security
- Cloud security
- Supplier management
- Audit
- Compliance
- NIST
- MITRE ATT&CK
- ISO 27001
Location
- London
Work Type
- Onsite (minimum 50% in office from Oct 2026)
- Flexible working
- Part time working
- Job share
Experience Level
- Senior
- Professional with a few years’ experience in business, consulting, procurement, audit, risk, or operations
- Transitioning into cyber security from a related field
- Junior cyber, risk, compliance or governance role seeking a new challenge
Education Level
- Relevant professional qualification (e.g. CISSP, BCS Foundation Certificate in Data Protection, BCS CISMP, ISO/IEC 27001 Foundation, BCS Foundation Certificate in Cyber Security, CompTIA Security+, ISC2 Certified in Cybersecurity, BCS Foundation Certificate in IT, CompTIA ITF+, CompTIA A+, CompTIA Network+, ISO 31000 Foundation)
- Additional technical qualifications (e.g. CRISC, CISM, NCSC CCP, ISSAP, CompTIA SecurityX, CCSK, CCSP, GDSA, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor)
Salary/Compensations
- £61,440 - £69,120
Benefits
- Non-contributory, career average pension (1/80th annual salary, option to adjust)
- Discretionary performance award
- 8% benefits allowance (can be taken as salary or flexible benefits)
- 26 days’ annual leave (option to buy up to 12 additional days)
- Private medical insurance
- Income protection
- Training and support for certifications
- Pathway into cyber security, compliance, risk, and resilience careers
About the Company
- The Cyber Security Division (CSD) is an award-winning group of cyber security experts committed to keeping the Bank of England safe from cyber-attacks and incidents.
- Within Cyber Security, you will be working with people who are passionate about protecting the Bank from Cyber security incidents.
- The Bank values diversity, equity and inclusion.
- We believe that it’s by drawing on different perspectives and experiences that we’ll continue to make the best decisions for the public.
- Proud member of the Disability Confident Scheme.
Equal Opportunity
- The Bank values diversity, equity and inclusion.
- We celebrate all forms of diversity, including (but not limited to) age, disability, ethnicity, gender, gender identity, race, religion, sexual orientation and socioeconomic status.
- We welcome applications from individuals who work flexibly, including job shares and part time working patterns.
- We've partnered with external organisations to support us in making adjustments for candidates and employees in the recruitment process where they're needed.
