About this role
Salary: £61,000 - 101,000 per year
Requirements: We require proven experience leading a data security, cyber security, information security or assurance capability within a complex organisation, including building, developing and maturing teams, operating models and security capabilities.We require demonstrable experience designing, implementing and assuring data security controls and frameworks across SaaS, cloud and enterprise environments, aligned to recognised frameworks such as NIST CSF and ISO 27001.We require a strong understanding of data security principles and risks, including data discovery, data lineage, encryption, logging, access control, identity management, data loss prevention and protection against data exposure and exfiltration.We require experience delivering security assurance and risk assessments across applications, cloud platforms, data repositories, AI systems and broader technology environments, supported by continuous monitoring, control health reviews and risk reporting.We require experience establishing governance, assurance and control oversight processes, including attestations, control validation, remediation tracking and risk-based prioritisation.We require strong expertise in Microsoft Purview and Microsoft 365 security and compliance capabilities, including data discovery, classification, sensitivity labelling, DLP, Insider Risk Management, DSPM for AI and related E5 functionality.We require knowledge of regulatory, legal and compliance requirements relevant to data security and experience translating these into practical controls, assurance activities and risk management outcomes.We require excellent stakeholder management and influencing skills, with the ability to work effectively across technology, cyber security, data governance and business teams and to communicate complex security risks and control issues to senior leadership and executive stakeholders.We require experience integrating security tooling, telemetry, APIs and automation to improve assurance, risk visibility and control effectiveness across Microsoft, AWS and interconnected technology platforms.We require strong strategic and analytical capabilities, with experience developing data security roadmaps, identifying emerging risks and driving improvements that strengthen organisational security posture. Responsibilities: We will lead our Data Security Assurance Framework, ensuring the confidentiality, integrity, authenticity, availability and appropriate use of corporate data, aligned to our Cyber Risk Management Framework, regulatory, legislative and internal control requirements.We will establish and deliver risk-based data security assurance across our data estate, including M365 security and compliance, cloud platforms, data lakes, AI systems and data repositories, ensuring the identification, assessment and treatment of security and data risks.We will drive the strategic evolution of our data security posture management for AI, assessing and assuring technical controls, data exposure and appropriate use across emerging AI capabilities such as MS Co-pilot, Agentic AI and AI-enabled platforms.We will produce meaningful KPIs, KRIs, risk assessments and management information to support senior management decision-making, while leading issue identification, remediation tracking and validation of corrective actions.We will lead and develop our Data Security Assurance capability, working across technology, cyber security, risk, compliance and data governance teams to embed effective controls throughout the data lifecycle and support consistent risk reporting, governance and oversight. Technologies: Agentic AIAIAWSCloudSupportMicrosoft 365SecurityOffice 365 More:
We regulate financial services firms in the UK to keep financial markets fair, thriving and effective. By joining us, youll play a key part in protecting consumers, driving economic growth and shaping the future of UK finance services. Our Cyber and Information Resilience team is responsible for managing cyber security at the FCA, protecting our data and systems from malicious activity so we can deliver our key business functions. This role sits within our Cyber Assurance team, which leads FCA and PSR cyber assurance activities to confirm the right cyber assurance and control measures are in place. The role is based in London, Leeds or Edinburgh, with a full-time hybrid model where colleagues spend a minimum of 50% of their working time in the office each month. We offer 25 days annual leave plus bank holidays, a non-contributory pension, private healthcare, income protection, 35 hours of paid volunteering annually, and a flexible benefits scheme. We are committed to a diverse, inclusive and flexible working culture, and we welcome adjustments and working styles that help people do their best work.
last updated 36 week of 2026