At a Glance
- Tasks: Lead the development of cyber resilience strategies and tools for the financial sector.
- Company: Join the Bank of England, a diverse organisation committed to public service.
- Benefits: Competitive salary, generous leave, private medical insurance, and flexible working options.
- Other info: Embrace diversity and inclusion in a dynamic work environment with excellent career growth.
- Why this job: Make a real impact on the UK's financial stability while shaping cyber resilience strategies.
- Qualifications: Strong background in cyber risk, regulatory experience, and relevant professional certifications.
The predicted salary is between 108800 - 122000 £ per year.
The Bank of England is the UK's central bank. Our mission is to deliver monetary and financial stability for the British people, and the Bank is a diverse organisation with more than 4,000 people committed to public service. Supervisory Risk Specialists (SRS) is a directorate within the Prudential Regulation Authority (PRA) that provides deep technical expertise and applies expert judgement across risk disciplines to support the PRA’s coordinated supervisory approach. The Sector Resilience Division (SRD) leads the PRA's work on the resilience of the financial sector to a range of non‑financial risks, including cyber. Its priorities include assessing systemic importance of firms, evaluating cyber resilience, developing supervisory and assurance tools, and strengthening the UK’s financial system resilience.
The role will play a key part in shaping the PRA’s cyber risk and resilience strategy within the context of Operational Resilience (OR). It includes ownership and evolution of the supervisory cyber approach, associated toolkits (CBEST, STAR‑FS, CQUEST), and the engagement required to deliver the PRA’s cyber agenda. The role is well suited for an individual with a strong cyber risk and security background, ideally with prior experience in a regulatory or supervisory environment and a good understanding of the PRA’s Operational Resilience framework.
Key Responsibilities- Taking a leading role in developing and advising on policy and supervisory recommendations aligned with Operational Resilience objectives.
- Leading the development of the PRA's supervisory cyber approach, including evaluation and assessment methodologies for cyber risk and resilience, working closely with Policy, Supervision and specialist teams.
- Leading the implementation, ongoing review and continuous improvement of the PRA's supervisory cyber toolkit, including CBEST, STAR‑FS and CQUEST.
- Defining and articulating what good cyber practices look like in the context of broader Operational Resilience expectations.
- Providing deep analytical and technical expertise, ensuring relevant industry standards and good practices are embedded in cyber resilience assessments.
- Leading meetings with regulated firms to assess cyber risk and resilience capabilities, providing effective challenge to firms' approaches and remediation plans.
- Developing and maintaining strong working relationships across the Bank and with external stakeholders, including the FCA, HMT, NCSC, CPNI and other domestic and international bodies.
- Drafting high‑quality papers and briefings, and contributing actively to horizon scanning and Risk Committee discussions.
- Significant experience leading independently regulatory cyber reviews, including threat‑led penetration‑testing assessments (CBEST, STAR‑FS) and other technical reviews across Cyber Resilience or related disciplines.
- Strong knowledge of the PRA’s approach to supervising cyber risk and resilience, including its application within the Operational Resilience framework.
- Strong understanding of the evolving cyber security regulatory landscape and the key Operational Resilience challenges facing UK financial sector firms and authorities.
- Ability to synthesise complex technical cyber and resilience information and translate it into clear, well‑reasoned conclusions and actionable recommendations for senior stakeholders.
- Strong understanding of recognised cyber resilience standards and frameworks (UK NCSC CAF, NIST, ISO/IEC 27001, ISO 22301) and cyber‑related regulatory and supervisory expectations (PRA Rulebook, DORA, NIS2 Directive, CPMI‑IOSCO).
- Relevant professional qualifications and certifications, such as CISA, CISM, CRISC, CISSP, CSX, or Lead Auditor certifications for ISO/IEC 27001 and ISO 22301.
- Demonstrated commitment to diversity and inclusion, fostering inclusive working practices and valuing diverse perspectives.
- Financial sector or regulatory experience, with a sound understanding of bank operations and risk and control environments.
- Experience in assessing and managing cyber and technology risk.
Salary of circa £108,800 – £122,000. Non‑contributory, career average pension giving a guaranteed retirement benefit of 1/80th of annual salary per year worked; option to increase to 1/65th or decrease to 1/105th through flexible benefits scheme. Discretionary performance award based on current award pool. 8% benefits allowance with option to take as salary or purchase flexible benefits. 26 days annual leave with option to buy up to 12 additional days through flexible benefits. Private medical insurance and income protection.
National Security Vetting ProcessEmployment in this role will be subject to the National Security Vetting clearance process (typically 6–12 weeks post‑offer) and passing additional Bank security checks. Further information will be provided to the successful applicant.
Our Approach to InclusionThe Bank values diversity, equity and inclusion. We work hard to build an inclusive culture that supports people from all backgrounds and communities to be at their best at work. We welcome applications from individuals who work flexibly, including job shares and part‑time patterns.
Application DeadlineThis role closes on 24th June.
Senior Technical Specialist, Cyber Resilience Team employer: Bank of England
The Bank of England is an exceptional employer, offering a unique opportunity to contribute to the UK's financial stability while working in a diverse and inclusive environment. With a strong commitment to employee growth, the Bank provides extensive benefits including a competitive salary, generous leave options, and a non-contributory pension scheme, all within the vibrant city of London. Joining the Cyber Resilience Team means being at the forefront of shaping cyber risk strategies, with ample opportunities for professional development and collaboration with key stakeholders across the financial sector.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Technical Specialist, Cyber Resilience Team
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Bank of England, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Bank of England
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Bank of England. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Technical Specialist, Cyber Resilience Team
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Bank of England insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Bank of England that you’re committed to staying ahead in the game.
How to prepare for a job interview at Bank of England
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Bank of England to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Bank of England.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.