At a Glance
- Tasks: Lead security initiatives and ensure safe project delivery in a dynamic banking environment.
- Company: Join Crown Agents Bank, a growing UK bank transforming payments in emerging markets.
- Benefits: Enjoy hybrid working, competitive salary, and comprehensive health benefits.
- Other info: Be part of a collaborative team with opportunities for professional growth and innovation.
- Why this job: Make a real impact on global financial infrastructure while enhancing your cybersecurity skills.
- Qualifications: 7-8 years in information security with strong technical and governance experience required.
The predicted salary is between 70000 - 90000 £ per year.
Crown Agents Bank is a vastly growing and regulated UK bank that connects emerging and frontier markets to the rest of the world, using FX and payments technology. We are transforming the way payments and FX move through emerging markets, reducing friction so that more money gets to those who need it. Our solutions help fix these pain points, ultimately connecting traditionally hard‑to‑reach regions to global financial infrastructure.
Role Purpose
This is a specialist dual‑focus role at the intersection of secure delivery and security assurance. You will own two primary programmes of work for Crown Agents Bank:
- Security in Change: Acting as the security voice in project delivery — conducting risk assessments, reviewing architecture, maintaining the Secure SDLC framework, and providing formal security sign‑off on material changes.
- Security Assurance: Running the Bank’s security testing and vulnerability management programme — commissioning and managing penetration tests, owning vulnerability reporting and trend analysis, managing attack surface visibility, and working collaboratively across the business to drive remediation.
You will be technically credible enough to challenge architects and developers, and clear and persuasive enough to land risk decisions with senior stakeholders. As part of a small, high‑trust CISO team, you will also flex across the wider service catalogue beyond your primary accountabilities.
Role Responsibilities
Security in Change
- Own and maintain the Secure SDLC framework, ensuring security requirements, controls, and standards are embedded across all material change programmes and project deliveries.
- Conduct security risk assessments on new projects, significant changes, architecture proposals, and new technology initiatives, producing clear risk documentation and recommendations.
- Provide architecture review and formal security sign‑off for project delivery, acting as the gating authority for security acceptance of changes into production.
- Define and maintain application security standards including OWASP‑aligned secure coding guidelines, security requirements, and application security testing criteria.
- Act as the embedded security adviser to project and engineering teams, providing practical, timely guidance that enables secure delivery without impeding pace.
- Contribute to third‑party and vendor risk assessments for new solutions and integrations, ensuring security due diligence is conducted as part of onboarding.
Security Testing & Vulnerability Management
- Own the vulnerability management programme end‑to‑end: aggregate and analyse data from Tenable and other scanning tooling, maintain prioritisation logic based on exploitability, asset criticality, and business context, and produce governance‑ready reporting for ORC and senior stakeholders.
- Commission, scope, and manage penetration tests (infrastructure, application, and where appropriate red team/social engineering), tracking findings through to remediation closure.
- Own attack surface management — maintain visibility of the firm’s externally exposed assets and services, identify unmanaged or unexpected exposure, and feed findings into the vulnerability management and pentest scoping pipeline.
- Conduct technical analysis of vulnerability and assessment data to produce actionable prioritisation recommendations, distinguishing between critical risk and noise.
- Work collaboratively with Production Services, engineering, and infrastructure teams to promote and track remediation — owning the reporting and assurance of remediation progress.
- Maintain and continuously improve vulnerability management tooling, processes, and SLA frameworks in line with the firm’s risk appetite.
Contributing Responsibilities
- Support ISO 27001, Cyber Essentials, SWIFT CSP, DORA, and NYDFS Part 500 compliance activities within areas of ownership, including evidence collection and control testing.
- Contribute to security incident response where technical expertise in vulnerability exploitation, application security, or network threat analysis is relevant.
- Support security awareness activities including specialist training content and targeted communication.
Qualifications
- Degree or equivalent professional experience in a relevant technical or security discipline.
- Professional certification — one or more of the following is desirable: CISSP, CISM, OSCP, CEH, GPEN, GWAPT, or equivalent.
- Additional certifications (AWS Security, AZ‑500, SC‑200) are a plus.
- Candidates with strong hands‑on experience and demonstrable technical capability will be considered regardless of formal certification.
Experience
- Minimum 7–8 years’ experience in information security roles, ideally with exposure to both technical delivery and governance functions.
- Demonstrable experience owning or managing a vulnerability management programme, including use of Tenable, Qualys, or equivalent scanning platforms.
- Experience commissioning, scoping, and managing penetration tests and tracking remediation to closure.
- Strong understanding of Secure SDLC frameworks (OWASP SAMM, BSIMM, or equivalent) and practical application security knowledge (OWASP Top 10, secure coding, security requirements).
- Experience conducting security risk assessments on projects, changes, or third‑party integrations.
- Excellent communication skills — able to engage technical teams, project managers, and senior stakeholders with equal clarity.
Desirable
- Experience in or with a PRA/FCA dual‑regulated financial institution.
- Working knowledge of ISO 27001, SWIFT CSP, DORA, NYDFS Part 500, or Cyber Essentials.
- Familiarity with attack surface management tooling or methodology.
- Hands‑on experience with Microsoft Defender for Endpoint, Sentinel, or equivalent security tooling.
- Innovative mindset with a genuine interest in the evolving threat landscape, including AI‑driven threats and offensive tooling developments.
Additional Information
Why Join Us?
- Be part of a small, agile, and collaborative team where your impact is direct and visible.
- Opportunity to work on cutting‑edge financial services and security projects.
- Competitive salary and benefits, including training and development support.
- Hybrid working arrangements and a culture that values innovation and initiative.
Benefits
- Hybrid working
- Contributory personal pension plan: minimum employee 2% and employer 7%; employer matches contributions in 1% increments up to employee 5% and employer 10%.
- Life assurance – four times annual salary
- Group income protection
- Private medical insurance – may include cover for partner and/or children at company cost. Cover includes optical, dental and audiology.
- Discretionary bonus
- Competitive annual leave
- Two volunteering days
- Benefit hub
Cyber Security Manager employer: Crown Agents Bank
Crown Agents Bank is an exceptional employer, offering a dynamic and collaborative work environment where your contributions are both impactful and visible. With a strong focus on employee growth, we provide opportunities for professional development through training and innovative projects in the financial services sector. Our hybrid working model, competitive benefits, and commitment to fostering a culture of initiative make us an attractive choice for those seeking meaningful and rewarding careers in cyber security.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Manager
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the cyber security field. Attend meetups, webinars, or even just chat with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio that highlights your experience with vulnerability management, penetration testing, and secure SDLC frameworks. This will give potential employers a clear view of what you bring to the table and how you can help them tackle their security challenges.
✨Tip Number 3
Prepare for interviews by brushing up on your communication skills. You’ll need to explain complex security concepts to both technical teams and senior stakeholders. Practice articulating your thoughts clearly and confidently, so you can make a strong impression when it counts.
✨Tip Number 4
Don’t forget to apply through our website! We’re always on the lookout for talented individuals who can help us transform payments and FX in emerging markets. Your next big opportunity could be just a click away!
We think you need these skills to ace Cyber Security Manager
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Cyber Security Manager role. Highlight relevant experience, especially in security risk assessments and vulnerability management. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how you can contribute to our mission at Crown Agents Bank. Keep it concise but impactful!
Showcase Your Technical Skills:Don’t forget to highlight your technical skills and certifications. Mention any hands-on experience with tools like Tenable or Qualys, and your understanding of Secure SDLC frameworks. We love seeing that expertise!
Apply Through Our Website:We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you don’t miss out on any important updates from us!
How to prepare for a job interview at Crown Agents Bank
✨Know Your Stuff
Make sure you brush up on your knowledge of Secure SDLC frameworks and vulnerability management. Be ready to discuss your experience with tools like Tenable or Qualys, and how you've managed security risk assessments in past roles.
✨Speak Their Language
Familiarise yourself with the specific terminology used in the job description. Use terms like 'risk assessments', 'penetration tests', and 'OWASP Top 10' during the interview to show that you understand the role and can communicate effectively with both technical teams and senior stakeholders.
✨Show Your Problem-Solving Skills
Prepare examples of how you've tackled security challenges in previous positions. Think about times when you had to make tough decisions regarding security risks and how you communicated those to your team or management.
✨Ask Insightful Questions
At the end of the interview, have a few thoughtful questions ready. Inquire about the current security challenges the bank faces or how they measure the success of their vulnerability management programme. This shows your genuine interest in the role and the company.