At a Glance
- Tasks: Lead the development and management of cyber policy frameworks to enhance organisational resilience.
- Company: Join the FCA, a key regulator in UK financial services, promoting fairness and consumer protection.
- Benefits: Enjoy 25 days annual leave, private healthcare, and a flexible benefits scheme tailored to your lifestyle.
- Other info: Diverse and inclusive culture with excellent career growth opportunities.
- Why this job: Make a real impact on UK finance while shaping cyber policies that protect consumers and markets.
- Qualifications: Experience in policy design and a solid understanding of cybersecurity standards required.
The predicted salary is between 53800 - 65000 £ per year.
Division: Operations
Department: Cyber and Information Resilience
Salary: National (Edinburgh and Leeds) ranging from £53,800 to £65,000 and London from £59,200 to £70,000 (salary offered will be based on skills and experience)
This role is graded as: Senior Associate, Regulatory
About the FCA and team
We regulate financial services firms in the UK, to keep financial markets fair, thriving and effective. By joining us, you’ll play a key part in protecting consumers, driving economic growth and shaping the future of UK finance services. The Cyber and Operational Resilience directorate enables secure and resilient regulation across the FCA and PSR, supporting the protection of UK consumers and financial markets.
This Senior Associate sits within the Policy & Risk team, part of the wider Governance and Human Risk function. The role focuses on the management and maintenance of the Cyber & Information Resilience Policy Framework, including associated standards, procedures and guidance.
Role responsibilities
- Maintain and refresh the cyber policy framework by managing policy and standards updates in line with agreed review/refresh cycles and making out-of-cycle updates where material changes are required.
- Modernise and simplify the policy & standards suite, exploring improved formats (e.g., “standards on a page”) to increase usability and adoption across the organisation.
- Serve as the FCA-wide point of contact for policy requirements, handling BAU and project-related queries and providing clear, consistent interpretations of published requirements.
- Manage and track policy non-compliance and exceptions, including owning and modernising the Policy Waiver process and ensuring issues are surfaced and understood by relevant stakeholders.
- Conduct policy gap analysis and horizon scanning, identifying emerging risks, regulatory/industry changes and required updates to keep the framework current and effective.
- Support articulation of the organisation’s Cyber Risk Appetite through the policy framework, ensuring requirements align to risk tolerance and are understood across the business.
- Enable a new self-service policy model for low-risk projects, helping define requirements and controls that balance agility with the FCA’s risk appetite.
- Provide reporting and governance support by assisting the Risk lead with controls performance measurement and supporting the GHR Manager/CISO with reporting on cyber issues, audit/risk engagements and organisational non-compliance; additionally supporting specialist investigation teams and HR with policy interpretation where needed.
Skills required
- Minimum: Experience in designing, drafting and maintaining policies, standards and procedures across their full lifecycle.
- Framework knowledge: Solid working knowledge of industry standards such as ISO 27001, NIST Cybersecurity Framework (CIS), CIS Controls.
- Essential: Security Domain Knowledge: Understanding of technical security controls, including network security, cloud security, identity and access management and vulnerability management.
- Working knowledge of Information Management practices and Data Privacy legislation.
- Stakeholder management: proven record in dealing with stakeholders at all levels (including Director level).
- Experience in delivering organisational change.
- Risk identification, articulation and management.
Benefits
- 25 days annual leave plus bank holidays.
- Non-contributory pension (8–12% depending on age) and life assurance at eight times your salary.
- Private healthcare with Bupa, income protection and 24/7 Employee Assistance.
- 35 hours of paid volunteering annually.
- Hybrid model where employees work a minimum of 40% in the office each month (expectation of 50% for senior leaders). Changing from September to a minimum of 50% in the office each month (expectation of 60% for Directors and Executive Directors).
- A flexible benefits scheme designed around your lifestyle.
Our values and culture
Our colleagues are the key to our success as a regulator. We are committed to fostering a diverse and inclusive culture: one that’s free from discrimination and bias, celebrates difference and supports colleagues to deliver at their best. We believe that our differences and similarities enable us to be a better organisation – one that makes better decisions, drives innovation and delivers better regulation.
If you require any adjustments due to a disability or condition, your recruiter is here to help - reach out for tailored support. We welcome diverse working styles and aim to find flexible solutions that suit both the role and individual needs, including options like part-time and job sharing where applicable.
Disability confident: our hiring approach
We’re proud to be a Disability Confident Employer and therefore, people or individuals with disabilities and long-term conditions who best meet the minimum criteria for a role will go through to the next stage of the recruitment process. In cases of high application volumes we may progress applicants whose experience most closely matches the role’s key requirements.
Useful information and timelines
Timeline:
- Job advert close: midnight, 13th May 2026.
- CV Review/Shortlist: 15th May 2026.
- Interview: 21st May onwards.
Your Recruiter will discuss the process in detail with you during screening for the role, therefore, please make them aware if you are going to be unavailable for any date during this time.
Cyber Policy Lead in Edinburgh employer: Financial Conduct Authority
The FCA is an exceptional employer, offering a dynamic work environment in the heart of Edinburgh or Leeds, where you can contribute to shaping the future of UK financial services. With a strong commitment to employee growth, a diverse and inclusive culture, and a comprehensive benefits package including private healthcare and generous leave, the FCA empowers its staff to thrive both personally and professionally. Join us to be part of a team that values innovation and collaboration while making a meaningful impact on consumers and the financial market.
Contact Details:
Financial Conduct Authority Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Policy Lead in Edinburgh
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Financial Conduct Authority, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Financial Conduct Authority
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Financial Conduct Authority. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Cyber Policy Lead in Edinburgh
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Financial Conduct Authority insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Financial Conduct Authority that you’re committed to staying ahead in the game.
How to prepare for a job interview at Financial Conduct Authority
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Financial Conduct Authority to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Financial Conduct Authority.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.