At a Glance
- Tasks: Design and deliver innovative cyber security initiatives to empower employees in reducing risks.
- Company: Join the FCA, a key regulator in UK financial services, promoting fairness and resilience.
- Benefits: Enjoy 25 days annual leave, private healthcare, and a flexible benefits scheme.
- Other info: Diverse and inclusive culture with excellent career growth opportunities.
- Why this job: Make a real impact on cyber security while fostering a positive workplace culture.
- Qualifications: Experience in cyber security behavioural change and stakeholder engagement is essential.
The predicted salary is between 43300 - 60000 € per year.
Division: Operations
Department: Cyber and Information Resilience
Salary: National (Edinburgh and Leeds) ranging from £43,300- £60,000 and London from £46,400 - £63,000 (salary offered will be based on skills and experience)
This role is graded as: Senior Associate – Corporate
About the FCA and team
We regulate financial services firms in the UK, to keep financial markets fair, thriving and effective. By joining us, you’ll play a key part in protecting consumers, driving economic growth, and shaping the future of UK finance services.
The Cyber and Operational Resilience directorate is responsible for enabling secure and resilient regulation within the FCA and PSR – an organisation responsible for protecting all UK consumers and financial markets. Cyber and Information Resilience (C&IR) is responsible for the management of cyber security at the FCA. The role of cyber security is to protect the FCA's data and systems from malicious and/or accidental activity, including theft, damage and disruption, in order that the FCA can deliver its key business functions.
C&IR is part of a Directorate lead by our CISO, Director of Cyber & Operational Resilience Division. This senior associate sits in the People Risk team and is part of the wider Governance and Human Risk team within that directorate. This role will play a key part in shaping our organisation’s approach to identifying and mitigating risks posed by human behaviour, while maintaining our team’s ethos of being friendly and approachable to foster positive relationships across the organisation.
This role is responsible for designing and delivering an innovative programme that empowers employees to make informed security decisions, champion best practices, and design pathways to explain and inform on emerging cyber risks. The role will develop and implement strategies to influence positive and negative behaviours, reduce vulnerabilities and build strong relationships with the organisation.
Role responsibilities
- Develop and deliver effective and innovative cyber security behavioural-change initiatives that ensure employees understand and own their role in reducing organisational cyber risk; and have responsibility for the ongoing improvement of the programme.
- Own and deliver a stakeholder engagement and management strategy, aligning internal and external stakeholders with best practice and organisational priorities and manage the team’s relationship with external service providers, including training providers.
- Measure the effectiveness of cyber security risk initiatives using metrics, feedback, and incident data, and continuously analyse human risk factors and refine approaches using insights from our work and from other cyber teams.
- Develop and design a communications and engagement strategy and manage the implementation of that strategy through a series of regular communications and events; including owning and delivering the Cyber Month calendar of events.
- Design and deliver a risk and role‑based training strategy, including tailored training materials, e‑learning and interactive exercises in conjunction with our HR learning team.
- Lead the ethical phishing simulation programme, ensuring realistic scenarios, supportive communications, and a learning‑focused employee experience.
- Manage, grow, and mature the security ambassador network, providing structure, resources, training, and alignment with wider human risk goals.
- Contribute to wider team activities, including inductions, ad‑hoc training, MI reporting, and reactive or proactive security communications.
Skills
- Minimum: Demonstrative experience of designing, delivering and managing effective cyber security behavioural change initiatives.
- Extensive experience in developing and delivering an effective stakeholder management and engagement strategy.
- Extensive experience working at a strategic level, creating or significantly contributing to organisational strategies and long-term plans.
- Essential: Experience in delivering innovative and effective cyber security behavioural change campaigns, translating technical topics for a range of audiences and balancing serious topics with a positive and engaging approach.
- Practical experience designing and delivering effective mandatory and bespoke cyber security training programmes that supported organisational culture change.
- Superb communications skills including written effective influence across diverse audiences.
- Demonstratable experience of organising and delivering an engagement strategy, including the delivery of events in a range of formats.
- Well-developed organisational skills and the capacity to prioritise and complete a range of tasks under strict time constraints.
Benefits
- 25 days annual leave plus bank holidays.
- Non-contributory pension (8–12% depending on age) and life assurance at eight times your salary.
- Private healthcare with Bupa, income protection, and 24/7 Employee Assistance.
- 35 hours of paid volunteering annually.
- Hybrid model where employees work a minimum of 40% in the office each month (expectation of 50% for senior leaders). Changing from September to a minimum of 50% in the office each month (expectation of 60% for Directors and Executive Directors).
- A flexible benefits scheme designed around your lifestyle.
Our values and culture
Our colleagues are the key to our success as a regulator. We are committed to fostering a diverse and inclusive culture: one that’s free from discrimination and bias, celebrates difference, and supports colleagues to deliver at their best. We believe that our differences and similarities enable us to be a better organisation – one that makes better decisions, drives innovation, and delivers better regulation.
If you require any adjustments due to a disability or condition, your recruiter is here to help - reach out for tailored support. We welcome diverse working styles and aim to find flexible solutions that suit both the role and individual needs, including options like part-time and job sharing where applicable.
Disability confident: our hiring approach
We’re proud to be a Disability Confident Employer, and therefore, people or individuals with disabilities and long-term conditions who best meet the minimum criteria for a role will go through to the next stage of the recruitment process. In cases of high application volumes we may progress applicants whose experience most closely matches the role’s key requirements.
Useful information and timelines
Timeline: Job advert close: midnight on the 01/06/2026 CV Review/Shortlist: 03/06/2026 Face to Face interview: 10th and 11th of June 2026 Your Recruiter will discuss the process in detail with you during screening for the role, therefore, please make them aware if you are going to be unavailable for any date during this time.
Cyber Human Risk Specialist in London employer: Financial Conduct Authority
The FCA is an exceptional employer, offering a dynamic work environment in the heart of Edinburgh or Leeds, where you can contribute to shaping the future of UK financial services. With a strong commitment to employee well-being, we provide generous benefits including 25 days of annual leave, a non-contributory pension, and private healthcare, alongside a culture that values diversity, inclusion, and professional growth. Join us to be part of a supportive team that empowers you to make a meaningful impact while enjoying a flexible working model.
Contact Detail:
Financial Conduct Authority Recruiting Team
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Human Risk Specialist in London
✨Tip Number 1
Network like a pro! Reach out to current employees at the FCA on LinkedIn or through mutual connections. Ask them about their experiences and any tips they might have for your application process.
✨Tip Number 2
Prepare for the interview by researching common questions for Cyber Human Risk Specialists. Think about how your past experiences align with the role's responsibilities and be ready to share specific examples.
✨Tip Number 3
Show your passion for cyber security! During interviews, discuss recent trends in the field and how you can contribute to the FCA’s mission of protecting consumers and financial markets.
✨Tip Number 4
Don’t forget to apply through our online portal! It’s the only way to ensure your application gets seen. Plus, it shows you’re serious about the opportunity!
We think you need these skills to ace Cyber Human Risk Specialist in London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in cyber security behavioural change initiatives. We want to see how your skills align with the role, so don’t hold back on showcasing your relevant achievements!
Show Off Your Communication Skills:Since this role involves engaging with diverse audiences, it’s crucial to demonstrate your superb communication skills. Use clear and concise language in your application to reflect your ability to translate complex topics into relatable content.
Highlight Stakeholder Engagement Experience:We’re looking for someone with extensive experience in stakeholder management. Be sure to include examples of how you’ve successfully aligned internal and external stakeholders with best practices in your previous roles.
Apply Through Our Website:Remember, applications must be submitted through our online portal. Don’t send your application via email or social media, as we won’t be able to accept it. Head over to our website and get your application in!
How to prepare for a job interview at Financial Conduct Authority
✨Know Your Cyber Stuff
Make sure you brush up on the latest trends and challenges in cyber security. Understand the specific risks associated with human behaviour and be ready to discuss how you can influence positive change within an organisation.
✨Showcase Your Communication Skills
Since this role involves engaging with diverse audiences, practice explaining complex cyber security concepts in simple terms. Prepare examples of how you've successfully communicated technical topics to non-technical stakeholders.
✨Prepare for Behavioural Questions
Expect questions that assess your experience in designing and delivering behavioural change initiatives. Use the STAR method (Situation, Task, Action, Result) to structure your responses and highlight your achievements.
✨Engagement Strategy Insights
Be ready to discuss your approach to stakeholder engagement and management. Think about how you would align internal and external stakeholders with best practices and organisational priorities, and come prepared with ideas for innovative engagement strategies.