Cyber Resilience & INFOSEC Assurance Lead

Cyber Resilience & INFOSEC Assurance Lead

Full-Time 60000 - 75000 £ / year (est.) Home office (partial)
Greater London Authority

At a Glance

  • Tasks: Lead cyber security initiatives and enhance information assurance across the GLA.
  • Company: Join a forward-thinking organisation committed to public service and innovation.
  • Benefits: Enjoy hybrid working, competitive salary, 30 days annual leave, and more.
  • Other info: Inclusive workplace with flexible arrangements and opportunities for career growth.
  • Why this job: Make a real difference in cyber resilience while shaping the future of public sector security.
  • Qualifications: Must have CISM, CISSP, and experience in cyber security management.

The predicted salary is between 60000 - 75000 £ per year.

Corporate Resources and Business Improvement

The Resources and Business Improvement directorate is responsible for People Function, Facilities Management, Digital Experience Unit and Technology Group, Information Governance, Executive Support Team and leadership of all our shared services across the GLA Group.

About The Team

This is a new role and forms part of a new structure and need at the GLA. It reports into the Director of Live Service, and initially part of a service team of 3.

About The Role

To act as the strategic owner and senior security authority SME for the GLA’s cyber security, information assurance and shared ICT services security posture. The role is required to address increasing cyber risk, assurance expectations, regulatory obligations, and the operational realities of a shared service model with Transport for London (TfL). It will provide sustained leadership, assurance and subject‑matter expertise beyond purely technical cyber functions, embedding cyber resilience, education and risk awareness across the organisation.

What your day will look like:

  • Review any security incidents reported and respond accordingly.
  • Deliver updates to the SLT on weekly, monthly dashboards reporting on tactical and strategic issues and opportunities.
  • Respond to any requests to work abroad.
  • Provide input into any project requests to provide any impact to Cyber stance.
  • Review and update any changes to policy following NCSC or other guidance.
  • Create, deliver proactive training updates via webinar, lunch and learn, core brief, media, comms.

Skills, Knowledge And Experience:

  • Strong experience in cyber security management within a complex or shared‑service environment.
  • Demonstrable understanding of NCSC principles, ISO 27001, and public‑sector security frameworks.
  • Experience managing suppliers and outsourced security services.
  • Ability to translate technical risks into business‑focused advice.
  • Strong communication and stakeholder‑management skills.
  • Creation and delivery of Security and Cyber strategies and operational assurance plans.

To be considered for the role you must meet the following essential criteria:

  • CISM (Certified Information Security Manager).
  • CISSP (Security & governance domains).
  • ISO 27001 Lead Implementer / Lead Auditor.
  • Knowledge of SIEM/SOC environments.
  • Threat detection & vulnerability management.
  • Business continuity / disaster recovery.

Desirable:

  • Exposure to smart city / data-sharing ecosystems.
  • Regulatory experience: UK GDPR + public sector frameworks.
  • Technical grounding: Architecture + cloud security awareness.

Behavioural Competencies:

  • Leading & Influencing (communication, stakeholders).
  • Delivering Results (execution, pragmatism).
  • Thinking & Judgement (risk, strategy, ethics).
  • Working Together (collaboration, partnerships).

How to apply:

Up to date CV and personal statement with a maximum of 1500 words. Please ensure you address how you demonstrate the essential criteria outlined above in the advert.

Please ensure your CV and Personal Statement have a maximum file size of 1.5MB each and upload your Personal Statement to the ‘CV and Cover Letters’ section of the form, ensuring you address the technical requirements and competencies in your Personal Statement. Word or PDF format preferred and do not include any photographs or images. Please ensure your CV and Personal Statement are saved with the job reference number as part of the naming convention (E.g., “CV – applicant name - 012345).

As part of GLA’s continuing commitment to be an inclusive and equal opportunity employer we will be removing personal identifiable information from CVs and Personal Statements that could cause discrimination. We may close this advert early if we receive a high volume of suitable applications.

If you have questions about the role, the hiring manager, Kieran Murphy would be happy to speak to you.

If shortlisted for interview – this is a two-stage process. 1st interview will involve a technical test lasting 10 minutes. These six questions will be used as part of the assessment process and suitability for the second stage, approximately one week after the initial interview.

Closing date for applications is Monday 22 June at 23:59:00. Once you have submitted an application, your details will be reviewed by a panel. If shortlisted, you’ll be invited to an interview/assessment.

Equality, diversity and inclusion: London's diversity is its biggest asset, and we strive to ensure our workforce reflects London's diversity at all levels. We welcome applications from everyone regardless of age, gender, gender identity, gender expression, ethnicity, sexual orientation, faith or disability. We particularly encourage applications from Black, Asian and Minority ethnic candidates and disabled candidates who are currently underrepresented in our workforce.

We are committed to being an inclusive employer and we are happy to consider flexible working arrangements. We would welcome applications from candidates who are seeking part time work as this role is open to job share. We are a Disability Confident Employer so for candidates who wish to be considered under the scheme and meet the essential criteria, they will automatically be invited to interview.

Benefits: GLA staff are hybrid working up to 3 days a week in our offices and remotely depending on their role. In addition to a good salary package, you will be paid every four weeks, providing frequent salary payments. We also offer an attractive range of benefits including 30 days’ annual leave, interest free season ticket loan, interest free bicycle loan and a career average pension scheme.

More Support: If you have a disability which makes submitting an online application form difficult, please contact.

Cyber Resilience & INFOSEC Assurance Lead employer: Greater London Authority

The Greater London Authority (GLA) is an exceptional employer, offering a dynamic work environment that fosters collaboration and innovation in the heart of London. With a strong commitment to diversity and inclusion, GLA provides employees with flexible working arrangements, extensive professional development opportunities, and a comprehensive benefits package, including 30 days of annual leave and hybrid working options. Joining GLA means being part of a forward-thinking organisation dedicated to enhancing the lives of Londoners while ensuring your career growth in a supportive atmosphere.

Greater London Authority

Contact Details:

Greater London Authority Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Resilience & INFOSEC Assurance Lead

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Greater London Authority, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Greater London Authority

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Greater London Authority. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cyber Resilience & INFOSEC Assurance Lead

Cyber Security Management
NCSC Principles
ISO 27001
Supplier Management
Technical Risk Translation
Communication Skills
Stakeholder Management

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Greater London Authority insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Greater London Authority that you’re committed to staying ahead in the game.

How to prepare for a job interview at Greater London Authority

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Greater London Authority to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Greater London Authority.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.