Cyber Security Lead

Cyber Security Lead

Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
J

At a Glance

  • Tasks: Lead cyber security efforts, protect digital systems, and respond to security incidents.
  • Company: Joseph Rowntree Foundation, a non-profit dedicated to social justice.
  • Benefits: Flexible working options, competitive pay, and commitment to diversity.
  • Other info: Join a supportive team focused on continuous improvement and professional growth.
  • Why this job: Make a real impact in safeguarding digital environments and enhancing organisational resilience.
  • Qualifications: Experience in cyber security frameworks and strong analytical skills required.

The predicted salary is between 63000 - 77000 £ per year.

You will be responsible for leading the delivery of the organisation’s cyber security activities, ensuring that digital systems and information assets are protected against current and emerging threats. Maintaining the cyber risk register, you will lead investigations into security breaches, coordinate disaster recovery (DR) and cyber incident response, and support business continuity planning (BCP), including defining Restore Point Objectives (RPOs) and Recovery Time Objectives (RTOs). The role ensures compliance with cyber security and information governance policies whilst providing subject‑matter expertise across the organisation. You will advise colleagues and senior stakeholders and act as a key liaison with third‑party providers to safeguard our digital environment and ensure alignment with standards and audit requirements. This is a hands‑on, standalone cyber security role. As the organisation’s senior cyber security authority, you will be the sole individual delivering cyber security activity, working closely with the Technology Manager and external IT provider. The role combines strategic oversight and independent risk‑based decision‑making with direct ownership of day‑to‑day cyber security delivery, driving continuous improvement in security maturity and organisational resilience.

We are seeking an experienced cyber security professional with expertise in frameworks such as ISO 27001, NIST, CIS Controls, GDPR, the UK Data Protection Act, and Cyber Essentials. The successful candidate will bring expertise in disaster recovery, business continuity, risk management, internal controls, and security technologies including SIEM, firewalls, EDR, MFA, encryption, Microsoft Purview, and Microsoft Entra. Experience with incident response, cyber forensics, enterprise security architecture, secure‑by‑design principles, and managing third‑party security risks is essential. The ideal candidate will have strong analytical and investigative skills to assess, document, report, and elevate cyber risks confidently. You will interpret vulnerability scans and penetration tests, evaluate cyber risks in projects or procurement, and deliver awareness programs, phishing simulations, and staff training. Excellent communication and stakeholder management skills are critical, including briefing senior leaders, liaising with external partners, and making high‑impact security decisions under pressure. You will have hands‑on experience working with cyber security tools or SOC services to monitor, detect, and respond to threats, as well as experience leading or supporting incident investigations and coordinating DR and BCP exercises. The role also involves supporting audits, compliance certifications, policy deployment, and regulatory requirements, with experience providing strategic advice to senior leadership or boards.

If you share our passion and this role sounds like you, we look forward to hearing from you. Please submit your CV and supporting information via our online application platform. The closing date for applications is 19th January 2026. Interviews will take place TBC. We reserve the right to bring the closing date forward should enough quality applications be received prior to the current closing date.

Applications are welcome from all, regardless of age, disability, marriage or civil partnership, pregnancy or maternity, religion or belief, race, sex, sexual orientation, trans status or socioeconomic background. We positively encourage applications from people from marginalised backgrounds, including but not limited to those with experience of living in poverty. We are committed to being an anti‑racist organisation and operate an anonymised recruitment process so that bias is eliminated from the shortlisting process. In support of our approach to flexible working, we are happy to receive applications from those seeking full‑time employment, as well as those who may wish to share the role on a part‑time basis. When making your application, please state whether you want to be considered for either full or part‑time work and, if part‑time, the number of hours per week you would be looking for. When working flexibly between the office and home, an expectation of two days a week in your home office applies. We are a Disability‑Confident Employer. We are committed to the recruitment, progression and retention of disabled individuals and will offer interviews to disabled candidates who meet the minimum criteria for the role. If you have a disability, please let us know if you would like to be considered for an interview under the Disability Confident Scheme. If you have any additional needs and need reasonable adjustments to be made to the interview process, please let us know.

Cyber Security Lead employer: Joseph Rowntree Foundation (JRF)

At the Joseph Rowntree Foundation, we pride ourselves on being an exceptional employer that champions inclusivity and employee development. Our commitment to flexible working arrangements, alongside a supportive work culture that values diversity and innovation, ensures that our Cyber Security Lead will thrive in a role that not only protects vital information assets but also contributes to meaningful social change. With opportunities for professional growth and a focus on continuous improvement, you will be part of a dedicated team making a real impact in the community.

J

Contact Details:

Joseph Rowntree Foundation (JRF) Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Security Lead

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Joseph Rowntree Foundation (JRF), love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Joseph Rowntree Foundation (JRF)

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Joseph Rowntree Foundation (JRF). Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cyber Security Lead

Cyber Security Expertise
ISO 27001
NIST
CIS Controls
GDPR
UK Data Protection Act
Cyber Essentials

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Joseph Rowntree Foundation (JRF) insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Joseph Rowntree Foundation (JRF) that you’re committed to staying ahead in the game.

How to prepare for a job interview at Joseph Rowntree Foundation (JRF)

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Joseph Rowntree Foundation (JRF) to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Joseph Rowntree Foundation (JRF).

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.