At a Glance
- Tasks: Lead cyber security efforts and ensure service providers meet security standards.
- Company: Join NS&I, a trusted government agency with a rich history.
- Benefits: Enjoy flexible working, generous pension, and performance bonuses.
- Why this job: Make a real impact in safeguarding millions of customers' savings.
- Qualifications: Proven experience in cyber security management and risk assessment.
- Other info: Great opportunities for professional development in a supportive environment.
The predicted salary is between 43200 - 72000 £ per year.
The Cyber Security Manager position is a critical role within the NS&I Risk Directorate. The role supports the Senior Cyber Security Manager in providing assurance that our service providers are operating effective cyber security control environments. Cyber security is a scientific field, encompassing scientific principles and methodologies from multiple disciplines, including computer science, mathematics, engineering, and behavioural sciences. The complexity of cyber security arises from the diverse and evolving nature of threats, technologies, regulations, and human factors involved. Addressing these complexities requires a holistic approach that combines technical expertise, strategic planning, organisational commitment, and continuous adaptation to emerging threats.
The Cyber Security Manager is responsible for being the primary contact for NS&I's service providers and providing NS&I with assurance that the service providers are managing the complexities and ensuring cyber security risks are mitigated to acceptable levels.
Responsibilities
- Extensive experience of overseeing the performance of service providers and holding them to account for the delivery of critical cyber security services through governance forums.
- Demonstrable success in delivering written and oral presentations on cyber security and management risk to senior internal and external stakeholders.
- Substantial experience of assuring evidence against the National Institute of Standards and Technology (NIST) Cyber Security Framework (CSF) and ISO27001.
- Proven experience of conducting cyber security risk assessments, developing cyber security risk mitigation plans linked to business objectives, and presenting to a senior management audience.
- Experience in developing cyber security performance metrics linked to business objectives to inform senior management of the performance of the cyber security control environment.
- Significant experience in responding to or managing security incidents/breaches, overseeing patching/vulnerabilities or hardening systems including detection, response, recovery, and post‑incident analysis.
- Extensive experience of implementing security solutions surrounding cloud transformation, data management, data storage.
- Strong analytical skills, including the ability to review, challenge and utilise complex technical information to provide advice and guidance to senior management.
Essential Technical Skills
- Ability to analyse complex technical information in order to provide advice and guidance to senior management.
- Strong knowledge of IT architectures and methodologies, including cloud environments.
- Significant experience with security technologies, solutions and systems such as:
- Firewalls
- Intruder Detection Systems (IDS) / Intruder Protection Systems (IPS)
- Content Delivery Networks (CDN)
- Advanced Endpoint Protection
- Anti‑Virus/Malware Solutions
- Security Information and Event Management (SIEM)
- Security Orchestration Automation and Response (SOAR)
- Data Loss Prevention (DLP) tooling
- Vulnerability Management Scanners
- Public Key Infrastructure (PKI)
- Symmetric and Asymmetric Cryptography
- Infrastructure as a Service (IaaS)
- Platform as a Service (PaaS)
- Software as a Service (SaaS)
- Cloud Access Security Brokers (CASB)
- Zero Trust Architecture Principles
- Micro‑segmentation
- Threat modelling (OWASP Top 10, PASTA, STRIDE, MITRE)
Security clearance: Security Clearance (SC)
NS&I is one of the largest savings organisations in the UK with more than 24 million customers and over £240 billion invested. We are both a government department and an Executive Agency of the Chancellor of the Exchequer. Our origins can be traced back more than 150 years to 1861. A small company with a big reach, we offer a range of benefits including flexible working, a 9‑day fortnight scheme, a performance‑related variable pay bonus, a generous pension scheme and great opportunities for development. We care for colleagues, respect one another, invest in our people and manage talent effectively.
Cyber Security Manager - National Savings and Investments - G7 in Gateshead employer: Manchester Digital
Contact Detail:
Manchester Digital Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Manager - National Savings and Investments - G7 in Gateshead
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the cyber security field. Attend industry events, join online forums, or even hit up LinkedIn. The more people you know, the better your chances of landing that Cyber Security Manager role.
✨Tip Number 2
Show off your skills! Prepare a portfolio or case studies that highlight your experience with NIST CSF, ISO27001, and any successful risk assessments you've conducted. When you get the chance to chat with potential employers, let them see what you can bring to the table.
✨Tip Number 3
Practice makes perfect! Get ready for interviews by rehearsing answers to common questions about cyber security management. Think about how you’d explain complex concepts to senior management – clarity is key!
✨Tip Number 4
Apply through our website! We’ve got loads of resources to help you ace your application. Plus, it shows you’re genuinely interested in working with us at NS&I. Don’t miss out on the chance to be part of our team!
We think you need these skills to ace Cyber Security Manager - National Savings and Investments - G7 in Gateshead
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in cyber security, especially around the NIST Cyber Security Framework and ISO27001. We want to see how your skills align with the role, so don’t hold back on showcasing your relevant achievements!
Showcase Your Communication Skills: Since this role involves presenting to senior stakeholders, it’s crucial to demonstrate your ability to communicate complex technical information clearly. Include examples of past presentations or reports you've delivered that had a significant impact.
Highlight Your Technical Expertise: We’re looking for someone with strong knowledge of IT architectures and security technologies. Be sure to mention your experience with firewalls, IDS/IPS, and cloud computing methodologies. The more specific you are, the better!
Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team at NS&I!
How to prepare for a job interview at Manchester Digital
✨Know Your Cyber Security Frameworks
Make sure you’re well-versed in the NIST Cyber Security Framework and ISO27001. Be ready to discuss how you've applied these frameworks in your previous roles, as this will show your technical expertise and understanding of industry standards.
✨Prepare for Scenario-Based Questions
Expect questions that ask you to respond to hypothetical security incidents or breaches. Think through your past experiences and be prepared to explain your thought process, actions taken, and the outcomes. This will demonstrate your analytical skills and ability to manage complex situations.
✨Showcase Your Communication Skills
As a Cyber Security Manager, you'll need to present information to senior stakeholders. Practice articulating complex technical concepts in simple terms. Bring examples of past presentations or reports you've delivered to illustrate your communication prowess.
✨Understand Cloud Security Solutions
With the increasing shift to cloud environments, brush up on your knowledge of cloud security methodologies like IaaS, PaaS, and SaaS. Be ready to discuss how you've implemented security solutions in cloud transformations and how you’ve managed data security in those contexts.