Cyber Security Manager - National Savings and Investments - G7 in Scotland
Cyber Security Manager - National Savings and Investments - G7

Cyber Security Manager - National Savings and Investments - G7 in Scotland

Scotland Full-Time 50000 - 63000 £ / year (est.) Home office (partial)
Go Premium
M

At a Glance

  • Tasks: Lead cyber security initiatives and ensure effective risk management across service providers.
  • Company: Join NS&I, a leading savings organisation with a rich history and a commitment to innovation.
  • Benefits: Enjoy flexible working, generous pension schemes, and opportunities for professional growth.
  • Why this job: Make a real impact in cyber security while working with cutting-edge technologies.
  • Qualifications: Must have CISM or CISSP certification and extensive experience in cyber security management.
  • Other info: Dynamic hybrid work environment with a focus on collaboration and career development.

The predicted salary is between 50000 - 63000 £ per year.

NS&I is one of the largest savings organisations in the UK with more than 24 million customers and over £240 billion invested. We are both a government department and an Executive Agency of the Chancellor of the Exchequer. Our origins can be traced back more than 150 years to 1861. A small company with a big reach, we offer a range of benefits including flexible working, a 9-day fortnight scheme, a performance-related variable pay bonus, a generous pension scheme and great opportunities for development. We care for colleagues, respect one another, invest in our people and manage talent effectively. We are currently working in a hybrid way with colleagues expected to work at their chosen office location for 40% of their working month.

The Cyber Security Manager position is a critical role within the NS&I Risk Directorate. The role supports the Senior Cyber Security Manager in providing assurance that our service providers are operating effective cyber security control environments. Cyber security is a scientific field, encompassing scientific principles and methodologies from multiple disciplines, including computer science, mathematics, engineering, and behavioural sciences. The complexity of cyber security arises from the diverse and evolving nature of threats, technologies, regulations, and human factors involved. Addressing these complexities requires a holistic approach that combines technical expertise, strategic planning, organisational commitment, and continuous adaptation to emerging threats.

The Cyber Security Manager is responsible for being the primary contact for NS&I’s service providers and providing NS&I with assurance that the service providers are managing the complexities and ensuring cyber security risks are mitigated to acceptable levels. The Cyber Security Manager will be proficient in forging and sustaining trust-based relationships with Senior Management across NS&I and service providers/B2B clients that help to build a security focused culture between NS&I and providers and B2B customers.

Person specification

  • Extensive experience of overseeing the performance of service providers and holding them to account for the delivery of critical cyber security services through governance forums.
  • Demonstrable success in delivering written and oral presentations on cyber security and management risk to senior internal and external stakeholders.
  • Substantial experience of assuring evidence against the National Institute of Standards and Technology (NIST) Cyber Security Framework (CSF) and ISO27001.
  • Proven experience of conducting cyber security risk assessments, developing cyber security risk mitigation plans linked to business objectives, and presenting to a senior management audience.
  • Experience in developing cyber security performance metrics linked to business objectives to inform senior management of the performance of the cyber security control environment.
  • Significant experience in responding to or managing security incidents/breaches, overseeing patching/vulnerabilities or hardening systems including detection, response, recovery, and post-incident analysis.
  • Extensive experience of implementing security solutions surrounding cloud transformation, data management, data storage.
  • Strong analytical skills, including the ability to review, challenge and utilise complex technical information to provide advice and guidance to senior management.

Essential Technical Skills

  • Ability to analyse complex technical information in order to provide advice and guidance to senior management.
  • Strong knowledge of IT architectures and methodologies, including cloud environments.
  • Significant experience of understanding of security technologies, solutions, and systems such as:
  • Firewalls
  • Intruder Detection Systems (IDS) / Intruder Protection Systems (IPS)
  • Content Delivery Networks (CDN)
  • Advanced Endpoint Protection
  • Anti-Virus/Malware Solutions
  • Security Information and Event Management (SIEM)
  • Security Orchestration Automation and Response (SOAR)
  • Data Loss Prevention (DLP) tooling
  • Vulnerability Management Scanners
  • Public Key Infrastructure (PKI)
  • Symmetric and Asymmetric Cryptography
  • Strong knowledge of cloud computing methodologies/concepts such as:
    • Infrastructure as a Service (IaaS)
    • Platform as a Service (PaaS)
    • Software as a service (SaaS)
    • Cloud Access Security Brokers (CASB)
    • Zero Trust Architecture Principles
    • Micro-segmentation
  • Knowledge of key Identity and Access Management (IAM) concepts; lifecycle and governance, role-based access control (RBAC), attribute-based access control (ABAC), user provisioning including privileged access management (PAM), workflow and self-service management, password management, audit and compliance, single sign on.
  • Strong understanding of security threats and threat modelling/response capabilities:
    • Threat modelling (OWASP Top 10, PASTA, STRIDE, MITRE)
    • Threat intelligence
    • Threat Hunting

    Essential Qualifications

    • Certified Information Security Manager (CISM) or Certified Information Systems Practitioner (CISSP)

    Desirable knowledge, experience, and skills

    • Experience in designing and assuring secure network architectures, application security, and enterprise security solutions.
    • Experience in designing, managing, and optimising Security Operations Centre’s, including threat monitoring, detection, and response from an assurance perspective.
    • Experience reviewing and overseeing penetration testing and vulnerability assessments and managing remediation processes from an assurance perspective.
    • Experience in threat intelligence analysis and integrating threat intelligence into security operations and strategic planning.

    Security clearance

    Security Clearance (SC)

    Qualifications

    In order to be considered for this role you must confirm that you hold one of the following qualifications: Certified Information Security Manager (CISM) or Certified Information Systems Practitioner (CISSP).

    Cyber Security Manager - National Savings and Investments - G7 in Scotland employer: Manchester Digital

    At National Savings and Investments, we pride ourselves on being an exceptional employer, offering a supportive work culture that values flexibility and employee development. With a range of benefits including a generous pension scheme, a 9-day fortnight, and opportunities for professional growth, we empower our Cyber Security Managers to thrive in a dynamic environment while contributing to the security of over 24 million customers across the UK.
    M

    Contact Detail:

    Manchester Digital Recruiting Team

    StudySmarter Expert Advice 🤫

    We think this is how you could land Cyber Security Manager - National Savings and Investments - G7 in Scotland

    ✨Tip Number 1

    Network like a pro! Reach out to your connections in the cyber security field, attend industry events, and join relevant online forums. The more people you know, the better your chances of landing that Cyber Security Manager role.

    ✨Tip Number 2

    Prepare for interviews by brushing up on your knowledge of the NIST Cyber Security Framework and ISO27001. Be ready to discuss how you've tackled complex security challenges in the past – real-life examples will make you stand out!

    ✨Tip Number 3

    Showcase your analytical skills! During interviews, highlight your ability to analyse complex technical information and provide strategic advice. This is key for a Cyber Security Manager, so make sure you demonstrate this capability.

    ✨Tip Number 4

    Don't forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are proactive about their job search.

    We think you need these skills to ace Cyber Security Manager - National Savings and Investments - G7 in Scotland

    Cyber Security Risk Assessment
    NIST Cyber Security Framework (CSF)
    ISO27001
    Cloud Security Solutions
    Data Management
    Incident Response Management
    Security Information and Event Management (SIEM)
    Threat Modelling
    Identity and Access Management (IAM)
    Analytical Skills
    Presentation Skills
    Stakeholder Engagement
    Security Operations Centre Management
    Vulnerability Management
    Certified Information Security Manager (CISM) or Certified Information Systems Practitioner (CISSP)

    Some tips for your application 🫡

    Tailor Your Application: Make sure to customise your CV and cover letter for the Cyber Security Manager role. Highlight your experience with NIST CSF and ISO27001, as well as any relevant projects that showcase your skills in managing cyber security risks.

    Showcase Your Achievements: Don’t just list your responsibilities; share specific achievements that demonstrate your impact in previous roles. Use metrics where possible to show how you’ve improved security measures or managed incidents effectively.

    Be Clear and Concise: When writing your application, keep it clear and to the point. Avoid jargon unless necessary, and ensure your key points stand out. We want to see your qualifications and experience without wading through unnecessary fluff!

    Apply Through Our Website: We encourage you to apply directly through our website for the best chance of getting noticed. It’s the easiest way for us to track your application and ensure it reaches the right people!

    How to prepare for a job interview at Manchester Digital

    ✨Know Your Cyber Security Frameworks

    Make sure you’re well-versed in the NIST Cyber Security Framework and ISO27001. Be ready to discuss how you've applied these frameworks in your previous roles, especially in relation to risk assessments and mitigation plans.

    ✨Showcase Your Communication Skills

    As a Cyber Security Manager, you'll need to present complex information clearly to senior management. Prepare examples of past presentations or reports you've delivered, focusing on how you made technical details accessible to non-technical stakeholders.

    ✨Demonstrate Your Analytical Skills

    Be prepared to discuss specific instances where you've analysed complex technical information to provide guidance. Think about challenges you've faced and how your analytical skills helped resolve them, particularly in security incidents or risk assessments.

    ✨Build Trust-Based Relationships

    Since this role involves working closely with service providers, think of examples where you've successfully built and maintained trust-based relationships. Highlight your approach to fostering a security-focused culture and how it benefited your previous organisations.

    Cyber Security Manager - National Savings and Investments - G7 in Scotland
    Manchester Digital
    Location: Scotland
    Go Premium

    Land your dream job quicker with Premium

    You’re marked as a top applicant with our partner companies
    Individual CV and cover letter feedback including tailoring to specific job roles
    Be among the first applications for new jobs with our AI application
    1:1 support and career advice from our career coaches
    Go Premium

    Money-back if you don't land a job in 6-months

    M
    • Cyber Security Manager - National Savings and Investments - G7 in Scotland

      Scotland
      Full-Time
      50000 - 63000 £ / year (est.)
    • M

      Manchester Digital

      50-100
    Similar positions in other companies
    UK’s top job board for Gen Z
    discover-jobs-cta
    Discover now
    >