At a Glance
- Tasks: Lead cybersecurity governance and risk management to ensure secure operations.
- Company: Dynamic financial services organisation focused on technology and security.
- Benefits: Competitive salary, professional development, and a collaborative work environment.
- Why this job: Make a real impact in cybersecurity while enabling secure decision-making.
- Qualifications: Strong background in cybersecurity governance and risk management.
- Other info: Join a forward-thinking team with opportunities for growth and mentorship.
The predicted salary is between 36000 - 60000 ÂŁ per year.
About the Organisation
The organisation operates across multiple regions and delivers technology‑enabled services to customers in both regulated and non‑regulated markets. It prioritises secure operations, responsible technology adoption, and a forward‑looking approach to risk management that supports growth and digital transformation.
Role Purpose
This role is responsible for building and maintaining the organisation's cybersecurity governance model, ensuring that security expectations are clearly defined, easily understood, and consistently applied across all teams. You will oversee the development of security policies and control frameworks, coordinate risk and compliance activity, and act as a partner to technology, operations, product, and risk teams. Your purpose is to enable secure decision‑making, not simply enforce rules - balancing risk, business needs, and practical implementation.
What You'll Do
- Establish and maintain the organisation's cybersecurity governance framework, including policies, control sets, and operating standards.
- Convert high‑level principles into clear, practical guidance for engineering, operations, and business teams.
- Lead the organisation's cybersecurity risk assessment processes, reviewing threats, control gaps, and remediation plans.
- Coordinate activity required for external reviews, assessments, or certifications aligned to recognised security frameworks.
- Evaluate the effectiveness of existing controls and ensure remediation activities are tracked and closed.
- Produce risk insights, metrics, and reporting for senior leadership and governance forums.
- Provide governance oversight for technology change, digital projects, and third‑party engagements.
- Perform assessments of internal systems, applications, vendors, and service providers where required.
- Partner with teams across the organisation to embed secure‑by‑design thinking and risk‑aware decision‑making.
- Support business continuity, incident readiness, and broader operational resilience initiatives.
Skills & Experience
Must Have
- Strong background in cybersecurity governance, technology risk, or information assurance.
- Experience writing, implementing, or managing security policies and control frameworks.
- Ability to interpret high‑level security concepts and translate them into usable, pragmatic controls.
- Knowledge of recognised frameworks (e.g., ISO 27001, NIST CSF, SOC 2) without needing to be tied to specific industry implementations.
- Comfortable engaging with senior stakeholders and presenting risk and security themes with clarity.
- Good understanding of audit processes, risk assessments, and control testing.
- Strong organisational and communication skills with the ability to work independently.
Nice to Have
- Security or risk certifications (e.g., CISSP, CISA, CRISC, Security+).
- Experience with GRC platforms or building governance processes.
- Background in a regulated, technology‑driven, or large‑scale environment.
- Experience leading small teams or mentoring colleagues.
- Formal education in cybersecurity, IT, assurance, or similar disciplines (beneficial but not essential).
McGregor Boyall is an equal opportunity employer and do not discriminate on any grounds.
Cyber Governance & Risk Enablement Lead in City of London employer: McGregor Boyall
Contact Detail:
McGregor Boyall Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Governance & Risk Enablement Lead in City of London
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the cybersecurity field. Attend industry events, webinars, or even local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or a personal website where you can showcase your projects, certifications, and any relevant experience. This gives potential employers a tangible way to see what you bring to the table.
✨Tip Number 3
Prepare for interviews by practising common questions related to cybersecurity governance and risk management. Think about how you can demonstrate your ability to translate high-level concepts into practical solutions. We want to see you shine!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team and contributing to our mission.
We think you need these skills to ace Cyber Governance & Risk Enablement Lead in City of London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV speaks directly to the role of Cyber Governance & Risk Enablement Lead. Highlight your experience in cybersecurity governance and risk management, and don’t forget to mention any relevant frameworks you’re familiar with!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re the perfect fit for this role. Share specific examples of how you've implemented security policies or managed risk assessments in the past.
Showcase Your Communication Skills: Since you'll be engaging with senior stakeholders, it's crucial to demonstrate your communication skills. Use clear and concise language in your application to show that you can present complex security themes effectively.
Apply Through Our Website: We encourage you to apply through our website for a smoother process. It’s the best way for us to receive your application and ensure it gets the attention it deserves!
How to prepare for a job interview at McGregor Boyall
✨Know Your Cybersecurity Frameworks
Familiarise yourself with recognised frameworks like ISO 27001 and NIST CSF. Be ready to discuss how these frameworks can be applied in practical scenarios, as this will show your understanding of cybersecurity governance and risk management.
✨Translate Concepts into Actionable Guidance
Prepare examples of how you've taken high-level security principles and turned them into clear, actionable policies or controls. This demonstrates your ability to bridge the gap between theory and practice, which is crucial for the role.
✨Engage with Stakeholders
Think about past experiences where you’ve had to present risk and security themes to senior stakeholders. Be prepared to share how you communicated complex information clearly and effectively, as this will highlight your strong communication skills.
✨Showcase Your Risk Assessment Experience
Be ready to discuss your experience with risk assessments and control testing. Bring specific examples of how you've identified threats and gaps, and what remediation plans you implemented. This will illustrate your hands-on experience in managing cybersecurity risks.