At a Glance
- Tasks: Lead cyber risk management and enhance security frameworks at Metro Bank.
- Company: Metro Bank, where people come first and trust is built through connections.
- Benefits: Competitive salary, annual bonus, generous holidays, and great career progression opportunities.
- Other info: Hybrid working options available to balance work and life.
- Why this job: Make a real impact in cybersecurity while working in a supportive and collaborative environment.
- Qualifications: 7+ years in Information Security or Cyber Risk with strong regulatory knowledge.
The predicted salary is between 80000 - 100000 £ per year.
At Metro Bank, we believe the best banking experience starts with people who genuinely care. We’re not just delivering banking services - we’re building trust through authentic connections. Here, our people come first; our colleagues are part of a team that values individuality, collaboration, and long-standing relationships. We are also all about balance so most of our jobs offer the opportunity for hybrid working built around your role and home life, wherever possible.
What you will do
- Lead Risk input into the Cyber Risk Improvement Programme, providing updates to SteerCo, Board, and regulators.
- Offer informed perspectives on risk reduction strategy and oversee third-party co-source arrangements.
- Take ownership of building and enhancing the 2LOD cyber risk oversight capability, including leveraging external partners.
- Provide ongoing oversight and assurance of the Information Security (Infosec) and Cyber risk and control environment.
- Deliver independent review and challenge across Infosec improvement programmes, including validation of risk position, prioritisation, target operating model, service design, and overall feasibility.
- Ensure identified control gaps are effectively addressed within solution design, and assess the maturity, sustainability, and practicality of proposed controls.
- Act as the key liaison between third-party assurance providers and internal stakeholders at Metro Bank.
- Conduct robust review and challenge of policies, standards, metrics, risks, and controls to ensure effectiveness and alignment with regulatory expectations.
- Ensure testing and assurance activities are completed to high standards and provide reliable outcomes.
- Support senior risk reporting by contributing clear, accurate updates on the Bank’s Infosec and Cyber risk posture to executive committees.
- Review and challenge the 1LOD approach to identifying and managing emerging risks.
- Provide input and challenge on regulatory updates and notifications to ensure appropriate response and compliance.
- Influence and challenge the design of Information Security controls across IT and the wider business to ensure they are efficient, effective, and aligned with the evolving threat landscape.
- Promote transparency and accountability in Information Security decisions across all supported programmes and projects.
- Build and maintain strong relationships with senior stakeholders across Information & Cyber Security, Audit, and Risk functions.
- Any other duties as required that reasonably fall within the job.
And… we are a bank so risk is a part of everything we do. We love people who take responsibility, do the right thing for customers, colleagues and Metro Bank and have the ability to call out any concerns.
What you will need
- Extensive experience (7+ years) in Information Security, Cyber, Technology Risk, or 2nd Line Risk, operating at Manager, Lead, or Head level.
- Demonstrated experience within a regulated UK financial services environment, with strong understanding of regulatory expectations and industry standards.
- Proven track record of designing, implementing, or enhancing risk management and resilience frameworks.
- Confident presenting to senior stakeholders, including Executive Committees and Board Risk Committees, with the ability to influence decision-making.
- Relevant professional certifications are desirable (e.g. CISSP, CISM, CISA, CRISC, ISO 27001), reflecting expertise across both Information Security and Risk disciplines.
- Strong experience in risk assessment methodologies, including RCSAs, control testing, and scenario analysis.
- Practical knowledge of secure design, build, and control frameworks aligned to recognised standards such as ISO 27001, PCI DSS, and NIST.
- Solid understanding of the regulatory landscape impacting financial institutions and the ability to interpret and apply regulatory requirements effectively.
- Good understanding of Information Security within the project lifecycle, combined with strong working knowledge of enterprise technology environments.
- Demonstrated experience in conducting security risk assessments for projects and designing effective, proportionate security controls.
- Strong communication skills, with the ability to translate complex technical and risk concepts into clear, actionable insights for non-technical stakeholders.
- Ability to critically assess regulatory and cyber risks across systems and projects, considering the broader business and Information Security context.
- Clear understanding of operational and enterprise risk, with accountability for managing the impact of risk decisions on the organisation and its stakeholders.
- Understand the risks associated with your job and what that means for you, Metro Bank and all our stakeholders.
Our promise to you
- We will make sure that you are well-rewarded by providing you with a competitive salary, discretionary annual bonus, and a wide range of benefits, including generous holiday allowance, attractive pension scheme, healthcare, life assurance, and a number of colleague discounts!
- We will give you the training to ensure you succeed in your role and plenty of internal opportunities to progress your career (around 40% of our recruitment comes from internal promotions!).
Lead Cyber Risk Manager in London employer: Metro Bank Plc
At Metro Bank, we prioritise our people and foster a collaborative work culture that values individuality and authentic connections. As a Lead Cyber Risk Manager, you will benefit from hybrid working options, a competitive salary, and a comprehensive benefits package, including generous holiday allowance and career progression opportunities, with 40% of our roles filled through internal promotions. Join us in a dynamic environment where your expertise in cyber risk will be valued and where you can make a meaningful impact on our customers and colleagues alike.
StudySmarter Expert Advice🤫
We think this is how you could land Lead Cyber Risk Manager in London
✨Network Like a Pro
Get out there and connect with people in the industry! Attend events, join online forums, or even hit up LinkedIn. Building relationships can open doors that a CV just can't.
✨Ace the Interview
Prepare for your interviews by researching Metro Bank's values and recent news. Show them you care about their mission and how you can contribute to their goals. Practice common interview questions and have your own ready to ask!
✨Showcase Your Skills
Don’t just talk about your experience; demonstrate it! Bring examples of your past work, especially those that align with cyber risk management. Use real scenarios to show how you’ve tackled challenges in the past.
✨Follow Up
After your interview, send a quick thank-you note. It shows appreciation and keeps you on their radar. Plus, it’s a great chance to reiterate your enthusiasm for the role at Metro Bank!
We think you need these skills to ace Lead Cyber Risk Manager in London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in Information Security and Cyber Risk. We want to see how your skills align with the specific needs of Metro Bank, so don’t hold back on showcasing your relevant achievements!
Showcase Your Experience:With 7+ years in the field, it’s crucial to detail your past roles and responsibilities. We’re looking for concrete examples of how you’ve designed or enhanced risk management frameworks, so be specific about your contributions and outcomes.
Communicate Clearly:When writing your application, keep it clear and concise. Use straightforward language to explain complex concepts, as we value strong communication skills. Remember, you’ll need to present to senior stakeholders, so let that shine through in your writing!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining the Metro Bank team!
How to prepare for a job interview at Metro Bank Plc
✨Know Your Cyber Risk Stuff
Make sure you brush up on the latest trends and regulations in cyber risk management. Be ready to discuss your experience with frameworks like ISO 27001 or PCI DSS, and how you've applied them in previous roles. This shows you're not just familiar with the theory but can also put it into practice.
✨Showcase Your Stakeholder Skills
Since you'll be liaising with senior stakeholders, prepare examples of how you've influenced decision-making in the past. Think about times when you presented complex information clearly to non-technical audiences. This will demonstrate your ability to communicate effectively across different levels of the organisation.
✨Prepare for Scenario Questions
Expect questions that ask you to assess risks in hypothetical situations. Practice articulating your thought process on how you would identify and mitigate risks, especially in a financial services context. This will highlight your analytical skills and understanding of the regulatory landscape.
✨Emphasise Team Collaboration
Metro Bank values teamwork, so be ready to discuss how you've worked collaboratively in the past. Share specific examples of how you've built relationships with colleagues and external partners to enhance risk management efforts. This will show that you align with their culture of collaboration and trust.