Head of Cyber Protection

Head of Cyber Protection

Full-Time No working from home possible
M

As the Head of Cyber Protection, you will drive a proactive risk-based approach to cyber security, ensuring threats and vulnerabilities are identified, understood, prioritised, and effectively managed. You will lead a high-performing team, foster a culture of continuous improvement, and work closely with senior stakeholders across the business to strengthen Metro Bank's security posture while enabling innovation and growth.

  • Lead Metro Bank's Cyber Protection capability, including Cyber Risk Assessment, Cyber Awareness & Training, Identity & Access Management (IAM), and Data Loss Prevention (DLP).
  • Define and deliver the Cyber Protection strategy and roadmap, ensuring alignment with the Bank's overall cyber security and business objectives.
  • Oversee cyber risk assessments for technology change and development, ensuring risks are identified and managed effectively.
  • Drive cyber awareness across the organisation, helping colleagues understand their responsibilities and adopt secure behaviours.
  • Ensure appropriate controls are in place to manage access to systems and data, following least-privilege and security best practices.
  • Lead the Data Loss Prevention capability, protecting sensitive customer and business information from unauthorised access or disclosure.
  • Work closely with Technology, Data, Risk, Change and business teams to embed security into processes, projects and new solutions.
  • Provide regular reporting to the CISRO and governance forums on cyber risks, control effectiveness, capability maturity and key priorities.
  • Build and develop a high-performing team, creating a culture of accountability, collaboration and continuous improvement.
  • Manage suppliers, budgets and service performance to ensure the Cyber Protection function delivers effective outcomes and value.
  • Work effectively with second and third lines of defence, external auditors and regulators to support strong governance and compliance.
  • Any other duties as reasonably required within the role
    Proven experience operating in a senior cyber security leadership role within a regulated financial services environment or similarly complex organisation.
  • Demonstrable expertise in leading cyber protection, security engineering, security architecture, vulnerability management, identity and access management, or security operations functions.
  • Strong track record of delivering significant cyber security control improvements, remediation programmes, and transformation initiatives across complex technology estates.
  • Deep technical understanding of enterprise cyber security controls, including identity and access management, endpoint security, network security, cloud security, vulnerability management, logging and monitoring.
  • Strong knowledge of industry-standard cyber security frameworks and methodologies, including NIST CSF, ISO 27001, CIS Controls, COBIT and MITRE ATT&CK.
  • Experience communicating cyber risks, control effectiveness and investment recommendations to Executive Committees, senior leadership teams and governance forums.
  • Proven ability to translate complex technical cyber risks into clear business impacts and actionable recommendations for non-technical stakeholders.
  • Experience working with second and third lines of defence, external auditors and regulatory bodies, ensuring effective governance and regulatory compliance.
  • Strong stakeholder management and influencing skills, with the ability to constructively challenge, build consensus and drive accountability across all levels of the organisation.
  • Demonstrated experience managing security budgets, suppliers and third-party service providers, ensuring effective operational performance and value for money.
  • Proven people leadership experience, including building high-performing teams, developing talent and fostering a culture of continuous improvement.
  • Strong understanding of cyber threats, attack methodologies and emerging security trends across hybrid and cloud environments.
  • Relevant professional cyber security qualification such as CISSP, CISM, CISA, CRISC, CCSP or equivalent.
  • Understand the risks associated with your job and what that means for you, Metro Bank and all our stakeholders
    At Metro Bank, we believe the best banking experience starts with people who genuinely care. We're not just delivering banking services - we're building trust through authentic connections. Here, our people come first; our colleagues are part of a team that values individuality, collaboration, and long-standing relationships. We are also all about balance so most of our jobs offer the opportunity for hybrid working built around your role and home life, wherever possible.
  • We will make sure that you are well-rewarded by providing you with a competitive salary, discretionary annual bonus, and a wide range of benefits, including generous holiday allowance, attractive pension scheme, healthcare, life assurance, and a number of colleague discounts!
  • We will give you the training to ensure you succeed in your role and plenty of internal opportunities to progress your career (around 40% of our recruitment comes from internal promotions!

#J-18808-Ljbffr

Head of Cyber Protection employer: Metro Bank

At Metro Bank, we pride ourselves on being an employer that truly values its people, fostering a culture of collaboration and individuality in the heart of Holborn, Greater London. With a strong commitment to employee growth, we offer extensive training and internal promotion opportunities, ensuring that our team members can thrive in their careers while enjoying a competitive salary and a comprehensive benefits package. Our flexible working arrangements and focus on work-life balance make us an attractive choice for those seeking a meaningful and rewarding role in the banking sector.

M

Contact Details:

Metro Bank Recruitment Team