At a Glance
- Tasks: Lead UK cyber risk initiatives and enhance security governance across teams.
- Company: Join PayPal, a leader in creating an inclusive global economy.
- Benefits: Enjoy flexible work culture, generous time off, and comprehensive health coverage.
- Other info: Be part of a diverse team committed to inclusivity and personal growth.
- Why this job: Make a real impact on cyber security while developing your leadership skills.
- Qualifications: 8+ years in cyber risk or related fields; strong writing and collaboration skills.
The predicted salary is between 70000 - 90000 £ per year.
Provide strong UK cyber/technology risk operational leadership in support of the UK Entity CISO. The role leads day‑to‑day execution of agreed UK cyber risk activities across key workstreams including cloud modernisation and operational resilience; co‑develops committee packs with the UK Entity CISO; drives collaboration across PCIS, ICR and technology teams; and leads UK cyber security awareness activity. The role also contributes to progressing UK regulatory and cyber/technology security strategy and maturity, aligned to UK and PCIS priorities.
Essential Responsibilities
- Recognized as a security governance, risk, and compliance expert, independently addressing the most complex security risks and providing strategic direction on risk mitigation and governance practices across the security domain.
- Define methods and procedures for new or special assignments, collaborating with cross‑functional teams to drive security risk and governance initiatives that align with business needs and objectives.
- Lead complex, high‑impact security governance and risk management initiatives, leveraging a deep understanding of business trends and security challenges to develop innovative risk mitigation strategies and solutions.
- Possess a keen awareness of the broader impact of decisions, with initiatives driving enterprise‑wide improvements in risk management and security governance, enhancing overall security practices and operational efficiency.
- Lead a security risk and governance team; set clear priorities and define actionable plans, ensuring alignment with organisational goals.
- Guide team members through complex challenges, fostering their growth and development while maintaining a focus on high‑impact results.
Minimum Qualifications
- 8+ years relevant experience and a Bachelor's degree OR any equivalent combination of education and experience.
Additional Responsibilities & Preferred Qualifications
- UK Cyber Risk Operational Execution and Delivery: Maintain a UK‑focused view of priority cyber/technology risk items across change, issues, and assurance activity. Run an operating rhythm (cadence, trackers, prioritisation) to keep UK topics current and decision‑ready. Translate UK Entity CISO priorities into defined workstreams with clear ownership, timelines, and outcomes.
- Cloud Modernisation: Maintain visibility of UK‑relevant cloud modernisation activity (migrations, platform changes, decommissioning, architecture shifts) and provide concise UK‑focused updates. Actively participate in highlighting regulatory requirements and cyber security opportunities for cloud modernisation, drawing on knowledge from UK obligations and wider work within ICR teams.
- Operational Resilience Workstreams: Maintain visibility of UK operational resilience workstreams impacting Important Business Services (IBS), including technology dependencies, material issues, and remediation actions. Ensure actions have clear ownership and progress, and that evidence is available for governance needs.
- Governance and Committee Packs: Co‑develop committee packs with the UK Entity CISO: propose structure, draft sections, integrate inputs, and ensure readiness to deadline. Produce executive‑ready content: clear status snapshots, key messages, decision points for consideration, and evidence links.
- Cross‑functional Delivery: Build and sustain working relationships across PCIS/ICR and technology/service owners to progress UK priorities. Remove blockers, clarify ownership, and ensure follow‑up actions are completed.
- UK Regulatory and Security Strategy Contribution: Contribute to the development and progression of UK regulatory, cyber and technology security strategy and maturity objectives, aligned with UK Entity needs and PCIS priorities.
- System‑led Insight and Evidence Management: Use Firefly, Jira, Confluence, ServiceNow, Archer, AuditBoard (and related tooling) to source, validate, and maintain evidence for UK governance and risk needs.
- UK Cyber Security Awareness Activities: Own the UK cyber security awareness plan aligned to PCIS strategy. Deliver UK‑tailored comms and reusable materials (posts, talking points, FAQs) and run local events/awareness moments.
What Success Looks Like
- Cloud modernisation activity is UK‑ready: regulatory requirements are surfaced early, evidence is reusable, and the cloud regulatory assessment/sign‑off cycle time improves through the ICR OKR initiative.
- Operational resilience topics are visible, well‑managed, and supported with clear evidence for governance.
- Committee packs are delivered on time with strong narrative, clean evidence, and clear decision points.
- UK regulatory and security maturity objectives progress in line with UK and PCIS priorities, with clear initiatives and evidence of improvement.
- UK awareness activity is embedded and delivered as part of a predictable annual rhythm.
Skills and Experience
- Experience in cyber/technology risk, security governance, cloud governance/assurance, operational resilience support, or similar roles (regulated environment beneficial).
- Strong executive writing (committee pack content, briefings, action logs).
- Proven ability to lead cross‑functional delivery and influence stakeholders.
- Confident using Jira/Confluence (or equivalents) and reporting/risk tooling.
Our Benefits
At PayPal, we're committed to building an equitable and inclusive global economy. We offer comprehensive, choice‑based programs to support all aspects of personal wellbeing—physical, emotional, and financial—delivering meaningful value where it matters most. We strive to create a flexible, balanced work culture with a holistic approach to benefits, including generous paid time off, healthcare coverage for you and your family, and resources to create financial security and support your mental health.
Commitment to Diversity and Inclusion
PayPal provides equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, pregnancy, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state, or local law. In addition, PayPal will provide reasonable accommodations for qualified individuals with disabilities.
Belonging at PayPal
Our employees are central to advancing our mission, and we strive to create an environment where everyone can do their best work with a sense of purpose and belonging. Belonging at PayPal means creating a workplace with a sense of acceptance and security where all employees feel included and valued.
UK Cyber Security & Risk Senior Manager employer: PayPal, Inc.
At PayPal, we pride ourselves on being an exceptional employer, offering a dynamic work culture that prioritises flexibility and inclusivity. Our comprehensive benefits package supports the holistic wellbeing of our employees, while our commitment to professional growth ensures that team members can thrive in their careers. Located in the UK, this role provides a unique opportunity to lead impactful cyber security initiatives within a collaborative environment, making a meaningful contribution to our mission of building an equitable global economy.
StudySmarter Expert Advice🤫
We think this is how you could land UK Cyber Security & Risk Senior Manager
✨Tip Number 1
Network like a pro! Reach out to folks in the cyber security field, especially those already working at PayPal. A friendly chat can open doors and give you insider info on what it’s really like to work there.
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of UK cyber risk and operational resilience. Be ready to discuss how you can contribute to cloud modernisation and governance initiatives. Show us you know your stuff!
✨Tip Number 3
Don’t just wait for job openings—create your own opportunities! Keep an eye on our website and apply directly. Tailor your application to highlight your experience in security governance and risk management.
✨Tip Number 4
Follow up after interviews with a thank-you note. It’s a simple way to show appreciation and keep your name fresh in the minds of the hiring team. Plus, it shows you’re genuinely interested in the role!
We think you need these skills to ace UK Cyber Security & Risk Senior Manager
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in cyber security and risk management. Use keywords from the job description to show that you understand what we're looking for.
Showcase Your Leadership Skills:Since this role involves leading teams and initiatives, be sure to include examples of how you've successfully managed projects or guided teams in the past. We want to see your ability to drive results!
Be Clear and Concise:When writing your application, keep it straightforward. Use bullet points where possible and make sure your key achievements stand out. We appreciate clarity and directness in communication.
Apply Through Our Website:Don't forget to submit your application through our official website! This ensures that your application is processed correctly and gives you the best chance of being considered for the role.
How to prepare for a job interview at PayPal, Inc.
✨Know Your Cyber Security Stuff
Make sure you brush up on the latest trends in cyber security and risk management. Be ready to discuss specific examples of how you've tackled complex security risks in the past, especially in relation to cloud modernisation and operational resilience.
✨Showcase Your Leadership Skills
This role requires strong leadership, so be prepared to share experiences where you've led cross-functional teams or initiatives. Highlight how you've set clear priorities and guided team members through challenges, ensuring alignment with organisational goals.
✨Be Ready with Executive Writing Samples
Since you'll be co-developing committee packs and executive content, bring along samples of your previous work. This could include reports, briefings, or any documentation that showcases your ability to communicate complex information clearly and effectively.
✨Understand Regulatory Requirements
Familiarise yourself with UK regulatory requirements related to cyber security. Be ready to discuss how you've previously navigated these regulations and how you can contribute to the development of security strategies that align with both UK and PCIS priorities.