Cyber Security Programme Lead

Cyber Security Programme Lead

Full-Time 80000 - 100000 £ / year (est.) No working from home possible
Strategic Resources ERC Ltd

At a Glance

  • Tasks: Lead cyber security initiatives and enhance organisational maturity across multiple functions.
  • Company: Major Oil and Gas Operator with a focus on innovation and security.
  • Benefits: Competitive PAYE contract, professional development, and a dynamic work environment.
  • Other info: Opportunity to drive change and grow within a leading industry.
  • Why this job: Make a significant impact in cyber security while working with diverse teams.
  • Qualifications: Experience in cyber security programmes and strong stakeholder management skills.

The predicted salary is between 80000 - 100000 £ per year.

Our Client, a Major Oil and Gas Operator is seeking an experienced Cyber Security Programme Lead. This is an initial 12 Month PAYE Contract role based in Aberdeen. The Client is seeking a Cyber Security Programme Manager to lead the delivery of its enterprise-wide cyber security maturity uplift.

The role will be accountable for driving The Client’s security maturity across all NIST CSF functions (Govern, Identify, Protect, Detect, Respond, Recover) and aligned with the UK Cyber Assessment Framework (CAF). The Programme Manager will own the end-to-end cyber improvement roadmap, coordinating delivery across IT, Security, Procurement, HR, Legal, Enterprise Risk Management (ERM), and business teams.

This role is responsible for translating strategy into execution, ensuring that priority controls, governance, and capabilities are implemented effectively, and that progress is measured, evidenced, and reported to senior stakeholders.

  • Cyber security programme leadership and delivery
    • Own and deliver the Client cyber security improvement programme aligned to NIST CSF and UK CAF
    • Define, maintain, and execute the integrated delivery roadmap to achieve Level 3 maturity by 2026
    • Establish programme governance, milestones, dependencies, and delivery plans across all workstreams
    • Track delivery progress, manage risks, issues, and interdependencies across multiple initiatives
    • Ensure clear alignment between cyber priorities, enterprise risk, and business objectives
  • Cross-functional coordination and stakeholder engagement
    • Coordinate delivery across IT, Security, Procurement, Legal, ERM, and operational teams
    • Act as the central point of accountability for programme execution and cross-functional alignment
    • Drive engagement and accountability across business units and third parties
    • Support supplier and third-party risk integration into programme delivery
    • Provide clear, consistent communication to senior leadership and governance forums
  • Maturity uplift across NIST CSF domains
    • Govern: enhance structured cyber reporting, and security standards
    • Identify: Ensure accurate asset inventory, classification, and vulnerability management coverage
    • Protect: Oversee enhancement of key controls including configuration, access control, and data protection as well as training, awareness and supply chain security
    • Detect: Increase monitoring coverage and use cases
    • Respond: Establish and mature incident response processes, roles, and testing (e.g. tabletop exercises)
    • Recover: Embed resilience through backup, recovery planning, and regular testing of recovery capabilities
  • Programme controls, reporting, and assurance
    • Define and track KPIs and maturity metrics aligned to NIST CSF and CAF
    • Provide regular reporting on programme status, risks, control effectiveness, and outcomes
    • Ensure appropriate evidence is produced to support regulatory, audit, and assurance requirements
    • Support internal and external audits and regulatory engagement
    • Maintain a clear view of residual risk and ensure escalation through governance forums

Skills, experience & attributes of candidate:

  • Proven experience delivering large-scale cyber security or technology transformation programmes
  • Strong understanding of cyber security frameworks (NIST CSF, UK CAF, ISO 27001)
  • Experience operating across complex stakeholder environments and driving cross-functional delivery
  • Strong programme management capability (planning, risk management, governance, and reporting)
  • Ability to translate cyber strategy into structured, deliverable plans
  • Confident engaging senior leadership and influencing decision-making
  • Strong analytical and problem-solving skills with a pragmatic, outcome-focused approach

Cyber Security Programme Lead employer: Strategic Resources ERC Ltd

As a Major Oil and Gas Operator, our client offers an exceptional work environment in Aberdeen, where innovation meets industry leadership. Employees benefit from a collaborative culture that prioritises professional growth, with opportunities to lead impactful cyber security initiatives aligned with global standards. The company is committed to fostering a diverse workforce and provides comprehensive support for career development, making it an ideal employer for those seeking meaningful and rewarding roles in the energy sector.

Strategic Resources ERC Ltd

Contact Details:

Strategic Resources ERC Ltd Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Security Programme Lead

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by practising common questions and scenarios related to cyber security. We recommend doing mock interviews with friends or using online platforms to get comfortable with your responses.

Tip Number 3

Showcase your expertise! Create a portfolio or a personal website where you can highlight your projects, achievements, and any relevant certifications. This will help you stand out from the crowd.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search!

We think you need these skills to ace Cyber Security Programme Lead

Cyber Security Programme Management
NIST Cybersecurity Framework (CSF)
UK Cyber Assessment Framework (CAF)
ISO 27001
Cross-Functional Coordination
Stakeholder Engagement
Risk Management

Some tips for your application 🫡

Tailor Your CV:Make sure your CV speaks directly to the Cyber Security Programme Lead role. Highlight your experience with NIST CSF and UK CAF, and don’t forget to showcase your programme management skills. We want to see how you’ve driven cyber security initiatives in the past!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re the perfect fit for this role. Share specific examples of how you've led cyber security programmes and engaged with stakeholders. Remember, we love a good story that shows your impact!

Showcase Your Achievements:When detailing your experience, focus on your achievements rather than just responsibilities. Use metrics where possible to demonstrate your success in improving cyber security maturity. We’re all about results, so let us know how you made a difference!

Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about us and what we stand for in the cyber security space.

How to prepare for a job interview at Strategic Resources ERC Ltd

Know Your Cyber Security Frameworks

Make sure you brush up on your knowledge of NIST CSF and UK CAF. Be ready to discuss how you've applied these frameworks in previous roles, as well as how you plan to leverage them in this position. Showing a deep understanding will impress the interviewers.

Demonstrate Cross-Functional Coordination Skills

Prepare examples that showcase your experience in coordinating across various teams like IT, Security, and Procurement. Highlight specific instances where you successfully managed stakeholder engagement and drove alignment on cyber security initiatives.

Showcase Your Programme Management Expertise

Be ready to talk about your programme management skills, especially in planning, risk management, and governance. Bring along metrics or KPIs from past projects to illustrate how you tracked progress and ensured successful delivery.

Communicate Clearly and Confidently

Practice articulating your thoughts clearly, especially when discussing complex topics. The ability to communicate effectively with senior leadership is crucial, so consider rehearsing answers to common questions and presenting your ideas succinctly.