At a Glance
- Tasks: Lead cyber security strategy and policy initiatives while enhancing organisational resilience.
- Company: Join a forward-thinking organisation committed to cyber security excellence.
- Benefits: Competitive salary, professional development, and a chance to shape the future of cyber security.
- Other info: Be part of a dynamic team with opportunities for growth in a critical sector.
- Why this job: Make a real impact in cyber security and drive cultural change across the organisation.
- Qualifications: Experience in cyber security policy and risk management is essential.
The predicted salary is between 48000 - 72000 £ per year.
The Strategy & Policy Team Lead plays a key role in supporting the Deputy CISO by overseeing strategic cyber security initiatives, refining governance processes, fostering cross-functional collaboration, and strengthening communication across the organisation. This role also drives the development of security awareness, education, and culture throughout the business. Acting as a trusted advisor and liaison, the Team Lead helps align cyber risk management, compliance efforts, and leadership engagement. They contribute to shaping the broader cyber security strategy and enhancing CS&IA’s long-term capability and resource planning. Additionally, they promote risk awareness and translate strategic security objectives into actionable insights for senior leadership.
PRINCIPAL ACCOUNTABILITIES
- Drive continuous improvement of cyber security processes, controls, and metrics to enhance resilience and reduce risk.
- Support the Deputy CISO in shaping and delivering the cyber security strategy, including talent planning and resource coordination.
- Coordinate governance boards and meetings, and prepare executive briefings, board papers, and stakeholder presentations.
- Act as a key liaison with NDA, GICC, and other oversight bodies, managing cross-cutting issues and urgent priorities.
- Develop and maintain cyber security policies, standards, and procedures, ensuring alignment with regulatory and organisational requirements.
- Maintain the cyber risk register and ensure accurate reporting of key metrics, maturity indicators, and dashboards for leadership.
- Lead internal cyber awareness campaigns and training initiatives to embed a strong security culture.
- Enhance governance processes, documentation standards, and operational workflows.
- Promote automation and innovation in compliance and assurance activities to improve efficiency and transparency.
AUTHORITIES & DIMENSIONS
- Directly manages a team of three within the Cyber Security Strategy & Policy function.
- Provides technical leadership across all CS&IA security domains, ensuring alignment with strategic objectives.
- Influences up to 16,000 personnel through the development and implementation of cyber security policy, risk management, and assurance across both IT and OT environments.
- Safeguards enterprise reputation by proactively managing and communicating cyber risks in collaboration with the CS&IA team, particularly in a landscape of increasing public, regulatory, and stakeholder scrutiny.
KNOWLEDGE SKILLS & EXPERIENCE
Essential
- Proven experience in drafting, reviewing, and implementing cyber security policies, procedures, and standards.
- Degree or equivalent professional experience in cyber security, information assurance, risk management, or a related discipline.
- Strong understanding of cyber risk management, including qualitative and quantitative risk assessments and maintenance of risk registers.
- Demonstrated ability to develop and track cyber security metrics, including dashboards and reporting for senior executives and governance forums.
- Familiarity with regulatory and legislative frameworks such as ONR SyAPs, CAF, NIS/NIS2, DPA, and GDPR.
- Experienced in engaging a wide range of stakeholders, including technical teams, business units, and risk, audit, and compliance functions.
- Proficient in data visualisation tools such as Power BI, Excel, and ServiceNow dashboards.
- Experience supporting cyber security awareness and culture change initiatives, including campaigns, briefings, and training delivery.
Desirable
- Experience in the nuclear, critical national infrastructure, or similarly regulated sectors.
- Knowledge of information security frameworks and standards (e.g., ISO/IEC 27001, ISO 27005, NIST CSF, CAF, NIST SP 800-53, CIS Controls).
- Familiarity with enterprise risk management frameworks and integration of cyber risk into broader business risk processes.
- Understanding of assurance models (1st, 2nd, 3rd line) and their application in cyber security.
- Experience with supplier assurance frameworks and third-party risk management tools.
- Experience working within federated or group structures (e.g., NDA Group) to align assurance practices.
- Awareness of digital transformation and its impact on cyber governance and risk.
- Experience engaging with regulatory bodies such as the ONR or ICO.
JOB CONTEXT AND CHALLENGES
This is a newly established role within the organisation, created to lead the development and implementation of cyber security policies, standards, and governance frameworks. The role plays a critical part in shaping the future-state (“to-be”) model of the cyber security function, helping to define its structure, capabilities, and strategic direction. A key challenge lies in reviewing existing policies and standards, identifying gaps, and establishing a coherent and forward-looking framework that aligns with regulatory expectations and business needs. This includes building a strong reference model and ensuring consistency across IT and OT environments. The role requires a deep understanding of cyber security across the organisation, particularly within ICT & Digital / ISO, to ensure CS&IA is effectively integrated and resourced to support delivery. It also involves working closely with stakeholders to identify policy gaps, drive improvements, and build the capability needed to mature the function. Operating in a complex and evolving threat landscape, the role must balance strategic oversight with hands-on delivery, ensuring that cyber risk is well understood, communicated, and managed across the enterprise.
Cyber Strategy and Policy Team Lead in Nottingham employer: Trades Workforce Solutions
At Sellafield Ltd, we pride ourselves on being an exceptional employer, offering a dynamic work environment that fosters innovation and collaboration in the field of cyber security. Our commitment to employee growth is evident through tailored training programmes and opportunities for advancement, ensuring that our team members are equipped to tackle the evolving challenges of the cyber landscape. Located in a region rich in heritage and community spirit, we promote a culture of inclusivity and support, making us an ideal choice for those seeking meaningful and rewarding careers.
Contact Details:
Trades Workforce Solutions Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Strategy and Policy Team Lead in Nottingham
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Trades Workforce Solutions, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Trades Workforce Solutions
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Trades Workforce Solutions. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Cyber Strategy and Policy Team Lead in Nottingham
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Trades Workforce Solutions insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Trades Workforce Solutions that you’re committed to staying ahead in the game.
How to prepare for a job interview at Trades Workforce Solutions
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Trades Workforce Solutions to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Trades Workforce Solutions.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.