Cyber Policy Lead in Edinburgh

Cyber Policy Lead in Edinburgh

Edinburgh Full-Time 40000 - 50000 £ / year (est.) Home office (partial)
U

At a Glance

  • Tasks: Lead the development and management of cyber policy frameworks to enhance organisational resilience.
  • Company: Join the Financial Conduct Authority, a key player in regulating UK financial services.
  • Benefits: Enjoy a competitive salary, hybrid working, and opportunities for professional growth.
  • Other info: Be part of a dynamic team with a focus on modernising and simplifying processes.
  • Why this job: Make a real difference in protecting consumers and financial markets through innovative cyber policies.
  • Qualifications: Experience in policy management, cyber security, and strong analytical skills required.

The predicted salary is between 40000 - 50000 £ per year.

The Cyber and Operational Resilience directorate enables secure and resilient regulation across the FCA and PSR, supporting the protection of UK consumers and financial markets.

This Senior Associate sits within the Policy & Risk team, part of the wider Governance and Human Risk function. The role focuses on the management and maintenance of the Cyber & Information Resilience Policy Framework, including associated standards, procedures and guidance.

Role Responsibilities

  • Maintain and refresh the cyber policy framework by managing policy and standards updates in line with agreed review/refresh cycles and making out-of-cycle updates where material changes are required.
  • Modernise and simplify the policy & standards suite, exploring improved formats (e.g., “standards on a page”) to increase usability and adoption across the organisation.
  • Serve as the FCA-wide point of contact for policy requirements, handling BAU and project-related queries and providing clear, consistent interpretations of published requirements.
  • Manage and track policy non‑compliance and exceptions, including owning and modernising the Policy Waiver process and ensuring issues are surfaced and understood by relevant stakeholders.
  • Conduct policy gap analysis and horizon scanning, identifying emerging risks, regulatory/industry changes and required updates to keep the framework current and effective.
  • Support articulation of the organisation’s Cyber Risk Appetite through the policy framework, ensuring requirements align to risk tolerance and are understood across the business.
  • Enable a new self‑service policy model for low‑risk projects, helping define requirements and controls that balance agility with the FCA’s risk appetite.
  • Provide reporting and governance support by assisting the Risk lead with controls performance measurement and supporting the GHR Manager/CISO with reporting on cyber issues, audit/risk engagements and organisational non‑compliance; additionally supporting specialist investigation teams and HR with policy interpretation where needed.

Location: Edinburgh

Contract type: Full time, Permanent

Working pattern: Hybrid, Office based

Closing Date: 22/06/2026

Cyber Policy Lead in Edinburgh employer: UK Regulators' Network

The Financial Conduct Authority (FCA) is an exceptional employer, offering a dynamic work environment in Edinburgh that prioritises employee growth and development. With a strong focus on modernising policies and enhancing operational resilience, the FCA fosters a culture of innovation and collaboration, ensuring that employees are empowered to make meaningful contributions to the protection of UK consumers and financial markets. Additionally, the hybrid working model provides flexibility, allowing for a balanced work-life integration while being part of a vital regulatory body.

U

Contact Details:

UK Regulators' Network Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Policy Lead in Edinburgh

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including UK Regulators' Network, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through UK Regulators' Network

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at UK Regulators' Network. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cyber Policy Lead in Edinburgh

Cyber Policy Management
Standards Development
Policy Framework Maintenance
Gap Analysis
Horizon Scanning
Risk Appetite Articulation
Stakeholder Engagement

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at UK Regulators' Network insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to UK Regulators' Network that you’re committed to staying ahead in the game.

How to prepare for a job interview at UK Regulators' Network

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at UK Regulators' Network to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at UK Regulators' Network.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.