Senior Cyber Risk and Assurance Lead in Glasgow
Senior Cyber Risk and Assurance Lead

Senior Cyber Risk and Assurance Lead in Glasgow

Glasgow Full-Time 55000 - 65000 £ / year (est.) No home office possible
University of Strathclyde

At a Glance

  • Tasks: Lead cyber risk management and assurance to strengthen the University’s cyber resilience.
  • Company: Join the University of Strathclyde's innovative Cybersecurity Team.
  • Benefits: Generous holiday package, pension contributions, on-the-job training, and family-friendly policies.
  • Other info: Opportunity for career growth in a dynamic and collaborative environment.
  • Why this job: Make a real impact on protecting systems and world-class research at a leading university.
  • Qualifications: Experienced in cybersecurity with strong analytical and communication skills.

The predicted salary is between 55000 - 65000 £ per year.

As part of the newly launched 3-year Cyber Improvement Programme, an exciting opportunity has arisen to join the Cybersecurity Team as a Senior Cyber Risk & Assurance Lead at the University of Strathclyde. This is a new role which is a permanent position offering the chance to play a pivotal role in strengthening the University's cyber resilience by leading the development of risk, governance, and assurance capabilities across a complex and devolved environment.

You will lead the University's approach to cyber risk management and assurance, ensuring risks are clearly understood, appropriately managed, and effectively communicated to senior stakeholders. You will be responsible for embedding a structured and consistent approach to risk and control assurance, aligned to recognised frameworks such as the NCSC Cyber Assessment Framework (CAF), CIS Controls and Cyber Essentials Plus.

Working closely with colleagues across Faculties and Professional Services, you will undertake assurance reviews, support compliance activities, and provide expert guidance on the design and effectiveness of security controls. You will also play a key part in strengthening supplier assurance, supporting audit readiness, and developing clear reporting that enables informed, risk-based decision-making at an institutional level.

This is a broad and varied role that demands both depth in cyber risk and a genuine understanding of the technology underpinning a modern university. You will be well-versed in vulnerability management and comfortable working with CVSS scoring, applying this knowledge to manage the University's outsourced penetration testing programme - from scoping and coordination through to tracking remediation and reporting outcomes.

Beyond testing, you will develop and lead tabletop exercises (TTX) and test scenarios for backup and recovery, using these activities to build cyber awareness, validate resilience assumptions, and hold departments accountable for managing their cyber risk effectively. You will translate findings into practical recommendations and ensure that risk ownership is clearly embedded across the institution.

You will also take a leading role in developing the University's supply chain assurance function, establishing the processes and frameworks needed to give the University full visibility of supplier risk, from onboarding assessments through to ongoing monitoring.

This role is suited to an experienced cybersecurity professional with a background in risk, governance, and assurance. You will be confident engaging with stakeholders at all levels, capable of providing constructive challenge, and able to translate complex technical risks into clear business impact.

You will have a sound understanding of enterprise technologies and IT infrastructure, enabling you to assess how controls operate in practice across areas such as servers, endpoints, identity, and cloud services including Microsoft 365, Defender, and Entra ID. This technical grounding will allow you to provide informed challenge, credible advice, and pragmatic recommendations to IT teams across the University.

We are looking for someone who combines strong analytical capability with excellent communication skills and a collaborative approach. You will be comfortable operating in a federated environment, working with diverse stakeholders to embed a culture of shared responsibility for cyber risk, while maintaining the independence and objectivity that effective assurance demands.

This is an excellent opportunity to contribute to a high-profile programme of work that is critical to protecting the University's systems, data, and research. You will help shape the University's cyber maturity journey and drive sustainable, long-term improvements in security posture.

If you are looking for a role where your expertise will make a tangible difference - protecting the people, systems, and world-class research that underpin one of Scotland's leading universities - we would be delighted to hear from you.

In return, you will receive 'on-the-job' training, a generous holiday package and be eligible to subscribe to a variety of schemes associated with being an employee of the University including: generous employer contributions to your pension; a world-class Sport Centre; family friendly policies; and various additional incentives including a Cycle Scheme. The University also has on-site childcare and parking for which you can apply.

All successful candidates must be willing to be located in the UK.

Please note the vacancy for this role does not meet the requirements for sponsorship under the Skilled Worker visa route. Candidates are welcome to apply if they have an alternative right to work for this role.

Senior Cyber Risk and Assurance Lead in Glasgow employer: University of Strathclyde

The University of Strathclyde is an exceptional employer, offering a unique opportunity to contribute to a vital Cyber Improvement Programme that enhances the institution's cyber resilience. With a strong commitment to employee development, generous benefits including a comprehensive pension scheme, and a supportive work culture that values collaboration and innovation, you will find a rewarding environment where your expertise can make a significant impact on safeguarding world-class research and systems. Located in the vibrant city of Glasgow, the University provides access to excellent facilities, including a world-class Sport Centre and on-site childcare, making it an attractive place for professionals seeking meaningful employment.
University of Strathclyde

Contact Detail:

University of Strathclyde Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Cyber Risk and Assurance Lead in Glasgow

✨Tip Number 1

Network like a pro! Reach out to current employees at the University of Strathclyde on LinkedIn. A friendly chat can give you insider info and maybe even a referral, which can really boost your chances.

✨Tip Number 2

Prepare for the interview by diving deep into the Cyber Improvement Programme. Understand its goals and how your skills align with their needs. This shows you're genuinely interested and ready to contribute.

✨Tip Number 3

Practice your storytelling! Be ready to share specific examples of how you've tackled cyber risk challenges in the past. This will help you demonstrate your expertise and make a lasting impression.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining the team.

We think you need these skills to ace Senior Cyber Risk and Assurance Lead in Glasgow

Cyber Risk Management
Governance Frameworks
Assurance Capabilities
NCSC Cyber Assessment Framework (CAF)
CIS Controls
Cyber Essentials Plus
Vulnerability Management
CVSS Scoring
Penetration Testing Coordination
Tabletop Exercises (TTX)
Supplier Assurance
Stakeholder Engagement
Enterprise Technologies
IT Infrastructure
Communication Skills

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in cyber risk management and assurance. We want to see how your skills align with the specific needs of the University of Strathclyde.

Showcase Your Technical Know-How: Don’t shy away from mentioning your familiarity with frameworks like NCSC Cyber Assessment Framework and CIS Controls. We’re looking for someone who can translate complex technical risks into clear business impacts, so let that shine through!

Engage with Stakeholders: Highlight any experience you have in engaging with diverse stakeholders. We value a collaborative approach, so share examples of how you've worked with different teams to embed a culture of shared responsibility for cyber risk.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets the attention it deserves, and we can’t wait to see what you bring to the table!

How to prepare for a job interview at University of Strathclyde

✨Know Your Cyber Risk Frameworks

Familiarise yourself with the NCSC Cyber Assessment Framework, CIS Controls, and Cyber Essentials Plus. Be ready to discuss how these frameworks can be applied in a university setting and how you would lead their implementation.

✨Showcase Your Stakeholder Engagement Skills

Prepare examples of how you've effectively communicated complex technical risks to non-technical stakeholders. Highlight your ability to provide constructive challenge and translate risks into business impacts.

✨Demonstrate Your Technical Knowledge

Brush up on your understanding of enterprise technologies and IT infrastructure. Be prepared to discuss how you would assess security controls across various platforms like Microsoft 365 and cloud services.

✨Prepare for Scenario-Based Questions

Expect questions that require you to think critically about cyber risk management. Prepare to discuss how you would conduct tabletop exercises and manage supplier assurance, showcasing your analytical and collaborative approach.

Senior Cyber Risk and Assurance Lead in Glasgow
University of Strathclyde
Location: Glasgow

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>