Senior Cyber Risk and Assurance Lead
Senior Cyber Risk and Assurance Lead

Senior Cyber Risk and Assurance Lead

Full-Time 55000 - 65000 £ / year (est.) No home office possible
University of Strathclyde

At a Glance

  • Tasks: Lead cyber risk management and assurance to strengthen the University's cyber resilience.
  • Company: Join the University of Strathclyde's innovative Cybersecurity Team.
  • Benefits: Generous holiday package, pension contributions, on-the-job training, and family-friendly policies.
  • Other info: Opportunity for career growth in a dynamic and collaborative environment.
  • Why this job: Make a tangible impact on protecting systems and world-class research at a leading university.
  • Qualifications: Experienced in cybersecurity with strong analytical and communication skills.

The predicted salary is between 55000 - 65000 £ per year.

As part of the newly launched 3-year Cyber Improvement Programme, an exciting opportunity has arisen to join the Cybersecurity Team as a Senior Cyber Risk & Assurance Lead at the University of Strathclyde. This is a new role which is a permanent position offering the chance to play a pivotal role in strengthening the University's cyber resilience by leading the development of risk, governance, and assurance capabilities across a complex and devolved environment.

The Role

  • You will lead the University's approach to cyber risk management and assurance, ensuring risks are clearly understood, appropriately managed, and effectively communicated to senior stakeholders.
  • You will be responsible for embedding a structured and consistent approach to risk and control assurance, aligned to recognised frameworks such as the NCSC Cyber Assessment Framework (CAF), CIS Controls and Cyber Essentials Plus.
  • Working closely with colleagues across Faculties and Professional Services, you will undertake assurance reviews, support compliance activities, and provide expert guidance on the design and effectiveness of security controls.
  • You will also play a key part in strengthening supplier assurance, supporting audit readiness, and developing clear reporting that enables informed, risk-based decision-making at an institutional level.
  • This is a broad and varied role that demands both depth in cyber risk and a genuine understanding of the technology underpinning a modern university.
  • You will be well-versed in vulnerability management and comfortable working with CVSS scoring, applying this knowledge to manage the University's outsourced penetration testing programme - from scoping and coordination through to tracking remediation and reporting outcomes.
  • Beyond testing, you will develop and lead tabletop exercises (TTX) and test scenarios for backup and recovery, using these activities to build cyber awareness, validate resilience assumptions, and hold departments accountable for managing their cyber risk effectively.
  • You will translate findings into practical recommendations and ensure that risk ownership is clearly embedded across the institution.
  • You will also take a leading role in developing the University's supply chain assurance function, establishing the processes and frameworks needed to give the University full visibility of supplier risk, from onboarding assessments through to ongoing monitoring.

About You

  • This role is suited to an experienced cybersecurity professional with a background in risk, governance, and assurance.
  • You will be confident engaging with stakeholders at all levels, capable of providing constructive challenge, and able to translate complex technical risks into clear business impact.
  • You will have a sound understanding of enterprise technologies and IT infrastructure, enabling you to assess how controls operate in practice across areas such as servers, endpoints, identity, and cloud services including Microsoft 365, Defender, and Entra ID.
  • This technical grounding will allow you to provide informed challenge, credible advice, and pragmatic recommendations to IT teams across the University.
  • We are looking for someone who combines strong analytical capability with excellent communication skills and a collaborative approach.
  • You will be comfortable operating in a federated environment, working with diverse stakeholders to embed a culture of shared responsibility for cyber risk, while maintaining the independence and objectivity that effective assurance demands.

Why Join Us

This is an excellent opportunity to contribute to a high-profile programme of work that is critical to protecting the University's systems, data, and research. You will help shape the University's cyber maturity journey and drive sustainable, long-term improvements in security posture. If you are looking for a role where your expertise will make a tangible difference - protecting the people, systems, and world-class research that underpin one of Scotland's leading universities - we would be delighted to hear from you.

In return, you will receive ‘on-the-job’ training, a generous holiday package and be eligible to subscribe to a variety of schemes associated with being an employee of the University including: generous employer contributions to your pension; a world-class Sport Centre; family friendly policies; and various additional incentives including a Cycle Scheme. The University also has on-site childcare and parking for which you can apply.

All successful candidates must be willing to be located in the UK.

Sponsorship and Skilled Worker Visa

Please note the vacancy for this role does not meet the requirements for sponsorship under the Skilled Worker visa route. Candidates are welcome to apply if they have an alternative right to work for this role.

Senior Cyber Risk and Assurance Lead employer: University of Strathclyde

The University of Strathclyde is an exceptional employer, offering a permanent position as a Senior Cyber Risk and Assurance Lead within a dynamic Cybersecurity Team. With a commitment to employee growth through on-the-job training, generous holiday packages, and family-friendly policies, the University fosters a collaborative work culture that values innovation and shared responsibility for cyber risk. Located in one of Scotland's leading universities, this role provides a unique opportunity to make a significant impact on the institution's cyber resilience while enjoying access to world-class facilities and support.
University of Strathclyde

Contact Detail:

University of Strathclyde Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Cyber Risk and Assurance Lead

✨Tip Number 1

Network like a pro! Reach out to current employees at the University of Strathclyde on LinkedIn. A friendly chat can give us insights into the team culture and what they really value in candidates.

✨Tip Number 2

Prepare for the interview by brushing up on your knowledge of the NCSC Cyber Assessment Framework and CIS Controls. We want to show that we’re not just familiar with these frameworks, but that we can apply them in real-world scenarios.

✨Tip Number 3

Practice articulating your past experiences in risk management and assurance. We need to be ready to explain how our previous roles have prepared us for this position, especially when it comes to stakeholder engagement and translating technical risks.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure our application gets noticed. Plus, we can tailor our submission to highlight how we align with the University’s goals and values.

We think you need these skills to ace Senior Cyber Risk and Assurance Lead

Cyber Risk Management
Governance and Assurance
NCSC Cyber Assessment Framework (CAF)
CIS Controls
Cyber Essentials Plus
Vulnerability Management
CVSS Scoring
Penetration Testing Coordination
Tabletop Exercises (TTX)
Backup and Recovery Testing
Stakeholder Engagement
Enterprise Technologies Understanding
IT Infrastructure Knowledge
Microsoft 365
Communication Skills

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in cyber risk management and assurance. We want to see how your skills align with the specific needs of the University, so don’t hold back on showcasing your relevant achievements!

Showcase Your Technical Know-How: Since this role requires a solid understanding of enterprise technologies, be sure to mention your familiarity with frameworks like NCSC Cyber Assessment Framework and tools like Microsoft 365. We love seeing candidates who can bridge the gap between technical details and business impact.

Communicate Clearly: Your ability to translate complex risks into clear, actionable insights is key. Use straightforward language in your application to demonstrate your communication skills. Remember, we’re looking for someone who can engage with stakeholders at all levels!

Apply Through Our Website: Don’t forget to submit your application through our official website! It’s the best way to ensure your application gets the attention it deserves. Plus, you’ll find all the details you need about the role and our team there.

How to prepare for a job interview at University of Strathclyde

✨Know Your Cyber Risk Frameworks

Familiarise yourself with the NCSC Cyber Assessment Framework, CIS Controls, and Cyber Essentials Plus. Be ready to discuss how these frameworks can be applied in a university setting and how you would lead their implementation.

✨Showcase Your Stakeholder Engagement Skills

Prepare examples of how you've effectively communicated complex technical risks to non-technical stakeholders. Highlight your ability to provide constructive challenge and translate risks into business impacts.

✨Demonstrate Technical Proficiency

Brush up on your knowledge of enterprise technologies and IT infrastructure, especially around servers, endpoints, and cloud services like Microsoft 365. Be prepared to discuss how you would assess and improve security controls in these areas.

✨Prepare for Scenario-Based Questions

Expect questions that require you to think critically about risk management scenarios. Practice articulating your thought process on how to handle vulnerabilities, manage outsourced penetration testing, and develop effective tabletop exercises.

Senior Cyber Risk and Assurance Lead
University of Strathclyde

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>