Senior Technical Specialist, Cyber Resilience Team
Listed on 2026-06-12
-
IT/Tech
Cybersecurity, IT Project Manager, Information Security, IT Consultant
The Bank of England is the UK's central bank. Our mission is to deliver monetary and financial stability for the British people, and the Bank is a diverse organisation with more than 4,000 people committed to public service.
Supervisory Risk Specialists (SRS) is a directorate within the Prudential Regulation Authority (PRA) that provides deep technical expertise and applies expert judgement across risk disciplines to support the PRA’s coordinated supervisory approach.
The Sector Resilience Division (SRD) leads the PRA's work on the resilience of the financial sector to a range of non‑financial risks, including cyber. Its priorities include assessing systemic importance of firms, evaluating cyber resilience, developing supervisory and assurance tools, and strengthening the UK’s financial system resilience.
London based.
Senior Technical Specialist – Cyber Resilience TeamThe role will play a key part in shaping the PRA’s cyber risk and resilience strategy within the context of Operational Resilience (OR). It includes ownership and evolution of the supervisory cyber approach, associated toolkits (CBEST, STAR‑FS, CQUEST), and the engagement required to deliver the PRA’s cyber agenda.
The role is well suited for an individual with a strong cyber risk and security background, ideally with prior experience in a regulatory or supervisory environment and a good understanding of the PRA’s Operational Resilience framework.
Key Responsibilities- Taking a leading role in developing and advising on policy and supervisory recommendations aligned with Operational Resilience objectives.
- Leading the development of the PRA's supervisory cyber approach, including evaluation and assessment methodologies for cyber risk and resilience, working closely with Policy, Supervision and specialist teams.
- Leading the implementation, ongoing review and continuous improvement of the PRA's supervisory cyber toolkit, including CBEST, STAR‑FS and CQUEST.
- Defining and articulating what good cyber practices look like in the context of broader Operational Resilience expectations.
- Providing deep analytical and technical expertise, ensuring relevant industry standards and good practices are embedded in cyber resilience assessments.
- Leading meetings with regulated firms to assess cyber risk and resilience capabilities, providing effective challenge to firms' approaches and remediation plans.
- Developing and maintaining strong working relationships across the Bank and with external stakeholders, including the FCA, HMT, NCSC, CPNI and other domestic and international bodies.
- Drafting high‑quality papers and briefings, and contributing actively to horizon scanning and Risk Committee discussions.
- Significant experience leading independently regulatory cyber reviews, including threat‑led penetration‑testing assessments (CBEST, STAR‑FS) and other technical reviews across Cyber Resilience or related disciplines.
- Significant experience leading independently strategic cyber resilience and proven experience to engage with senior stakeholders while delivering projects.
- Strong knowledge of the PRA’s approach to supervising cyber risk and resilience, including its application within the Operational Resilience framework.
- Strong understanding of the evolving cyber security regulatory landscape and the key Operational Resilience challenges facing UK financial sector firms and authorities.
- Strong understanding of the evolving cyber security landscape including risks associated with emerging technologies such as Artificial Intelligence and post‑quantum computing.
- Ability to synthesise complex technical cyber and resilience information and translate it into clear, well‑reasoned conclusions and actionable recommendations for senior stakeholders.
- Ability to represent the organisation’s position on key cyber and operational resilience matters internally and externally, including leading meetings, influencing senior audiences, and adapting communication style to context and audience.
- Strong understanding of recognised cyber resilience standards and frameworks (UK NCSC CAF, NIST, ISO/IEC 27001, ISO 22301) and cyber‑related regulatory and supervisory expectations (PRA…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: