Data Security Assurance Lead
Job in
Midlothian, Midlothian county, EH22 1FA, Scotland, UK
Listed on 2026-09-03
Listing for:
Financial Conduct Authority (FCA)
Full Time
position Listed on 2026-09-03
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Operations Department:
Cyber and Information Resilience Salary:
National (Edinburgh and Leeds) ranging from 57,000 to 77,000 and London from 63,000 to 85,000. (Salary offered will be based on skills and experience)
This role is graded as:
Lead Associate, Regulatory Your external recruitment contact is Raimonda via raimonda.stankute.ukYour internal recruitment contact is Fizah via fizahfarouk.ibrahim.uk Applications must be submitted through our online portal. Applications sent via social media or email will not be accepted.
About the FCA and team We regulate financial services firms in the UK, to keep financial markets fair, thriving and effective. By joining us, you’ll play a key part in protecting consumers, driving economic growth and shaping the future of UK finance services. Cyber and Information Resilience (C&IR) is responsible for the management of cyber security at the FCA. 'Cyber security' means the protection of the FCA's data and systems from malicious activity, including theft, damage and disruption, in order that the FCA can deliver its key business functions.
C&IR is now part of a new formed Directorate lead by our CISO, Director of Cyber & Operational Resilience Division.The role is based in the Cyber Assurance team, who leads on the FCA & PSR cyber assurance activities working to determine that correct cyber assurance and control measures are in place.
The team conducts thorough reviews, analysis and testing to confirm the appropriate security and data controls (whether through technology, process, or behaviour) and the secure operation of the FCA systems and data are in place
Role responsibilities
Lead the FCA's Data Security Assurance Framework, ensuring the confidentiality, integrity, authenticity, availability and appropriate use of corporate data, aligned to the FCA's Cyber Risk Management Framework, regulatory, legislative and internal control requirements
Establish and deliver risk-based data security assurance across the FCA's data estate, including M365 security and compliance, cloud platforms, data lakes, AI systems and data repositories, ensuring the identification, assessment and treatment of security and data risks in line with the FCA's Cyber Risk Management Framework and associated tooling
Drive the strategic evolution of the FCAs data security posture management for AI, assessing and assuring technical controls, data exposure and appropriate use across emerging AI capabilities such as MS Co-pilot, Agentic AI and AI-enabled platforms, ensuring security by design, effective data security governance and continuous assurance as the FCAs AI estate evolves
Produce meaningful KPIs, KRIs, risk assessments and management information to support senior management decision-making, alignment with the FCA's Cyber Risk Management Framework and effective second-line Risk and Compliance oversight, while leading issue identification, remediation tracking and validation of corrective actions
Lead and develop the FCA's Data Security Assurance capability, working across technology, cyber security, risk, compliance and data governance teams to embed effective controls throughout the data lifecycle, integrate assurance into the wider cyber risk management ecosystem and support consistent risk reporting, governance and oversight.
Skills required
Minimum:
Proven experience leading a data security, cyber security, information security or assurance capability within a complex organisation, including building, developing and maturing teams, operating models and security capabilities
Demonstrable experience designing, implementing and assuring data security controls and frameworks across SaaS, cloud and enterprise environments, aligned to recognised frameworks such as NIST CSF and ISO 27001
Strong understanding of data security principles and risks, including data discovery, data lineage, encryption, logging, access control, identity management, data loss prevention and protection against data exposure and exfiltration
Essential:
Experience delivering security assurance and risk assessments across applications, cloud platforms, data repositories, AI…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×