19h ago
New

Head of Department, Cyber & Information Resilience

3 Locationsexecutive
OtherHead
0 views0 saves0 applied

Quick Summary

Overview

The FCA has retained Odgers to advise on this appointment. For further information about the position and additional details on qualifications, requirements,

Technical Tools
OtherHead

The FCA has retained Odgers to advise on this appointment. For further information about the position and additional details on qualifications, requirements, terms and conditions of service and how to apply, please click here. 


About the FCA  

 

At the FCA, we’re creating a fair and more resilient financial system. We’re establishing more transparent relationships between financial services and customers, building trust in financial markets and protecting vulnerable consumers.  

  

We’re currently on an exciting journey as we drive forward significant organisational, people, process, and technology transformation to become a more forward-thinking, proactive regulator. We will use data more effectively to drive better regulatory decisions and build greater cohesion across our broad financial services remit.   

  

Significant improvements in digital enablement, business intelligence, market data and information management maturity are all being pursued to maintain our position as a world leader in financial services regulation.  

 

In March 2025, the FCA launched a new 5-year strategy to deepen trust, rebalance risk, support growth and improve lives. The FCA will focus on four priorities:  

  

  • Be a smarter regulator; predictable, purposeful and proportionate. The FCA will improve its processes and embrace technology to become more efficient and effective.  
  • Support sustained economic growth, by enabling investment, innovation and ensuring the continued competitiveness of the UK’s world-leading financial services.  
  • Help consumers navigate their financial lives by working with industry to boost trust, product innovation and ensuring the right information and support is available for people to take financial decisions.  
  • Fight financial crime, focusing on those who seek to use the fact they are regulated to do harm. It will go further to disrupt criminals and support firms to be an effective line of defence. 

 

  

The Role   

 

The Cyber and Information Resilience department is responsible for protecting the FCA’s systems, data, services and information assets, and for providing the organisation with the strategic cyber security, information resilience and assurance capability needed to operate within risk tolerance. This role is the single Head of Department for Cyber and Information Resilience and operates as the organisational CISO. It combines strategic oversight, departmental leadership and delivery of delegated SMF responsibilities from the COO, setting the organisation’s cyber strategy, owning departmental planning, risk and governance, and ensuring senior decision-makers receive clear, timely advice on cyber and information resilience matters. 

 

What will the candidate get from the role?  

 

  • Joining the Senior Leadership Team at the FCA during an exciting and challenging time of great change in financial services, technology and its regulation 
  • Leading a strategically important department responsible for cyber security, information resilience, assurance and operational cyber capability across the FCA 
  • Exposure to strategic cyber, technology risk, operational resilience and regulatory issues, working with senior stakeholders across DTI, enterprise governance, audit, risk and regulatory forums 

  

Key responsibilities:  

 

  • Set the strategic direction for Cyber and Information Resilience, ensuring priorities, operating model, controls and capability plans align to FCA risk appetite, enterprise priorities and regulatory expectations. 
  • Own departmental planning, including annual and in-year prioritisation, workforce and capability planning, budget and FTE considerations, delivery commitments, performance reporting and dependency management. 
  • Deliver delegated SMF responsibilities on behalf of the accountable senior executive, ensuring cyber and information resilience risks, controls, issues and decisions are visible, evidenced and escalated through appropriate governance. 
  • Senior engagement with Technology and Data, enterprise governance forums, audit, and risk is managed to provide clear judgment on material cyber risks, trade-offs, and control expectations. 
  • Provide the mandate, prioritisation and escalation support required for the Deputy CISO and C&IR management team to organise delivery across cyber defence, assurance, governance, security expertise and related teams. 
  • Ensure C&IR operates as an integrated department, connecting strategic cyber risk, operational insight, assurance findings, change demand, incident learning and external threat intelligence into a coherent plan of action. 

  

 

  Skills/Experience Required   

 

We’re proud to be a Disability Confident Employer, and therefore, people or individuals with disabilities and long-term conditions who best meet the minimum criteria for a role will go through to the next stage of the recruitment process. In cases of high application volumes we may progress applicants whose experience most closely matches the role’s key requirements. (To learn more about the Disability Confident Scheme Click Here) 

 

 

Minimum   

  • Significant experience leading cyber security, information resilience, technology risk or comparable enterprise risk functions in a complex organisation, with ability to lean in and drive team performance across all areas (including detection & response, Assurance, SSDLC, policy and AI Security). 
  • Demonstrated experience translating cyber and information resilience risk into senior-level decisions, priorities, control expectations and accountable delivery plans. 
  • Experience owning or contributing to departmental planning, workforce planning, budget prioritisation, governance reporting and management of cross-cutting dependencies. 
  • Experience operating with delegated senior management accountabilities, including evidencing decisions, escalating material risks and maintaining effective governance disciplines. 
  • Experience leading through senior managers, deputies or management teams, with the ability to set mandate and direction while enabling operational leaders to manage delivery. 

  

Essential   

  • Strong strategic judgement, with the ability to identify material cyber and information resilience risks, make proportionate trade-offs and advise senior stakeholders clearly. 
  • Ability to lead departmental planning and prioritisation across multiple teams, balancing operational resilience, assurance, change demand, regulatory expectations and resource constraints. 
  • Strong understanding of cyber security risk management, security governance, control frameworks, assurance, incident response, vulnerability management and technology change. 
  • Highly effective communication and relationship management skills, along with the confidence to speak for Cyber & Information Resilience in enterprise governance and senior decision-making settings. 
  • Ability to provide clear mandate, escalation support and constructive challenge to a Deputy CISO and management team without duplicating day-to-day team management. 
  • All candidates should be capable of obtaining and maintaining UK national security vetting at DV level. 
  • Experience shaping cyber operating models, security portfolios, strategic workforce plans, governance forums or cross-organisation control improvement programmes. 
  • Understanding of emerging cyber risks, including AI-enabled threats, enterprise use of AI, cloud security, privileged access risk, operational resilience and third-party technology risk. 

  

Desirable  

  • Experience operating as, or closely supporting, a CISO, HoD Cyber or equivalent senior cyber leadership role in a regulated environment. 
  • Relevant professional qualification or equivalent experience (such as CISM) or comparable senior cyber credentials or experience.  

 

 

The FCA’s Values & Diversity   

 

Our ambition is to create a diverse and inclusive workplace that reflects the society we serve, helping us to be a better regulator. We serve the public and our decisions directly affect the wellbeing of people, businesses and the UK economy.  So, our values matter. They represent the culture we aspire to every day, guiding our judgements, building trust and helping us to be ‘At our best’. 

 

The FCA is committed to achieving greater diversity across all levels of our organisation. Given this, we particularly welcome applications from women, disabled, and minority ethnic candidates, as under-represented groups. 

 

As an inclusive employer, we are open to considering flexible working arrangements, including job shares. Please inform your recruiter if you wish to apply for this role on a flexible basis. 

 

As part of the FCA’s on-going commitment to develop our national presence, most of our vacancies are now open to working in our Edinburgh, Leeds or London offices. This means that as part of the application process you will be able to select your preference of which office location you would like to work from. 

 

 

Application Support 

 

We want to remove any possible barriers and are committed to providing a wide range of reasonable adjustments so that you can keep the focus on your conversations and be at your best.  

 

If you have an accessibility requirement, disability, or condition that means you might require changes to the recruitment process, please contact your recruiter to discuss this further. Our aim is to make you application as easy as possible, and your recruiter will be happy to work with you to make any necessary arrangements where possible. 

 

Benefits 

 

Our competitive benefits scheme gives you the opportunity to create a personalised benefits package, tailored to suit your lifecycle. You can this this allowance to purchase additional benefits such as dental or cycle to work, or you have the option to top up your base salary by taking this as cash. 

 

Core benefits that you will receive as standard are: 

  • 30 days holiday per year plus bank holidays  
  • Private healthcare with Bupa 
  • A non-contributory Pension of at least 8% of basic salary each month (there are several contribution levels that increase depending on your age- up to 12% a month once you reach age 35) 
  • Life assurance of eight times your basic salary 
  • Income protection 

 

 

Conflicts of interest  

 

All applicants to the FCA are required to demonstrate that they do not have other interests likely to conflict with their responsibilities as an employee of the FCA. You should declare any potential conflict of interest as early as possible in the selection process, and also disclose information or personal connections that, if appointed, might be open to misperception.   

 

Any potential conflicts of interest will not prevent candidates going forward to interview but may, if appropriate, be explored during the interview to establish how the candidate would address the issue(s) should they be successful in their application.   

 

 

Useful information  

 

  • The closing date for this role is 23:55 on 25th October 2026. 
  • Selection will be via a two-stage interview and psychometric assessment .  
  • If successful, you will be required to obtain and retain DV Clearance.   
  • Colleagues spend a minimum of 50% of their working time in the office each month (60% for Directors and Executive Directors) across our London, Leeds and Edinburgh offices. 
  • The salary range for the role is £140k to £190k (London); £126k-£171k (National).  

 

 

The FCA has retained Odgers to advise on this appointment. For further information about the position and additional details on qualifications, requirements, terms and conditions of service and how to apply, please click here. 

Location & Eligibility

Where is the job
—
Location terms not specified
Who can apply
Same as job location

Listing Details

Posted
October 7, 2026
First seen
October 7, 2026
Last seen
October 7, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
55%
Scored at
October 7, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Head of Department, Cyber & Information Resilience