Salary: £36,000 - 76,000 per year
Requirements:
- Strong experience in cyber security operations, incident response or security monitoring.
- Experience managing security service providers, SOC or MDR capabilities.
- Knowledge of cyber threats, attack techniques, threat intelligence and vulnerability management.
- Experience of security incident management and cyber crisis response.
- Experience of supplier cyber risk assessments and 3rd-party risk management.
- Understanding of ISO 27001, NIST CSF, FCA/PRA expectations and operational resilience requirements.
- Strong stakeholder management, communication and reporting skills.
- Minimum of one of the following: ISO27001 Lead Implementer or Lead Auditor.
- Desirable: CISSP, CISM, GIAC Incident Handler (GCIH), Certified Cyber Defender (CCD) or equivalent, ISO 27001 Lead Implementer or Lead Auditor, CRISC.
Responsibilities:
- Lead our cyber security operations capability, including oversight of security monitoring and detection services.
- Manage relationships with Managed Detection and Response (MDR), SOC and threat intelligence providers.
- Ensure security events are triaged, investigated, escalated and resolved in accordance with policy and procedure.
- Coordinate the operational response to cyber security incidents and support execution of our Cyber Incident Response Plan (CIRP).
- Maintain incident response playbooks, escalation procedures and operational runbooks.
- Produce reporting and management information on security events, incidents and emerging threats.
- Oversee vulnerability management processes across infrastructure, cloud services, applications and end-user devices.
- Ensure vulnerabilities are assessed, prioritised, tracked and remediated in line with risk appetite and policy requirements.
- Monitor threat intelligence sources and assess relevance to our technology landscape.
- Coordinate threat hunting activities and investigations arising from security alerts and intelligence feeds.
- Identify recurring security weaknesses and drive remediation actions.
- Lead our 3rd-Party Cyber Risk Management framework.
- Assess supplier cyber security risks throughout the supplier lifecycle, including onboarding, ongoing monitoring and offboarding activities.
- Review supplier security assessments, control attestations, certifications and due diligence submissions.
- Oversee the management of supplier vulnerabilities, cyber incidents, breaches and control deficiencies.
- Ensure material supplier cyber risks are escalated and tracked through appropriate governance forums.
- Support operational resilience and outsourcing requirements relating to 3rd-party cyber security.
- Develop and maintain operational cyber security procedures and standards.
- Support ISO 27001 certification, regulatory compliance activities and audit engagements.
- Contribute to cyber risk reporting, metrics and management information for senior management and governance committees.
- Drive continual improvement of cyber monitoring, incident management and 3rd-party risk management capabilities.
- Support implementation and optimisation of cyber security tooling, including ServiceNow Security Incident Response and 3rd-Party Risk Management capabilities.
Technologies:
- Cloud
- Incident Management
- Support
- Security
- ServiceNow
More:
Arbuthnot Latham has been associated with banking since 1833, combining private and commercial banking, wealth planning and investment management with a traditional relationship and service-led approach powered by modern technology. We seek proactive individuals who embrace high standards and bring energy to a dynamic environment that values innovative ideas, stability and support for personal and professional growth. Our human-scale ethos means everyone is recognised as an individual, and our service-led, relationship-driven culture values in-person collaboration and wellbeing. We offer one day a week working from home, along with competitive holiday allowance, pension via a market-leading provider, private healthcare cover, 4x life assurance, discretionary bonus and a suite of flexible benefits including Cycle to Work, Gym Scheme, Health Assessment, Season Ticket/Travel loans and dental insurance. The role is based in London.
last updated 37 week of 2026