Data Security Assurance Lead

Financial Conduct Authority (FCA)

Greater London

Hybrid

GBP 61,000 - 101,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

25 days annual leave
Private healthcare
Pension

Job summary

Financial Conduct Authority (FCA) in the UK is seeking a senior leader to drive data security assurance across the organisation, aligning controls with NIST CSF and ISO 27001. You will shape governance, risk reporting and assurance across data estates, AI systems and cloud platforms.

The role focuses on leading the Data Security Assurance capability, implementing mature controls, risk-based prioritisation and embedding governance across technology, risk, and governance teams.

Qualifications

  • Experience leading data security and assurance capabilities within a complex organisation.
  • Demonstrable design, implementation and assurance of data security controls across SaaS, cloud and on-prem environments.
  • Strong understanding of data security principles, risks, data discovery and data protection.

Responsibilities

  • Lead the Data Security Assurance Framework ensuring confidentiality, integrity and availability of data.
  • Deliver risk-based data security assurance across data estate including M365 and cloud platforms.
  • Drive strategic evolution of data security posture management for AI capabilities.
  • Produce KPIs, KRIs, risk assessments and management information for senior leadership.
  • Lead and develop the Data Security Assurance capability across tech, risk, compliance and governance teams.

Skills

Data security
Microsoft Purview
Microsoft 365 security
Cloud security
Governance & assurance
Stakeholder management
Regulatory compliance
Risk management

Tools

AWS
Microsoft 365
Office 365
AI tools
Cloud platforms

Job description

Salary: £61,000 - 101,000 per year

Requirements
  • We require proven experience leading a data security, cyber security, information security or assurance capability within a complex organisation, including building, developing and maturing teams, operating models and security capabilities.
  • We require demonstrable experience designing, implementing and assuring data security controls and frameworks across SaaS, cloud and enterprise environments, aligned to recognised frameworks such as NIST CSF and ISO 27001.
  • We require a strong understanding of data security principles and risks, including data discovery, data lineage, encryption, logging, access control, identity management, data loss prevention and protection against data exposure and exfiltration.
  • We require experience delivering security assurance and risk assessments across applications, cloud platforms, data repositories, AI systems and broader technology environments, supported by continuous monitoring, control health reviews and risk reporting.
  • We require experience establishing governance, assurance and control oversight processes, including attestations, control validation, remediation tracking and risk-based prioritisation.
  • We require strong expertise in Microsoft Purview and Microsoft 365 security and compliance capabilities, including data discovery, classification, sensitivity labelling, DLP, Insider Risk Management, DSPM for AI and related E5 functionality.
  • We require knowledge of regulatory, legal and compliance requirements relevant to data security and experience translating these into practical controls, assurance activities and risk management outcomes.
  • We require excellent stakeholder management and influencing skills, with the ability to work effectively across technology, cyber security, data governance and business teams and to communicate complex security risks and control issues to senior leadership and executive stakeholders.
  • We require experience integrating security tooling, telemetry, APIs and automation to improve assurance, risk visibility and control effectiveness across Microsoft, AWS and interconnected technology platforms.
  • We require strong strategic and analytical capabilities, with experience developing data security roadmaps, identifying emerging risks and driving improvements that strengthen organisational security posture.
Responsibilities
  • We will lead our Data Security Assurance Framework, ensuring the confidentiality, integrity, authenticity, availability and appropriate use of corporate data, aligned to our Cyber Risk Management Framework, regulatory, legislative and internal control requirements.
  • We will establish and deliver risk-based data security assurance across our data estate, including M365 security and compliance, cloud platforms, data lakes, AI systems and data repositories, ensuring the identification, assessment and treatment of security and data risks.
  • We will drive the strategic evolution of our data security posture management for AI, assessing and assuring technical controls, data exposure and appropriate use across emerging AI capabilities such as MS Co-pilot, Agentic AI and AI-enabled platforms.
  • We will produce meaningful KPIs, KRIs, risk assessments and management information to support senior management decision-making, while leading issue identification, remediation tracking and validation of corrective actions.
  • We will lead and develop our Data Security Assurance capability, working across technology, cyber security, risk, compliance and data governance teams to embed effective controls throughout the data lifecycle and support consistent risk reporting, governance and oversight.
Technologies
  • Agentic AI
  • AI
  • AWS
  • Cloud
  • Support
  • Microsoft 365
  • Security
  • Office 365
More

We regulate financial services firms in the UK to keep financial markets fair, thriving and effective. By joining us, youll play a key part in protecting consumers, driving economic growth and shaping the future of UK finance services. Our Cyber and Information Resilience team is responsible for managing cyber security at the FCA, protecting our data and systems from malicious activity so we can deliver our key business functions. This role sits within our Cyber Assurance team, which leads FCA and PSR cyber assurance activities to confirm the right cyber assurance and control measures are in place. The role is based in London, Leeds or Edinburgh, with a full-time hybrid model where colleagues spend a minimum of 50% of their working time in the office each month. We offer 25 days annual leave plus bank holidays, a non-contributory pension, private healthcare, income protection, 35 hours of paid volunteering annually, and a flexible benefits scheme. We are committed to a diverse, inclusive and flexible working culture, and we welcome adjustments and working styles that help people do their best work.

last updated 36 week of 2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Security Assurance Lead
Data Security Assurance Lead

Financial Conduct Authority • City of Edinburgh

Hybrid
GBP 57,000 - 85,000
25 days annual leave
Pension 8–12%
Private healthcare
+3
Data Security Assurance Lead
Data Security Assurance Lead

Financial Conduct Authority • Leeds

Hybrid
GBP 57,000 - 77,000
25 days annual leave
Pension
Private healthcare
+3
Cybersecurity Consultant
Cybersecurity Consultant

Experis UK • Greater London

Hybrid
GBP 111,000 - 166,000
Senior Data Security Assurance Lead
Senior Data Security Assurance Lead

Financial Conduct Authority • Leeds

Hybrid
GBP 57,000 - 77,000
25 days annual leave
Pension
Private healthcare
+3
Data Security Assurance Lead, AI & Cloud Security
Data Security Assurance Lead, AI & Cloud Security

Financial Conduct Authority • City of Edinburgh

Hybrid
GBP 57,000 - 85,000
25 days annual leave
Pension 8–12%
Private healthcare
+3
Information Security – (Data & AI team)
Information Security – (Data & AI team)

Lorien • Greater London

Hybrid
Security Assurance Specialist
Security Assurance Specialist

G-Research • Greater London

On-site
GBP 90,000 - 130,000
Competitive compensation
Annual discretionary bonus
Lunch via Just Eat for Business
+6
Domain Expert - Responsible AI, Ethics & Assurance
Domain Expert - Responsible AI, Ethics & Assurance

Methods Consulting • Greater London

Hybrid
GBP 70,000 - 110,000
Private medical insurance
Pension salary exchange
Worldwide travel insurance
+1
Cyber Assurance Lead
Cyber Assurance Lead

Rullion • Greater London

Hybrid
GBP 120,000 - 157,000
Cyber Security Engineer
Cyber Security Engineer

IT Naturally • Peterborough

Hybrid
GBP 40,000 - 50,000
Private healthcare from day one
Company bonus
Pension
+4