Data Security Assurance Lead

Financial Conduct Authority

Leeds

On-site

GBP 57,000 - 85,000

Full time

17 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

25 days annual leave plus bank holiays
Non-contributory pension (8–12%) and 8
Private healthcare with Bupa and life/
35 hours of paid volunteering annually
Hybrid model with 50% office time
Flexible benefits scheme

Job summary

Financial Conduct Authority is seeking a Data Security Assurance Lead within the Cyber and Information Resilience team in the Operations division. The role focuses on leading the Data Security Assurance Framework and embedding security controls across the FCA's data estate, including AI systems and cloud platforms.

You will produce risk-based assurance outputs, develop governance processes, and partner with technology, risk, and data governance teams to strengthen the FCA's security posture.

Qualifications

  • Experience leading data security/cyber/assurance teams in a complex org.
  • Designing and assuring data security controls across SaaS, cloud and on-prem.
  • Strong understanding of data security principles including data discovery, encryption, DLP.
  • Experience delivering security assurance and risk assessments across applications, cloud, data repositories and AI.
  • Establish governance, assurance and control oversight processes with attestations and remediation tracking.
  • Expertise in Microsoft Purview and Microsoft 365 security and compliance.
  • Knowledge of regulatory/compliance requirements translated into controls.
  • Strong stakeholder management and ability to communicate risks to leadership.
  • Experience integrating security tooling, telemetry, APIs across platforms.
  • Strategic and analytical capabilities to develop data security roadmaps.

Responsibilities

  • Lead the FCA's Data Security Assurance Framework, ensuring confidentiality and proper data use.
  • Establish risk-based data security assurance across the data estate including cloud and AI.
  • Drive strategic evolution of data security posture for AI and AI-enabled platforms.
  • Produce KPIs, KRIs and risk reports to support senior management decisions.
  • Lead and develop the Data Security Assurance capability across teams.

Skills

Data security leadership
Data security controls
Data security fundamentals
Security assurance & risk assessments
Governance & control oversight
Stakeholder management
Security tooling integration
Strategic analytics

Tools

Microsoft Purview
Microsoft 365 security

Job description

Division: Operations
  • Salary: National (Edinburgh and Leeds) ranging from £57,000 to £77,000 and London from £63,000 to £85,000. (Salary offered will be based on skills and experience)
  • This role is graded as: Lead Associate, Regulatory
  • Your external recruitment contact is Raimonda via raimonda.stankute@fca.org.uk
  • Your internal recruitment contact is Fizah via fizahfarouk.ibrahim@fca.org.uk
Data Security Assurance Lead
Division: Operations
Department: Cyber and Information Resilience
  • Salary: National (Edinburgh and Leeds) ranging from £57,000 to £77,000 and London from £63,000 to £85,000. (Salary offered will be based on skills and experience)
  • This role is graded as: Lead Associate, Regulatory
  • Your external recruitment contact is Raimonda via raimonda.stankute@fca.org.uk
  • Your internal recruitment contact is Fizah via fizahfarouk.ibrahim@fca.org.uk
About The FCA And Team

We regulate financial services firms in the UK, to keep financial markets fair, thriving and effective. By joining us, you’ll play a key part in protecting consumers, driving economic growth and shaping the future of UK finance services.

Cyber and Information Resilience (C&IR) is responsible for the management of cyber security at the FCA. 'Cyber security' means the protection of the FCA's data and systems from malicious activity, including theft, damage and disruption, in order that the FCA can deliver its key business functions. C&IR is now part of a new formed Directorate lead by our CISO, Director of Cyber & Operational Resilience Division.

The role is based in the Cyber Assurance team, who leads on the FCA & PSR cyber assurance activities working to determine that correct cyber assurance and control measures are in place.

The team conducts thorough reviews, analysis and testing to confirm the appropriate security and data controls (whether through technology, process, or behaviour) and the secure operation of the FCA systems and data are in place

Role Responsibilities
  • Lead the FCA's Data Security Assurance Framework, ensuring the confidentiality, integrity, authenticity, availability and appropriate use of corporate data, aligned to the FCA's Cyber Risk Management Framework, regulatory, legislative and internal control requirements
  • Establish and deliver risk-based data security assurance across the FCA's data estate, including M365 security and compliance, cloud platforms, data lakes, AI systems and data repositories, ensuring the identification, assessment and treatment of security and data risks in line with the FCA's Cyber Risk Management Framework and associated tooling
  • Drive the strategic evolution of the FCAs data security posture management for AI, assessing and assuring technical controls, data exposure and appropriate use across emerging AI capabilities such as MS Co-pilot, Agentic AI and AI-enabled platforms, ensuring security by design, effective data security governance and continuous assurance as the FCAs AI estate evolves
  • Produce meaningful KPIs, KRIs, risk assessments and management information to support senior management decision-making, alignment with the FCA's Cyber Risk Management Framework and effective second-line Risk and Compliance oversight, while leading issue identification, remediation tracking and validation of corrective actions
  • Lead and develop the FCA's Data Security Assurance capability, working across technology, cyber security, risk, compliance and data governance teams to embed effective controls throughout the data lifecycle, integrate assurance into the wider cyber risk management ecosystem and support consistent risk reporting, governance and oversight.
Minimum
Skills required
  • Proven experience leading a data security, cyber security, information security or assurance capability within a complex organisation, including building, developing and maturing teams, operating models and security capabilities
  • Demonstrable experience designing, implementing and assuring data security controls and frameworks across SaaS, cloud and enterprise environments, aligned to recognised frameworks such as NIST CSF and ISO 27001
  • Strong understanding of data security principles and risks, including data discovery, data lineage, encryption, logging, access control, identity management, data loss prevention and protection against data exposure and exfiltration
Essential
  • Experience delivering security assurance and risk assessments across applications, cloud platforms, data repositories, AI systems and broader technology environments, supported by continuous monitoring, control health reviews and risk reporting
  • Experience establishing governance, assurance and control oversight processes, including attestations, control validation, remediation tracking and risk-based prioritisation
  • Strong expertise in Microsoft Purview and Microsoft 365 security and compliance capabilities, including data discovery, classification, sensitivity labelling, DLP, Insider Risk Management, DSPM for AI and related E5 functionality
  • Knowledge of regulatory, legal and compliance requirements relevant to data security and experience translating these into practical controls, assurance activities and risk management outcomes
  • Excellent stakeholder management and influencing skills, with the ability to work effectively across technology, cyber security, data governance and business teams and to communicate complex security risks and control issues to senior leadership and executive stakeholders
  • Experience integrating security tooling, telemetry, APIs and automation to improve assurance, risk visibility and control effectiveness across Microsoft, AWS and interconnected technology platforms
  • Strong strategic and analytical capabilities, with experience developing data security roadmaps, identifying emerging risks and driving improvements that strengthen organisational security posture
Benefits
  • 25 days annual leave plus bank holidays
  • Non-contributory pension (8–12% depending on age) and life assurance at eight times your salary
  • Private healthcare with Bupa, income protection and 24/7 Employee Assistance
  • 35 hours of paid volunteering annually
  • Hybrid model where colleagues spend a minimum of 50% of their working time in the office each month (60% for Directors and Executive Directors) across our London, Leeds and Edinburgh offices
  • A flexible benefits scheme designed around your lifestyle

For a full list of our benefits and our recruitment process as a whole visit our benefits page.

Our values and culture

Our colleagues are the key to our success as a regulator. We are committed to fostering a diverse and inclusive culture: one that’s free from discrimination and bias, celebrates difference and supports colleagues to deliver at their best. We believe that our differences and similarities enable us to be a better organisation – one that makes better decisions, drives innovation and delivers better regulation.

If you require any adjustments due to a disability or condition, your recruiter is here to help - reach out for tailored support.

We welcome diverse working styles and aim to find flexible solutions that suit both the role and individual needs, including options like part‑time and job sharing where applicable.

Disability confident: our hiring approach

We’re proud to be a Disability Confident Employer and therefore, people or individuals with disabilities and long-term conditions who best meet the minimum criteria for a role will go through to the next stage of the recruitment process. In cases of high application volumes we may progress applicants whose experience most closely matches the role’s key requirements.

Useful information and timelines
Timeline
  • Job advert closes: Midnight, 8 September 2026
  • CV Review/Shortlist: 10 September 2026
  • Interview: w/c 21 September 2026

Your Recruiter will discuss the process in detail with you during screening for the role, therefore, please make them aware if you are going to be unavailable for any date during this time.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Integrated Planning Data and Technology Lead
Integrated Planning Data and Technology Lead

Financial Conduct Authority • Greater London

Hybrid
GBP 50,000 - 68,000
25 days annual leave
Non-contributory pension (8–12%)
Private healthcare with Bupa, income保护
+3
Integrated Planning Data and Technology Lead
Integrated Planning Data and Technology Lead

Financial Conduct Authority • Leeds

On-site
GBP 50,000 - 68,000
25 days annual leave
Non-contributory pension
Private healthcare
+3
Integrated Planning Data and Technology Lead
Integrated Planning Data and Technology Lead

Financial Conduct Authority • City of Edinburgh

On-site
GBP 50,000 - 68,000
Annual leave 25 days
Pension 8–12%
Private healthcare
+3
Lead AI Engineer
Lead AI Engineer

Financial Conduct Authority • Leeds

On-site
GBP 72,000 - 108,000
28 days annual leave
Private healthcare
Pension plan
Lead AI Engineer
Lead AI Engineer

Financial Conduct Authority • City of Edinburgh

On-site
GBP 72,000 - 120,000
28 days annual leave
Private healthcare
Pension (8–12%)
+3
Data Specialist
Data Specialist

FCA International • Leeds

Hybrid
GBP 72,000 - 103,000
28 days holiday
Hybrid working (up to 60%)
Private healthcare
+4
Financial Resilience Risk - Technical Specialist
Financial Resilience Risk - Technical Specialist

Financial Conduct Authority • Greater London

On-site
GBP 80,000 - 120,000
28 days annual leave plus bank holiday
Non-contributory pension
Private healthcare with Bupa
+2
Fund Data and Analytics Associate
Fund Data and Analytics Associate

Financial Conduct Authority • Leeds

On-site
GBP 43,000 - 57,000
25 days annual leave
Non-contributory pension (8–12%) and 8
Private healthcare with Bupa
+3
AI Analyst
AI Analyst

Financial Conduct Authority • City of Edinburgh

On-site
GBP 54,000 - 80,000
25 days annual leave
Office presence in multiple cities
Non-contributory pension 8–12%
+3
Fund Data and Analytics Associate
Fund Data and Analytics Associate

Financial Conduct Authority • City of Edinburgh

On-site
GBP 43,000 - 63,000
25 days annual leave
Non-contributory pension (8–12%)
Private healthcare with Bupa
+3