Cyber Risk and Compliance Lead

7 months ago


Manchester, United Kingdom SCOTTISH FUNDING COUNCIL Full time

**Cyber Risk & Compliance Lead**
**12 Month FTC**
**Edinburgh/Hybrid**:

- **£61,626 - £72,684**_

Everything we do at the Scottish Funding Council (SFC) aims to create the right environment for colleges and universities to thrive.

The Scottish Funding Council is Scotland’s tertiary education and research authority. Our ambition is to make Scotland an outstanding place to learn, educate, research, and innovate - now and for the future. So, naturally, we have a clear focus on recruiting the best people and developing them throughout their career. We invest around £2 billion every year, and our funding enables colleges and universities to provide life-changing opportunities for over half a million people. 

We’re not only looking for the best people to come and work for us, but also people who will connect with our guiding principles which include working in partnership, championing diversity, and supporting sustainability for future generations.

By fostering our guiding principles, we are very proud of the inclusive working environment that we have created. We are committed to attracting people of all backgrounds: we want our colleague base to reflect the people and communities that we serve.

**Job Summary**

As the Cyber Risk & Compliance Lead at the Scottish Funding Council, you will champion our cybersecurity initiatives, ensuring the protection of our operations, data and technologies in alignment with UK-specific cybersecurity standards and frameworks. This role is critical in maintaining the SFC’s reputation for excellence and integrity in the funding of education and research across Scotland.

**Key Responsibilities**
- Develop and implement a cyber risk management framework tailored to the specific needs and challenges of the SFC, focusing on the protection of financial data, personal information of students and staff, and sensitive research data.
- Ensure full compliance with Scottish and UK data protection laws, as well as adherence to specific regulations relevant to our organisation and our internal and external audit obligations.
- Collaborate closely with academic institutions, research bodies, and government agencies to align cyber security practices and foster a culture of shared responsibility and leading practices in data protection and risk management.
- Lead the review and enhancement of policies, procedures, and controls governing data security, risk assessment, and compliance within the funding council’s operations.
- Conduct targeted cyber risk assessments and compliance audits, providing strategic insights and recommendations to the SFC’s senior management and governing board.
- Act as a principal advisor on cyber security matters, offering expert guidance to support the council’s strategic initiatives in funding education and research.
- Stay abreast of emerging cyber threats and advancements in cyber security technologies and practices, ensuring the SFC remains proactive and responsive in its cyber risk and compliance strategies.

**Person specification**

**It is important through your CV / Cover Letter that you give evidence of proven experience of each of the following essential criteria**:
**Essential Requirements**:

- Proven track record in cybersecurity risk management, with a strong understanding of the UK cybersecurity landscape, including Cyber Essentials, ISO 27001 frameworks.
- Familiarity with the NCSC’s guidelines and recommendations for public sector organisations.
- Experience in managing cybersecurity compliance projects within the UK, including the attainment of Cyber Essentials certification.
- Leadership experience with the ability to mentor a team and drive cybersecurity awareness across an organisation.
- Excellent communication and influencing skills, capable of engaging effectively with a range of stakeholders on complex cybersecurity issues to ensure change is adopted and sustained.

**Professional Certifications**:

- Holding or working towards UK-recognized cybersecurity certifications, such as those offered by CREST or Cyber Essentials Plus, is highly desirable.
- Additional certifications such as CISSP, CISM, or ISO 27001 Lead Auditor/Implementer would be beneficial.

**Additional information**

**Location**
SFC offers hybrid working for its employees. This means that whilst the role is based at our Edinburgh office, there is substantial opportunity to work from home most of the time. As a rule of thumb SFC expects that a minimum of three days a month in the office (on average) will achieve the benefits of its hybrid approach, however it is for the employee and their line manager to agree the balance between home and workplace working - determined primarily by business need. Please be aware that this role can only be worked from within the UK and not overseas. Relocation expenses are not available.

**Key Rewards and Benefits**
- Normal full-time hours of work are 35 per week. We will consider flexible working arrangements. A flex



  • Manchester, United Kingdom Iceberg Cyber Security Full time

    Iceberg Cyber SecurityData Loss Prevention Governance LeadJob Type: Full-timeLocation: RemoteAbout Iceberg Cyber SecurityWe are a dynamic and innovative Cyber Security company committed to delivering exceptional results for our clients. Our team is passionate about staying ahead of the curve and pushing the boundaries of what is possible.Job Description:The...


  • Manchester, United Kingdom Iceberg Cyber Security Full time

    Are you a seasoned professional with expertise in Data Loss Prevention (DLP) governance and risk management?About Iceberg Cyber SecurityWe are a leading global cybersecurity firm seeking an experienced individual to join our team as a DLP Governance Lead.The RoleYou will play a critical role in overseeing global DLP policies, standards, and risk management....


  • Manchester, United Kingdom Cyber Security Specialists Full time

    **Cyber Security Consultant** Based in Manchester UK, we are an independent Cyber Security Consultancy providing Security Consultancy and Managed Security services across a wide range of markets, from multi-national Corporate Organisations and Government Agencies, through to smaller Businesses that want to develop strong security strategies. We are a UK...


  • Manchester, United Kingdom Iceberg Cyber Security Full time

    Job Title: Cyber Security Governance ExpertAbout the Role:A seasoned professional is required to oversee global Data Loss Prevention (DLP) policies, standards, and risk management in a highly regulated financial environment. This role involves managing and improving DLP policies globally while leading risk management processes to support broader...


  • Manchester, United Kingdom The Portfolio Group Full time

    Portfolio are proud to be exclusively representing our award-wining, multinational HR & Employment Law services client in their search for a GRC Analyst to add to their team! The leading UK's Employment Law and Health & Safety Specialists, who provide a service to 28,000 Client's daily business operations are on the hunt. An exciting opportunity to join...


  • Manchester, United Kingdom AJ Fox Compliance Full time

    We are working with a top 100, full-service law firm who are looking to recruit a Risk & Compliance Lawyer for them. The firm is a fully inclusive employer and they are committed to creating personal and professional development opportunities for their staff. The successful applicant in this role will be working alongside the Head of Risk & Compliance in...


  • Greater Manchester, United Kingdom AJ FOX COMPLIANCE Full time

    Company OverviewAJ Fox Compliance is a dynamic Law Firm seeking a talented Senior Risk & Compliance Lawyer to join their Risk & Compliance team.We pride ourselves on providing exceptional service to our clients and are committed to excellence in everything we do.This role will play a crucial part in supporting our continued growth and success.Estimated...


  • Manchester, United Kingdom Umbrella Cyber Ltd Full time

    **Cyber Essentials and Essentials Plus Auditor** Umbrella-cyber.co.uk Fully Remote except for training days if required. £30,000 - £40,000 a year - Full-time **Benefits** - Permanent - Work from home - Flexible hours - Casual attire - Monday - Friday working. 9am - 6pm. No weekends or evenings **About Us** We are a dynamic business and an established...


  • Manchester, United Kingdom AJ FOX COMPLIANCE Full time

    Role OverviewAJ FOX COMPLIANCE is looking for an ambitious and forward-thinking Senior Risk & Compliance Lawyer to join their team in Manchester.The ideal candidate will have experience in law firm regulation, complaints handling or commercial contracts, and be able to collaborate with colleagues across other office locations.


  • Manchester, New Hampshire, United Kingdom Iceberg Cyber Security Full time

    Data Loss Prevention (DLP) Governance Lead Role OverviewIceberg Cyber Security seeks a seasoned professional to lead their global DLP initiatives. This role involves overseeing policies, standards, and risk management across the business.Key Responsibilities include:Providing leadership in governance and oversight for DLP initiatives.Managing, improving, and...


  • Manchester, United Kingdom Iceberg Cyber Security Full time

    Company OverviewMission-driven Global Financial Organisation is seeking a seasoned professional to join their Cyber Security team as a Data Loss Prevention (DLP) Governance Lead. With a strong understanding of governance and risk management, you will play a key role in overseeing global DLP policies and standards.Job DescriptionThe successful candidate will...


  • Greater Manchester, United Kingdom AJ FOX COMPLIANCE Full time

    About AJ FOX COMPLIANCE: We are a forward-thinking, ambitious Law Firm looking for a Senior Risk & Compliance Lawyer to join our Risk & Compliance team in Manchester. Our ideal candidate has background experience in law firm regulation, complaints handling or commercial contracts.The estimated salary for this role is £70,000 - £100,000 per annum.,...


  • Manchester, United Kingdom AJ FOX COMPLIANCE Full time

    A forward-thinking law firm in Manchester is seeking a Senior Compliance Lawyer to join their Risk and Compliance team.The ideal candidate has experience in law firm regulation, complaints handling, or commercial contracts.Responsibilities include:Supporting colleagues in claims handling according to internal proceduresLiaising with stakeholders on...

  • Cyber Risk Analyst

    4 weeks ago


    Manchester, United Kingdom Starling Bank Limited Full time

    Are you passionate about cybersecurity? Do you want to work for a forward-thinking company that's changing the face of banking? We're looking for a talented Cyber Risk Analyst to join our team at Starling Bank Limited.About the JobAs a Cyber Risk Analyst, you will be responsible for:Evaluating and mitigating cyber risks associated with our technology...


  • Manchester, United Kingdom Iceberg Cyber Security Full time

    Data Loss Prevention (DLP) Governance Lead RoleIceberg Cyber Security is seeking a talented professional to lead its global DLP initiatives as a DLP Governance Lead. The successful candidate will oversee the development and implementation of DLP policies, standards, and risk management processes.About the RoleThis position involves taking on a leadership...


  • Manchester, United Kingdom Iceberg Cyber Security Full time

    Job Summary: Global Cybersecurity Policy LeadWe are looking for a highly skilled individual to lead our global cybersecurity policy initiatives. As a key member of our team, you will be responsible for developing and implementing comprehensive cybersecurity policies that align with industry best practices. Your expertise will help us maintain a robust...


  • Manchester, United Kingdom AccessPay Full time

    Cyber Security Strategist RoleSalary: £120,000 - £150,000 per annum.We are seeking an experienced Cyber Security Strategist to lead our Governance, Risk and Compliance team and drive the development of our cyber security strategy. The ideal candidate will have a strong understanding of cybersecurity frameworks, standards, and regulations, as well as...


  • Manchester, United Kingdom Paradigm Tech Full time

    Job Title: Senior OT Cyber Security ConsultantA highly experienced and skilled Senior OT Cyber Security Consultant is required to lead our team in delivering exceptional cyber security solutions for our clients.About the Role:We are looking for a seasoned Cyber Security professional with expertise in Operational Technology (OT) to join our team as a Senior...


  • Manchester, United Kingdom NatWest Group Full time

    Job OverviewWe are seeking a highly skilled Business Compliance Specialist to join our team at NatWest Group. As a key member of our information security team, you will play a critical role in ensuring the effective management of risks associated with information and cyber security.Key ResponsibilitiesApply risk management and decision-making capability to...


  • Greater Manchester, United Kingdom AJ FOX COMPLIANCE Full time

    Job OverviewA forward-thinking AJ FOX COMPLIANCE in Manchester seeks a senior risk and compliance lawyer to support its growth.The ideal candidate has experience in law firm regulation, complaints handling or commercial contracts.Suitable applicants will have 5+ years PQE and excellent analytical, communication and organisational skills.Collaborate with...