Cyber Controls Framework Specialist
3 days ago
**Cyber Controls Framework Specialist**:
- Job Req ID: 51245
- Posting Date: 18 Sept 2025
- Function: Cyber Security
- Unit: Networks
- Location: Snowhill, Birmingham, United Kingdom
- Salary: Competitive with Great Benefits
**Why this job matters**:
BT’s ambition is to be the UK’s most trusted connector, and trust depends on the strength of our cyber security. The Cyber Controls Framework Manager plays a pivotal role in protecting that trust by ensuring BT has a resilient, transparent, and effective system of cyber controls.
By defining and sustaining a clear framework for how cyber risks are managed across BT, this role enables the business to demonstrate control discipline, regulatory confidence, and operational resilience. It ensures that security is not just a compliance exercise, but a source of assurance to customers, investors, regulators, and society that BT is managing risk responsibly.
This position creates value by making BT’s control environment measurable, understandable, and continuously improving — empowering leaders to make informed decisions, protecting customer data and services, and enabling BT to deliver digital transformation with confidence.
Through this focus, the Cyber Controls Framework Manager directly supports BT’s mission to connect for good and its ambition to lead with trust, resilience, and performance in an increasingly complex cyber threat landscape.
**This role is hybrid (3 days in office) in one of the following offices: London, Bristol, Manchester, Bletchley, Glasgow, Birmingham**
**What you’ll be doing**:
**About the role**:
The Cyber Controls Framework Specialist owns and develops BT’s cyber control framework, ensuring it remains current, risk-based, and aligned with regulatory and business needs. The role translates policy into practical, auditable controls that are clearly defined and allocated across BT’s business units and works with operational owners to ensure they are embedded and measurable.
You will not operate controls directly, but act as the architect and custodian of the framework — providing visibility of control health, driving improvements, and ensuring clear accountability across the control lifecycle. By maintaining strong integration with governance, assurance, and audit, this role helps BT sustain a resilient, transparent, and trusted control environment.
**Key Responsibilities**:
- Own and evolve BT’s Cyber Controls Framework to keep it current, risk-based, and aligned with policy and regulation.
- Translate policy and standards into practical, auditable controls that can be embedded across all business units.
- Define control requirements, scope, and workflow logic, ensuring alignment with BT’s central compliance reporting tools.
- Engage with operational control owners to ensure accountability for day-to-day implementation and operation.
- Build alignment with risk managers, standards managers, architects, solution designers, CIOs, and business leaders.
- Monitor compliance and control health using data and reporting to highlight effectiveness and systemic gaps.
- Drive improvements to both individual controls and the overall framework based on compliance insights and risk trends.
- Coordinate control issue management, ensuring risks and weaknesses are captured, owned, tracked, and resolved through a structured process.
- Ensure documentation, education, and accountability mechanisms are in place to support a repeatable framework.
- Integrate assurance and audit feedback into framework improvements while maintaining segregation of duties.
**Skills Required for the Role**:
- Systems thinking - able to see how policies, controls, operations, and governance connect, and design frameworks that work end-to-end.
- Sensemaking - skilled at interpreting complex, fragmented information to create clarity and direction.
- Influence and collaboration - skilled at building alignment across technical, risk, and business stakeholders in a federated organization.
- Analytical decision-making - confident using data, metrics, and assurance findings to make evidence-based improvements.
- Clear communication - capable of simplifying complex control concepts for diverse audiences, from technical teams to senior executives.
- Continuous improvement mindset - proactive in spotting gaps, learning from issues, and evolving the framework to meet new risks and regulations.
**Experience Required for the Role**:
Mandatory Experience:
- Proven experience or knowledge designing or managing cyber security control frameworks in a complex, federated organisation.
- Strong knowledge of security standards and regulations (e.g. CAF, NIS2, ISO 27001, UK Corporate Governance Code, PCI DSS).
- Hands-on experience working with control owners, risk managers, and assurance teams to embed and evidence security controls.
- Demonstrated ability to use compliance data, tooling, and metrics to monitor control effectiveness and drive improvements.
- Track record of stakeholder engageme
-
Cyber Security Specialist Devi Technologies
5 days ago
Birmingham, United Kingdom Devitechs Full timeWe are hiring a Cyber Security Specialist to strengthen our IT security framework and safeguard sensitive data across business and SAP environments.ResponsibilitiesConducted vulnerability assessments and penetration testing.Implemented firewalls, IDS/IPS, and endpoint protection.Monitored systems for security breaches.Managed security incidents and...
-
Cyber Security Consultancy Specialist
7 days ago
Birmingham, United Kingdom Randstad Digital Full timeJob Title: Cyber Security Specialist (Threat Modelling Contract) Location: Birmingham (Hybrid, 3 days on-site) Contract: 3 - 6 MonthsWe are seeking an experienced Cyber Security Specialist for a 3 - 6 month hybrid contract in Birmingham. This role is focused on conducting comprehensive threat modelling and risk assessments on complex IT and...
-
Cyber Security Consultancy Specialist
5 days ago
Birmingham, United Kingdom Randstad Technologies Recruitment Full timeJob DescriptionJob Title: Cyber Security Specialist (Threat Modelling Contract) Location: Birmingham (Hybrid, 3 days on-site) Contract: 3 - 6 MonthsWe are seeking an experienced Cyber Security Specialist for a 3 - 6 month hybrid contract in Birmingham. This role is focused on conducting comprehensive threat modelling and risk assessments on complex IT and...
-
Cyber Security Technical Specialist
1 week ago
Birmingham, Birmingham, United Kingdom UK Regulators' Network Full time £60,000 - £100,000 per yearOfwatWe regulate the water sector in England and Wales, Requirements of the roleWe are Ofwat, the Water Services Regulation Authority, a non-ministerial government department responsible for regulating the water sector in England and Wales.We have an opportunity for aCyber Security Technical Specialistto join our Water Supply Team within RAPID &...
-
Cyber Security Consultancy Specialist
7 days ago
Birmingham, United Kingdom Experis Full timeCyber Security Specialist Birmingham - hybrid3 months Inside IR35 - Umbrella only Overview We are seeking a highly skilled contractor to perform threat modelling and assessment activities across complex IT and telecommunications infrastructure. This role will be part of a small team whose function will be to identify risks across multiple and complex...
-
Cyber Security Policy and Guidance Manager
2 weeks ago
Birmingham, United Kingdom National Highways Full timeYour new role Cyber Security Policy and Guidance Manager The Cyber Security and Information Rights (CSIR) Team within Digital Services is accountable for the security of National Highways' Information and Operational Technology. You will work with experienced colleagues across the CSIR Team, wider National Highways directorates and external bodies. You...
-
Cyber Security Specialist
5 days ago
Birmingham, United Kingdom OCC Computer Personnel Full timeOne of our clients is recruiting a Cyber Security Specilialist to provide expert up-to-date technical and business knowledge on Cyber and Information security. It will also including ongoing maintenance, enhancements and improvements to ensure that the computinginfrastructure provided to the firm is effective, reliable, secure and performant. About you: -...
-
Head of Cyber Security
2 weeks ago
Birmingham, United Kingdom Ingeus UK Full timeHead of Cyber UK Midlands / Birmingham Contract: Permanent Salary: Competitive Hours: Full Time – hours will be discussed at interview Overview This is a unique and exciting opportunity to have end-to‑end Cyber accountability for our growing regional businesses across the UK and Europe, whilst also collaborating at a global group agenda. This role will...
-
Head of Cyber Security
2 weeks ago
Birmingham, United Kingdom Ingeus UK Full timeHead of Cyber UK Midlands/ Birmingham Contract: Permanent Salary: Competitive Hours: Full Time - Hours will be discussed at interview This is a unique and exciting opportunity to have end to end Cyber accountability for our growing regional businesses across the UK and Europe, whilst also collaborating at a global group agenda. This role will report directly...
-
Cyber Security Consultancy Specialist
3 weeks ago
Birmingham, United Kingdom Experis Full timeCyber Security Specialist Birmingham - hybrid 3 months Inside IR35 - Umbrella only Overview We are seeking a highly skilled contractor to perform threat modelling and assessment activities across complex IT and telecommunications infrastructure. This role will be part of a small team whose function will be to identify risks across multiple and complex...