Cyber Risk and Compliance Lead
21 hours ago
**Cyber Risk & Compliance Lead**
**Permanent**
**Edinburgh/Hybrid**:
- **£61,626 - £72,684**_
Everything we do at the Scottish Funding Council (SFC) aims to create the right environment for colleges and universities to thrive.
The Scottish Funding Council is Scotland’s tertiary education and research authority. Our ambition is to make Scotland an outstanding place to learn, educate, research, and innovate - now and for the future. So, naturally, we have a clear focus on recruiting the best people and developing them throughout their career. We invest around £2 billion every year, and our funding enables colleges and universities to provide life-changing opportunities for over half a million people.
We’re not only looking for the best people to come and work for us, but also people who will connect with our guiding principles which include working in partnership, championing diversity, and supporting sustainability for future generations.
By fostering our guiding principles, we are very proud of the inclusive working environment that we have created. We are committed to attracting people of all backgrounds: we want our colleague base to reflect the people and communities that we serve.
**Job Summary**
As the Cyber Risk & Compliance Lead at the Scottish Funding Council, you will champion our cybersecurity initiatives, ensuring the protection of our operations, data and technologies in alignment with UK-specific cybersecurity standards and frameworks. This role is critical in maintaining the SFC’s reputation for excellence and integrity in the funding of education and research across Scotland.
**Key Responsibilities**
- Develop and implement a cyber risk management framework tailored to the specific needs and challenges of the SFC, focusing on the protection of financial data, personal information of students and staff, and sensitive research data.
- Ensure full compliance with Scottish and UK data protection laws, as well as adherence to specific regulations relevant to our organisation and our internal and external audit obligations.
- Collaborate closely with academic institutions, research bodies, and government agencies to align cyber security practices and foster a culture of shared responsibility and leading practices in data protection and risk management.
- Lead the review and enhancement of policies, procedures, and controls governing data security, risk assessment, and compliance within the funding council’s operations.
- Conduct targeted cyber risk assessments and compliance audits, providing strategic insights and recommendations to the SFC’s senior management and governing board.
- Act as a principal advisor on cyber security matters, offering expert guidance to support the council’s strategic initiatives in funding education and research.
- Stay abreast of emerging cyber threats and advancements in cyber security technologies and practices, ensuring the SFC remains proactive and responsive in its cyber risk and compliance strategies.
**Person specification**
**It is important through your CV / Cover Letter that you give evidence of proven experience of each of the following essential criteria**:
**Essential Requirements**:
- Proven track record in cybersecurity risk management, with a strong understanding of the UK cybersecurity landscape, including Cyber Essentials, ISO 27001 frameworks.
- Familiarity with the NCSC’s guidelines and recommendations for public sector organisations.
- Experience in managing cybersecurity compliance projects within the UK, including the attainment of Cyber Essentials certification.
- Leadership experience with the ability to mentor a team and drive cybersecurity awareness across an organisation.
- Excellent communication and influencing skills, capable of engaging effectively with a range of stakeholders on complex cybersecurity issues to ensure change is adopted and sustained.
**Professional Certifications**:
- Holding or working towards UK-recognized cybersecurity certifications, such as those offered by CREST or Cyber Essentials Plus, is highly desirable.
- Additional certifications such as CISSP, CISM, or ISO 27001 Lead Auditor/Implementer would be beneficial.
**Additional information**
**Location**
SFC offers hybrid working for its employees. This means that whilst the role is based at our Edinburgh office, there is substantial opportunity to work from home most of the time. As a rule of thumb SFC expects that a minimum of three days a month in the office (on average) will achieve the benefits of its hybrid approach, however it is for the employee and their line manager to agree the balance between home and workplace working - determined primarily by business need. Please be aware that this role can only be worked from within the UK and not overseas. Relocation expenses are not available.
**Key Rewards and Benefits**
- Normal full-time hours of work are 35 per week. We will consider flexible working arrangements. A flexi-t
-
Cyber Security Analyst
18 hours ago
Aberdeen City, United Kingdom Cyber Fraud Centre Full timeSword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving transformational change within our clients. We use proven technology, specialist teams and domain expertise to build solid technical foundations across platforms, data, and business applications. We have a passion for using technology to solve...
-
Cyber Risk
2 weeks ago
Aberdeen, Aberdeen City, United Kingdom Deloitte Full time £40,000 - £80,000 per yearBasic informationLocationAberdeen, Bristol, Cambridge, Manchester, Milton Keynes, Reading, St AlbansBusiness LineEnabling FunctionsJob TypePermanent / FTCDate published10-Oct-2025Req #21009Job descriptionConnect to your IndustryDeloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world....
-
Senior Cyber
22 hours ago
Aberdeen City, United Kingdom Cyber UK Full timeJob DescriptionRemarkable people, trusted by clients to design and advance the world. Wood is recruiting for a Senior Network & Cyber Security Engineer experienced in Automation and Control Network design and implementation to join our Systems Integration team as part of Wood Consulting business unit to support across our UK projects. This is a hybrid role...
-
Global CSIRT Lead
5 days ago
Aberdeen City, United Kingdom Cyber Security training courses Full timeJob description About KPMG International Together with more than 273,000 colleagues in 143 countries throughout our member firms, people at KPMG imagine big ideas and bring solutions to life for clients both big and small. A role with KPMG International will open a world of opportunity in your career. KPMG International helps set the strategy and protects...
-
Cyber Security Analyst
2 weeks ago
Aberdeen, Aberdeen City, United Kingdom Sword Group Full time £45,000 - £80,000 per yearSword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving transformational change within our clients. We use proven technology, specialist teams and domain expertise to build solid technical foundations across platforms, data, and business applications. We have a passion for using technology to...
-
Manager, Cyber
2 days ago
Aberdeen, Aberdeen City, United Kingdom Deloitte Full timeBasic informationLocationAberdeen, Belfast, Birmingham, Bristol, Cambridge, Cardiff, Edinburgh, Gatwick, Glasgow, Guernsey, Ipswich, Isle of Man, Jersey, Leeds, Liverpool, London, Manchester, Milton Keynes, Newcastle, Nottingham, Port Talbot, Reading, Southampton, St AlbansBusiness LineTechnology & TransformationJob TypePermanent / FTCDate...
-
Aberdeen, United Kingdom IACS Consulting Ltd Full time**Position Description**: Do you have existing Operational Technology (OT) experience or currently working in a role involving Control & Instruments, Risk Management or Systems Engineering with exposure and experience to OT Cyber Security? Perhaps you have experience with working with OG86 or the NIS Regulation? If the answer is yes to any of the above,...
-
Cyber Security Specialist
2 weeks ago
Aberdeen, United Kingdom Orion Full time**Job description**: Our client is currently recruiting for the position of Cyber Security Specialist, based in Aberdeen. **Responsibilities**: - Focal point for Cyber Security project scopes and development. - Scope and support external Cyber Security study work. - Develop and maintain detailed plans to address internal and external commitments. - Provide...
-
Cyber Operations Advisory Lead
7 days ago
Aberdeen, United Kingdom Atos Atos Full timeAbout AtosAtos is a global leader in digital transformation with c. 78000 employees and annual revenue of c. 10 billion. European number one in cybersecurity cloud and high-performance computing the Group provides tailored end-to-end solutions for all industries in 68 countries. A pioneer in decarbonization services and products Atos is committed to a secure...
-
Cyber Security Engineer
1 week ago
Aberdeen, United Kingdom TEC PARTNERS LIMITED Full time**OT Cyber Security Engineer** **Location: Aberdeen**(hybrid working + some offshore) **Salary: Negotiable - Market Rates** TEC Partners are working with a long-standing client in the Oil & Gas industry who are currently looking to recruit an experienced OT Cyber Security Engineer to join them as a focal point for Cyber Security duties. As an OT Cyber...