Cyber Resilience Exercising and Planning Delivery

3 weeks ago


London, UK, United Kingdom Sumitomo Mitsui Banking Corporation – SMBC Group Full time

Department and Role Overview

Security and Operations exist to ensure that the Bank’s security risks are managed and aligned to business objectives, enable sustained growth and prevent harm, damage or loss to its people, information or assets.


This is a new role within a growing Cyber Resilience Team, presenting an exciting opportunity to shape our approach to exercising, scenario testing, and horizon scanning. This role will act as a key interface between the Security Operations Centre (SOC), EU entities, and the Americas Division, as well as other stakeholders at all levels of seniority across the business. This role will deliver on testing requirements set out under DORA, as well as other regulatory regimes, in order to ensure that the bank is less vulnerable to attack and able to respond and recover effectively if an attack is successful.


Key Job Functions

  • Take the lead in developing, maintaining, and implementing frameworks, policies, and procedures in relation to exercising and scenario testing on cyber resilience. This includes the development of playbooks, runbooks, and recovery plans. These should be consistent with regulatory requirements and industry best practice.
  • Act as a subject matter expert on cyber resilience related matters in relation to our Important Business Services, providing support across the business to ensure resilience.
  • Manage the delivery of exercising and scenario testing within the region and collaborate with the US on cross-regional exercising. This includes managing the delivery of such activity through third party vendors and service providers in a manner consistent with regulatory requirements.
  • Provide oversight, guidance, and robust challenge on remediation of lessons learned identified through exercising and scenario testing activity to ensure continuous improvement.
  • Maintain effective stakeholder relationships across subject matter experts across the business, including Important Business Service owners, to ensure effective exercising and scenario testing with high levels of assurance.
  • Provide appropriate reporting on metrics and escalation of identified issues to management in a timely manner, clearly communicating progress and risks.
  • Maintain a scenario library for exercising and scenario testing reflective of the risks faced by the Bank.
  • Deliver regular Horizon Scanning reports, in close coordination with our SOC Cyber Threat Intelligence team, to enhance the Bank’s understanding of threats and risks in relation to cyber resilience. These insights will also be used to maintain the scenario library.
  • Coordinate and manage our approach to information sharing and industry engagement, ensuring we make effective contributions to countering the cyber threat to the sector and gain value from insights shared across a variety of forums.



Responsibility and Authority

  • Responsible for cyber resilience exercising and scenario testing within EMEA to ensure regulatory compliance, directly and through third parties.
  • Responsible for providing valuable insight into how exercising, and the services within the Bank, are performing. Maintain records and track key metrics to identify areas for improvement, developing recommendations and ensuring timely escalation of issues.
  • Responsible for creation, maintenance and testing of key playbooks and recovery plans in relation to cyber resilience.
  • Responsible for maintaining strong stakeholder engagement in exercising regime to ensure effective delivery and subsequent remediation of issues identified. This will include regular contact across senior stakeholders in London, across the region and within the US and input into regular, formal governance forums.
  • Responsible for delivery of horizon scanning reports on cyber resilience, working closely with the SOC Cyber Threat Intelligence Team.
  • Responsible for maintaining records and key metrics to identify areas for improvement, developing recommendations and ensuring timely escalation of issues.
  • Responsible for coordinating and managing information sharing agreements and industry engagement.
  • No direct reports.
  • No budget responsibility.


Key Stakeholders

  • Head of Cyber Resilience EMEA
  • CISO
  • Operational Resilience (BSM)
  • CRES
  • CIMT
  • IT
  • Important Business Service/CIF owners
  • EMEA entities
  • AD Cyber Resilience


Organisation Structure

  • No direct reports
  • Reports to Head of Cyber Resilience EMEA


Key Skills & Abilities, Specific Experience and Qualifications

  • Very good knowledge & understanding of relevant frameworks such as NIST, ISO27001, MITRE ATT&CK.
  • Formal security certifications required: CompTIA Security+ minimum, CISM / CISSP / CRISC beneficial.
  • Very good knowledge and understanding of regulatory requirements on cyber resilience exercising and scenario testing, including under DORA and BoE Operational Resilience, and CBEST.
  • Strong knowledge of cyber security threats within the EMEA region, and preferably at a global level, including tactic, techniques and procedures used by threat actors.
  • Degree in cyber or technology related discipline, or equivalent work experience.
  • Training in intelligence analysis and assessment.
  • Experience of delivering cyber resilience exercising or scenario testing within a regulated corporate environment, preferably Financial Services.
  • Experience of handling and assessing cyber threat intelligence, including the development of actionable reporting at a tactical or strategic level.
  • Experience of industry engagement and information sharing forums on cyber, preferably within Financial Services.
  • Experience of playbook development and testing.
  • Excellent stakeholder management, communications (both written and verbal) and influencing skills.
  • Strong analytical and problem-solving skills applied to complex technical problems.
  • Proven ability to drive progress on projects, manage time effectively and ensure organised approach to work.



  • London,, UK, United Kingdom Harrington Starr Full time

    Harrington Starr have a brand new role within one our key banking clientsWe are seeking someone from a Threat Intelligence/ Cyber Resilience background to take a key role in cyber scenario testing/ tabletop exercises to work across London and the US as part of a growing cyber resilience teamKey accountabilities include:Manage the delivery of exercising and...


  • London, UK, United Kingdom Rothstein Recruitment Full time

    Operational Resilience & Third Party Oversight Manager Excellent opportunity to join top rated Private Bank to Manage Operational Resilience and 3rd party oversight. With a focus on Op Resilience - the ideal candidate will have experience in Op Resilience as well as ideally experience leading or mentoring teams. Manage and coordinate the bank’s Operational...


  • London,, UK, United Kingdom Europe Arab Bank Full time

    Job Purpose: The purpose for this role is to support the Hof Operational Resilience & Third Party Oversight and manage the direct team in both: 1) the execution/ongoing management of EAB’s Operational Resilience programme (covering both UK and EU regulatory requirements) & also 2) the oversight capabilities around Outsourcing and Third Party Risk...


  • London,, UK, United Kingdom BACB plc Full time

    An experienced Cybersecurity contractor to work as part of the Cybersecurity Target Operating Model to define/create BACB’s Cybersecurity Policies, Standards & Frameworks are required to meet the BACB Cybersecurity Maturity model.Scope of work:Policies, Procedures & Standards ISMS Framework Define a framework of policies, procedures and standards to...

  • Cyber Project Manager

    3 weeks ago


    London,, UK, United Kingdom identifi Global Resources Full time

    Technical Project Manager - Cyber Risk Transformations and MitigationLocation: London (2-3 days per week on-site)Salary: up to £65,000Industry: Naval/Maritime/MilitaryClearance: SC clearance neededAbout the Client:Our client is a leading provider of Cyber Security SME Consultancy dedicated to helping organizations enhance their cyber risk management...


  • London, UK, UK, United Kingdom IPS Group Full time

    Are you an Operational Resilience Specialist, and capable of spearheading business continuity?Our client, an established insurance specialist, seeks an Operational Resilience Specialist with expertise in business continuity to reviews and manage organisational resilience adhering to all legal and regulatory requirements.In the role, you will be exposed...


  • London, UK, UK, United Kingdom IPS Group Full time

    Are you an Operational Resilience Specialist, and capable of spearheading business continuity?Our client, an established insurance specialist, seeks an Operational Resilience Specialist with expertise in business continuity to reviews and manage organisational resilience adhering to all legal and regulatory requirements.In the role, you will be exposed...


  • London,, UK, United Kingdom Locke and McCloud Full time

    Cyber Security AnalystWe seek a Global Security Analyst to support and enhance our Firm’s security infrastructure. This role involves managing security tickets, assisting with strategic projects, and collaborating with IT departments to enforce best practices.Key Responsibilities:Serve as the first point of contact for security-related issues via the...


  • London,, UK, United Kingdom Hays Full time

    GTM Cyber Security Sales Director Professional Services Experience LondonAs a GTM Cyber Director, you will be leading and coordinating the different offer & chapter management activities for Cyber & Digital Risk across our Cyber offerings to support the development of our integrated business, in particular: Offer Strategy and Plan. Drive yearly planning...


  • London,, UK, United Kingdom Travelex Full time

    Job Title: Cyber Services SpecialistJob Type: Full-Time, PermanentLocation: London (Hybrid)Do you want to play a vital part in the strategy design, process development and management of a leading cyber function? Do you have the ability to spot gaps and opportunities for improvement in business and team processes? Do you enjoy deploying and managing cyber...

  • Business Continuity

    2 weeks ago


    London, UK, United Kingdom Venn Group Full time

    Operational Resilience and Business Continuity Planning Manager (Contract) Location: London (hybrid) Duration: 6-12 month rolling contract, detail TBC Company: Venn Group Industry: Financial Services/Asset Management About: Our client, a leading financial services institution, is seeking an experienced Operational Resilience and Business Continuity...


  • London, UK, United Kingdom Meraki Talent Full time

    Operational Resilience & Data Governance Manager (Tech) Excellent Salary & Package London (Hybrid) Permanent Posted Wed 04 Sep 24 CVs ASAP Start date Sep – Dec 24 Meraki Talent are working exclusively with a boutique financial services organisation in appointing an Operational Resilience & Data Governance Manager to sit within their technology...


  • London,, UK, United Kingdom Sumitomo Mitsui Banking Corporation – SMBC Group Full time

    Department and Role OverviewSecurity and Operations exist to ensure that the Bank’s security risks are managed and aligned to business objectives, enable sustained growth and prevent harm, damage or loss to its people, information or assets.This is a new role within a growing Cyber Resilience Team, presenting an exciting opportunity to shape our approach...

  • Delivery Driver

    3 weeks ago


    London, UK, UK, United Kingdom iMile Delivery Full time

    Self-employed Delivery DriverAs one of our Self-Employed Delivery Driver you'll enjoy freedom, flexibility and better financial rewards, plus all the support and benefits of being part of our wider iMile team. You don't need any experience, and the more you deliver, the more you earn.Why join iMileiMile is a logistics and courier services provider...


  • London,, UK, United Kingdom Wintermann Search Full time

    Our Client, a major global Banking group, is currently seeking a Senior Data Governance Risk Manager for their London Office. Principal Purpose of the Job:The Senior Data Governance Risk Manager role will have broad 2nd line of defence responsibility for a range of critical activities necessary to strengthen and maintain the data, information security, data...


  • London,, UK, United Kingdom Jefferies Full time

    Description for Internal CandidatesSupport implementation of the Operational Resilience and DORA (Digital Operational Resilience Act) requirements within the Firm, to ensure the Firm is compliant with both these regulations by Mar 2025.Perform assessments of service/function criticality and provide guidance to the business in the annual review cycles.Support...


  • London,, UK, United Kingdom Albany Beck Full time

    Albany Beck are hiring for a Junior Cyber Business Analyst to join our team to work with a leading Investment Bank based in London on a long-term programme of work. The bank is embarking on a large project to enhance cybersecurity and ensure compliance with the Digital Operational Resilience Act (DORA). We are looking for a proactive and detail-oriented...


  • London,, UK, United Kingdom Intec Select Full time

    Head of Cyber Security – circa £150,000 – Hybrid – Global ConsultancyOverview: We are seeking a Head of Cyber Security for one of our global consultancy clients. This role will oversee the Cyber Security team, ensuring robust technology, controls, and processes to safeguard devices, data, and digital networks from cyber threats.Key...


  • London,, UK, United Kingdom Hydras Full time

    Senior Cyber Security Architect | London | Hybrid (2-3 Days per week) | Up to £100,000 per annum & Excellent Benefits PackageA fast-growing technical consultancy headquartered in Central London is seeking a Senior Cyber Security Architect to join their team. The role will eventually move into a Lead Architect role and will require the successful candidate...


  • London,, UK, United Kingdom 55 Exec Search Full time

    Cyber Risk Advisory GRC Consultant - (ISO27001, PCI, NIST 2, TPRM) – REMOTE Looking for the next step in your Cyber Security career? Want to join a healthy, happy, collaborative, multicultural inclusive work environment? Our client could be your next employer! Our client is a pure-play cyber security consulting firm, due to a recent M&A and continued...