Search

Cyber Security Lead

Posted: 18/09/26
Recruiter:Cambridge University Press & Assessment
Reference:3179909279
Type:Permanent
Disciplines: Network Security
Salary:£71,800 - £96,100 Annual
Location:Cambridge, Cambridgeshire
Description: English Technology Cyber Security Lead

Salary: £71,800 £96,100 per annum
Location: Cambridge, UK Hybrid, with approximately % of time in the office
Contract: Permanent
Hours: Full time, 35 hours per week

About the Role

We are seeking an experienced Cyber Security Lead to take strategic, technical and governance responsibility for cyber security across an English Learning Technology function.

This is a senior leadership opportunity to shape and own the cyber security agenda across a complex technology environment. You will establish security priorities, influence technology and investment decisions, develop security capabilities and ensure that security is embedded throughout the planning, development and operation of technology services.

You will work closely with senior technology leaders and a wider central security function to align local security priorities with the organisation's overall cyber security strategy.

As the senior authority for cyber risk within the function, you will provide clear and pragmatic advice to senior stakeholders, maintain visibility of the security posture across applications, platforms, suppliers and services, and ensure that risks and vulnerabilities are appropriately identified, prioritised and addressed.

You will also lead and develop a small security operations team.

Key Responsibilities

As Cyber Security Lead, you will:

  • Define the cyber security strategy, roadmap and priorities for the technology function.
  • Align security strategy and priorities with the wider organisational security framework.
  • Act as the subject matter expert and senior authority on cyber security and cyber risk.
  • Provide senior leaders with clear, evidence-based advice and appropriate challenge on security risks.
  • Maintain an authoritative view of the organisation's security posture across applications, platforms, cloud environments, suppliers and technology services.
  • Lead security governance, assurance and reporting activities.
  • Provide senior-level reporting on cyber risks, threats, vulnerabilities, incidents and security improvements.
  • Influence technology architecture, investment and transformation decisions to ensure security is incorporated from the outset.
  • Lead security assurance activities for major technology systems, projects and third-party suppliers.
  • Establish and promote secure-by-design principles across technology development and delivery.
  • Oversee the identification, prioritisation and remediation of security vulnerabilities.
  • Provide leadership and direction during significant security incidents and response activities.
  • Ensure technology teams and suppliers meet agreed security controls and remediation commitments.
  • Work closely with central security, technology, legal, procurement and supplier management teams.
  • Lead, coach and develop the security operations team.
  • Drive continuous improvement across cyber security processes, controls and capabilities.
Working Arrangements

This is a hybrid position, with the successful candidate typically expected to spend approximately % of their working time in the office in Cambridge to support collaboration, leadership and stakeholder engagement.

Flexible working arrangements may be considered where appropriate, including reasonable adjustments for candidates with disabilities or long-term health conditions.

About You

You will be an experienced cyber security leader with a proven track record of operating at a senior level within a complex technology environment.

You will bring strong expertise across security strategy, governance, risk management and assurance, combined with practical knowledge of application, platform and cloud security.

You will be confident working with senior stakeholders, providing constructive challenge and communicating complex cyber risks in a clear and commercially relevant way.

You will have experience developing security strategies, managing security risks and vulnerabilities, and driving incidents and remediation activities through to resolution.

Essential Experience and Knowledge
  • Senior-level experience in cyber security within a complex technology or enterprise environment.
  • Strong experience developing and implementing cyber security strategies and roadmaps.
  • Extensive knowledge of security governance, risk management and assurance.
  • Strong understanding of application, platform and cloud security.
  • Hands-on knowledge of AWS security and cloud security principles.
  • Experience managing cyber security risks, vulnerabilities and security incidents.
  • Strong stakeholder management and influencing skills, including experience working with senior leaders.
  • Ability to provide effective challenge and communicate cyber risk clearly to technical and non-technical audiences.
  • Knowledge and practical application of recognised security standards and frameworks, including:
    • ISO 27001
    • NIST
    • Cyber Essentials
    • OWASP
  • Experience working collaboratively across technology, legal, procurement and third-party suppliers.
  • Experience leading, mentoring and developing security professionals.
  • Strong understanding of security assurance across applications, platforms, projects and suppliers.
Desirable Experience

The following would be advantageous:

  • A recognised cyber security qualification or certification such as CISSP, CISM or CCSP.
  • Hands-on experience with AWS security services.
  • Experience with security and vulnerability management tools such as SonarCloud and Tenable.
  • Experience implementing Secure by Design principles.
  • Experience embedding DevSecOps practices throughout the software development lifecycle.
  • Experience working alongside a central or enterprise security function.
  • Experience within a regulated, education, publishing or similarly complex environment.
  • Experience establishing or developing security operations capabilities.
Benefits

The role offers a competitive salary and benefits package, which may include:

  • 28 days annual leave plus bank holidays.
  • Private medical insurance.
  • Permanent Health Insurance.
  • Discretionary annual bonus.
  • Group personal pension scheme.
  • Life assurance of up to four times annual salary.
  • Green travel schemes.
  • Flexible working arrangements where appropriate.
Recruitment Process

The recruitment process is expected to include:

  1. Initial screening call with the Hiring Manager approximately 15 minutes.
  2. First-stage virtual interview via Microsoft Teams.
  3. Completion of a role-related task as part of the first-stage assessment.
  4. Final-stage interview conducted in person in Cambridge.

The closing date for applications is 27 September 2026. Applications may be reviewed on an ongoing basis, with interviews expected to take place shortly after the closing date.

Candidates requiring reasonable adjustments during the recruitment process will have the opportunity to request these as part of the application process.

Successful candidates will be required to complete satisfactory background checks, which may include DBS checks due to the regulated nature of the working environment.

Equality, Diversity and Inclusion

We are committed to providing an equitable, inclusive and accessible recruitment process.

Applications are welcomed from candidates of all backgrounds and communities. Reasonable adjustments can be considered throughout the recruitment process for candidates with disabilities or long-term health conditions.

We value diversity of thought, background and experience and are committed to creating an environment where individuals can develop their careers and contribute effectively.

Role Summary

This is a senior cyber security leadership position with responsibility for strategy, governance, cyber risk, security assurance, cloud security, vulnerability management and security operations.

The successful candidate will play a key role in shaping the security direction of the technology function, influencing senior stakeholders, strengthening security capabilities and ensuring cyber security is embedded across technology delivery and operations.

Recruiting now