
Lead Cyber Consultant in SUPPLY CHAIN & CULTURE
at Bank of England
Posted a day ago
No clicks
- Compensation
- £72,320 – £81,360 GBP
- City
- Not specified
- Country
- United Kingdom
Currency: £ (GBP)
Lead Security Consultant / Lead Security Architect in the Bank of England Cyber Security Division, focusing on managing cyber risk across the supply chain. You will conduct risk assessments, lead programs, and shape secure, usable supplier solutions while engaging senior stakeholders. This Leeds-based role offers flexible working and a path to senior leadership within a prestigious central bank.
Location: Leeds, United Kingdom
Lead Cyber Consultant, Technology Directorate
x1 Permanent
x2 12 Months FTC
Location - Leeds
Flexible Working Options
This role is open to flexible working patterns, these may include:
- Job share
- Flexible start and end time to each day
- Part time
- Ability to adapt calendar as needed, this could be to fit in the school run, gym, or appointments
- A 50% in-office attendance requirement can be spread across the month to accommodate diverse working patterns, such as the flexibility to purchase a weekly train ticket for certain weeks
- Compressed hours (subject to approval and policy within the team)
- Working from abroad policy (subject to approval and policy within the team)
Opportunities in Leeds
We’re excited to be growing our presence in Leeds, a city we’ve been connected to for nearly 200 years! Our modern, accessible office in the City Centre offers a supportive, flexible working environment. The majority of roles, including this one, are now available in Leeds, giving you the chance to build a meaningful career outside of London while contributing to our mission from a dynamic and growing location. You’ll work collaboratively with London-based colleagues in a hybrid model, with regular opportunities to travel into the London office to meet and connect together in person.
Want to learn more? Discover what makes our Leeds office such a dynamic place to work by visiting our Leeds page for more details.
A Day in the Role
Cyber Security Division
The Cyber Security Division (CSD) is an award-winning group of cyber security experts who are committed to keeping the Bank of England safe from cyber-attacks and incidents. In 2023 CSD were recognised with the Financial Services award of the year at the National Cyber Awards. This followed previous award wins for individuals within our team at the WeAreTechWomen and Women in IT Awards, and Central Banking’s Best Cyber Resilience Initiative.
Within Cyber Security you will be working with people who are passionate about protecting the Bank from Cyber security incidents. Given the importance and complexity of technology for the Bank of England, the security challenges are rarely straightforward and often span multiple systems hosted in our own data centres, in the cloud and as SaaS, requiring cross-team working and deep technical expertise to address them effectively.
You’ll assess the security of solutions being considered by Bank teams, including SaaS solutions. By collaborating closely with colleagues across Technology and throughout the organisation you will play a key role in safeguarding the Bank and its information.
Our teams are committed to developing their expertise in a constantly evolving environment. Aligned to industry best-practice, staff are encouraged to develop their skills both internally and externally, through mentoring, training and formal qualifications.
Job Description:
The Cyber Security Division advises business areas on how best to manage and mitigate the cyber security risks in one of the Bank’s most complex and fastest growing risk areas: the supply chain.
We are looking for a highly experienced Lead Security Consultant or Lead Security Architect who will perform complex risk and assurance activities on systems and solutions that underpin the economy and modernise how our colleagues securely work every day.
As a Lead Security Consultant, you’ll risk assess a range of IT solutions and steer major programmes so that cyber security, simplicity, and user experience move forward together. You’ll combine hands‑on consultancy or architectural leadership with great stakeholder influence to ensure our suppliers provide secure, useable, and cost-effective solutions to the Bank.
The Lead Security Consultant will:
- Champion a modern security posture - threat‑informed and focused on measurable reduction of attack surface.
- Conduct IT security risk assessments and assurance activities to ensure solutions meet policy and technical standards, including as part of formal procurement tenders;
- Act as senior consultancy voice for high‑impact initiatives, aligning security capabilities to business outcomes and risk profiles, and shaping option analysis with clear trade‑offs.
- Lead/implement projects and initiatives to reduce supply chain security risks and improve our ability to recover from, and be resilient to, supplier incidents;
- Communicate complex security choices simply - at meetings/workshops, in option papers, and risk assessments that influence senior stakeholders and unblock decisions.
- Review and agree cyber security contract terms;
- Provide stakeholder leadership – be comfortable influencing senior leaders and guiding engineers/SMEs, produce strong documentation and have strong communication skills.
Role Requirements:
Minimum Criteria
- Proven in technical roles (preferably with a cyber security element).
- Significant experience working in cyber security consultancy or architecture roles within highly regulated sectors (e.g. financial/insurance, defence, civil nuclear, intelligence).
- Considerable experience conducting technical risk assessments:
- Analysing technical problems to identify potential security concerns
- Reviewing IT architecture to identify potential security gaps and/or vulnerabilities
- Assessing compliance with IT security policies and technical standards (e.g. ISO 27001, NIST, Cyber Essentials, COBIT, etc…)
- Liaising with other stakeholders to reach agreement of the level of risk
- Writing technical reports.
- Relevant technical qualifications (e.g. CRISC, CISM, NCSC CCP, CISSP, ISSAP).
Essential Criteria
- Sufficient experience and expertise in cyber security and risk to be able to act as a point of escalation for the team.
- A solid understanding of IT network architecture and components, software/application security, infrastructure security, Cloud.
- Active interest in new technical concepts and/or technologies.
- Must be able to collaborate with stakeholders to identify critical business functions and establish how cyber security controls can support them.
- Ability to communicate complex security choices simply and effectively
- Strong stakeholder management and collaboration skills and experience advising up to, and including, ‘C’ suite staff.
Desirable Criteria
- The ability to acquire DV clearance (To be eligible to apply you must be a British citizen (either born here or naturalised) and one of your parents must be a British citizen or have substantial ties to the UK.)
- Additional technical qualifications (e.g. CompTIA SecurityX, CCSK, CCSP, CompTIA Network Plus;, GDSA)
- Advanced qualifications in Cyber Security, Technology, Computer Science.
- Knowledge of well-known Frameworks (e.g., NIST, MITRE ATT&CK, ISO 27001) and how they are applied pragmatically within delivery.
- Currently a non-contributory, career average pension giving you a guaranteed retirement benefit of 1/80th of your annual salary for every year worked. There is the option to increase your pension (to 1/65th) or decrease (to 1/105th) in exchange for salary through our flexible benefits programme each year. The Bank has the discretion to vary standard accrual rates and dial up and dial down rates at any time and to withdraw dial up and dial down options at any time.
- A discretionary performance award based on a current award pool.
- An 8% benefits allowance with the option to take as salary or purchase a wide range of flexible benefits.
- 26 days’ annual leave with option to buy up to 12 additional days through flexible benefits.
- Private medical insurance and income protection.
The Bank of England welcomes applications from all candidates, but as a UK Visas and Immigration (UKVI) approved sponsor, we have a responsibility to comply with the Immigration Rules and guidance. As such, our ability to employ individuals who require sponsorship for immigration purposes is limited. The Bank cannot guarantee that you and / or the role you are applying for will be eligible for sponsorship and that any application made to UKVI will be successful. Eligibility will therefore be considered on a case by case basis.

