Job Title: Head of Cyber Strategy and Resilience
Department: IT Department
Reporting to: Head of Cyber Security
Main Role: Lead the organization’s cyber strategy, security investment portfolio, third-party cyber risk, remediation governance and cyber resilience capabilities. The role converts enterprise priorities and risk appetite into a funded multi-year roadmap and ensures that critical services can prepare for, withstand, respond to and recover from significant cyber disruption.
Principal Duties and Responsibilities
1. Core Accountabilities
- Own the cyber strategy, target-state operating model and multi-year roadmap, and lead the annual strategy refresh cycle.
- Govern portfolio prioritization, business cases, benefits, dependencies, OpEx and CapEx, and provide executive-level performance reporting.
- Maintain the cyber resilience strategy and crisis-management framework and oversee exercises, cyber recovery readiness and lessons learned.
- Oversee the first-line third-party cyber risk programme and ensure supplier risks are assessed and treated through the procurement lifecycle.
- Establish central remediation governance, risk-based prioritization and escalation for overdue or SLA-breaching security issues.
- Set objectives, service measures and accountability across strategy, resilience, remediation and third-party risk teams.
2. Governance Stakeholder and Reporting Responsibilities
- Maintain clear operating procedures, evidence, service metrics and management reporting for the assigned security services.
- Coordinate with IT operations, architecture, application, risk, compliance, audit and business stakeholders to resolve control gaps and delivery dependencies.
- Escalate material risks, incidents, SLA breaches and control weaknesses through the approved governance and incident-management channels.
- Support regulatory examinations, internal and external audits, risk assessments and management committees by providing accurate evidence and subject-matter input.
Personnel Specification
1. Education and Experience
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, Engineering or a related discipline; a relevant master’s degree is advantageous.
- 10-15 years, including at least 5 years in cyber leadership, strategy, resilience or portfolio governance.
- Demonstrated experience in a regulated, high-availability or financial-services environment is strongly preferred.
2. Technical Knowledge and Skills
- Cyber strategy, operating-model design, portfolio governance and executive reporting.
- Cyber resilience, crisis management, BIA, IT disaster recovery and cyber recovery.
- Financial planning, investment prioritization, supplier governance and benefits realization.
- Enterprise risk management, third-party risk and regulatory expectations for financial services.
- Working knowledge of NIST Cybersecurity Framework 2.0, ISO/IEC 27001 and the control lifecycle from design through operation and assurance.
- Ability to translate business, regulatory and risk requirements into measurable security outcomes, procedures and service metrics.
- Strong analytical, written communication, stakeholder-management and evidence-management skills in a regulated environment.
3. Operational and Behavioral Skills
- Sound judgement, integrity and the ability to handle sensitive information and high-pressure situations appropriately.
- Ability to prioritize risk, manage competing demands and deliver clear decisions, actions and escalation.
- Strong collaboration, influencing and communication skills across technical, business and executive audiences.
- Commitment to measurable service quality, continuous improvement and disciplined documentation.
- Ability to work effectively with internal teams, external suppliers, auditors and regulators.
Desired Certifications
- CISSP or CISM
- CRISC or CGEIT
- ISO 22301 Lead Implementer or CBCI/MBCI
- PMP or PRINCE2 Practitioner