Lead Cyber Risk Manager

Company: Metro Bank Plc
Apply for the Lead Cyber Risk Manager
Location: London
Job Description:

At Metro Bank, we believe the best banking experience starts with people who genuinely care. We’re not just delivering banking services – we’re building trust through authentic connections. Here, our people come first; our colleagues are part of a team that values individuality, collaboration, and long-standing relationships. We are also all about balance so most of our jobs offer the opportunity for hybrid working built around your role and home life, wherever possible.

What you will do

  • Lead Risk input into the Cyber Risk Improvement Programme, providing updates to SteerCo, Board, and regulators. Offer informed perspectives on risk reduction strategy and oversee third-party co-source arrangements. While the 1LOD programme will drive delivery, take ownership of building and enhancing the 2LOD cyber risk oversight capability, including leveraging external partners.
  • Provide ongoing oversight and assurance of the Information Security (Infosec) and Cyber risk and control environment.
  • Deliver independent review and challenge across Infosec improvement programmes, including validation of risk position, prioritisation, target operating model, service design, and overall feasibility.
  • Ensure identified control gaps are effectively addressed within solution design, and assess the maturity, sustainability, and practicality of proposed controls.
  • Act as the key liaison between third-party assurance providers and internal stakeholders at Metro Bank.
  • Conduct robust review and challenge of policies, standards, metrics, risks, and controls to ensure effectiveness and alignment with regulatory expectations.
  • Ensure testing and assurance activities are completed to high standards and provide reliable outcomes.
  • Support senior risk reporting by contributing clear, accurate updates on the Bank’s Infosec and Cyber risk posture to executive committees.
  • Review and challenge the 1LOD approach to identifying and managing emerging risks.
  • Provide input and challenge on regulatory updates and notifications to ensure appropriate response and compliance.
  • Influence and challenge the design of Information Security controls across IT and the wider business to ensure they are efficient, effective, and aligned with the evolving threat landscape.
  • Promote transparency and accountability in Information Security decisions across all supported programmes and projects.
  • Build and maintain strong relationships with senior stakeholders across Information & Cyber Security, Audit, and Risk functions.
  • Any other duties as required that reasonably fall within the job.

And… we are a bank so risk is a part of everything we do. We love people who take responsibility, do the right thing for customers, colleagues and Metro Bank and have the ability to call out any concerns.

What you will need

  • Extensive experience (7+ years) in Information Security, Cyber, Technology Risk, or 2nd Line Risk, operating at Manager, Lead, or Head level.
  • Demonstrated experience within a regulated UK financial services environment, with strong understanding of regulatory expectations and industry standards.
  • Proven track record of designing, implementing, or enhancing risk management and resilience frameworks.
  • Confident presenting to senior stakeholders, including Executive Committees and Board Risk Committees, with the ability to influence decision-making.
  • Relevant professional certifications are desirable (e.g. CISSP, CISM, CISA, CRISC, ISO 27001), reflecting expertise across both Information Security and Risk disciplines.
  • Strong experience in risk assessment methodologies, including RCSAs, control testing, and scenario analysis.
  • Practical knowledge of secure design, build, and control frameworks aligned to recognised standards such as ISO 27001, PCI DSS, and NIST.
  • Solid understanding of the regulatory landscape impacting financial institutions and the ability to interpret and apply regulatory requirements effectively.
  • Good understanding of Information Security within the project lifecycle, combined with strong working knowledge of enterprise technology environments.
  • Demonstrated experience in conducting security risk assessments for projects and designing effective, proportionate security controls.
  • Strong communication skills, with the ability to translate complex technical and risk concepts into clear, actionable insights for non-technical stakeholders.
  • Ability to critically assess regulatory and cyber risks across systems and projects, considering the broader business and Information Security context.
  • Clear understanding of operational and enterprise risk, with accountability for managing the impact of risk decisions on the organisation and its stakeholders.
  • Understand the risks associated with your job and what that means for you, Metro Bank and all our stakeholders.

Our promise to you

  • We will make sure that you are well-rewarded by providing you with a competitive salary, discretionary annual bonus, and a wide range of benefits, including generous holiday allowance, attractive pension scheme, healthcare, life assurance, and a number of colleague discounts!
  • We will give you the training to ensure you succeed in your role and plenty of internal opportunities to progress your career (around 40% of our recruitment comes from internal promotions!).

#J-18808-Ljbffr…

Posted: May 25th, 2026