Rodeo
Get started

Iceberg

Director – Cyber Effectiveness & Insight

Surrey
Posted about 16 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About the Company

A global financial services organisation with more than 50 years of history is continuing to invest in its Cyber & Information Security function.

The Cyber Effectiveness & Insight team provides the evidence and analysis needed to understand how the firm's cyber posture is changing, where controls are performing well, where they are falling short, and where investment is needed.

The Role

This is a senior leadership role responsible for building a clear, evidence-based view of cyber effectiveness across the organisation.

You'll lead the function responsible for cyber measurement and reporting, security data, control testing, maturity assessment, benchmarking, cyber risk quantification and executive insight.

The goal is to bring these areas together into one coherent view of cyber posture and control effectiveness, giving Security and business leaders a better understanding of where risk is changing and where action is required.

You'll be responsible for turning technical and security data into insight that can be used by senior leadership and the board to make decisions around risk, priorities and investment.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

The role covers:

  • Cyber posture and control effectiveness
  • Security data, measurement and reporting
  • Control testing and assurance
  • Cyber maturity assessment and benchmarking
  • Cyber risk quantification
  • Executive and board-level reporting
  • Identifying areas where controls, priorities or investment need to change

This is a first-line role, rather than a second-line Enterprise Technology Risk position. You won't own risk appetite or independent oversight. Instead, you'll build the evidence, transparency and analysis that allow accountable risk owners to understand their position and make better decisions.

What They're Looking For

  • Significant experience leading cyber risk, control effectiveness, security assurance, security data or a similar first-line capability within a complex or regulated organisation.
  • Strong understanding of how to measure cyber effectiveness and translate control performance into business risk.
  • Experience across areas such as control testing, maturity assessment, cyber metrics, risk quantification and security reporting.
  • The ability to bring fragmented data and assurance activity together into a clear view of cyber posture.
  • Experience presenting complex security and risk information to senior executives and boards.
  • Strong judgement and the ability to challenge constructively while maintaining clear ownership between first- and second-line functions.
  • Experience leading teams across different disciplines, including data, assurance, governance and cyber risk.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Why Join

This is an opportunity to build out a function that sits close to the CISO and has a direct influence on how cyber investment and priorities are decided.

Rather than owning a traditional GRC or second-line risk function, you'll be responsible for answering a more practical question: how effective is our security, where are the gaps, and what should we do about them?

You'll have broad ownership across cyber data, control effectiveness, assurance and risk insight, with visibility at executive and board level.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

Surrey, England, United Kingdom

Sign up to applySee more jobs like this