Metro Bank (UK)
Head of Cyber Protection

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Team
Location AMAZE Central - Holborn
County Greater London
Ref # POS_18392
Closing Date 23-Sep-2026
At Metro Bank, we believe the best banking experience starts with people who genuinely care. We’re not just delivering banking services - we’re building trust through authentic connections. Here, our people come first; our colleagues are part of a team that values individuality, collaboration, and long-standing relationships. We are also all about balance so most of our jobs offer the opportunity for hybrid working built around your role and home life, wherever possible.
What You Will Do
As the Head of Cyber Protection, you will drive a proactive risk-based approach to cyber security, ensuring threats and vulnerabilities are identified, understood, prioritised, and effectively managed. You will lead a high-performing team, foster a culture of continuous improvement, and work closely with senior stakeholders across the business to strengthen Metro Bank’s security posture while enabling innovation and growth.
- Lead Metro Bank's Cyber Protection capability, including Cyber Risk Assessment, Cyber Awareness & Training, Identity & Access Management (IAM), and Data Loss Prevention (DLP).
- Define and deliver the Cyber Protection strategy and roadmap, ensuring alignment with the Bank's overall cyber security and business objectives.
- Oversee cyber risk assessments for technology change and development, ensuring risks are identified and managed effectively.
- Drive cyber awareness across the organisation, helping colleagues understand their responsibilities and adopt secure behaviours.
- Ensure appropriate controls are in place to manage access to systems and data, following least-privilege and security best practices.
- Lead the Data Loss Prevention capability, protecting sensitive customer and business information from unauthorised access or disclosure.
- Work closely with Technology, Data, Risk, Change and business teams to embed security into processes, projects and new solutions.
- Provide regular reporting to the CISRO and governance forums on cyber risks, control effectiveness, capability maturity and key priorities.
- Build and develop a high-performing team, creating a culture of accountability, collaboration and continuous improvement.
- Manage suppliers, budgets and service performance to ensure the Cyber Protection function delivers effective outcomes and value.
- Work effectively with second and third lines of defence, external auditors and regulators to support strong governance and compliance.
- Any other duties as reasonably required within the role
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
And... we are a bank so risk is a part of everything we do. We love people who take responsibility, do the right thing for customers, colleagues and Metro Bank and have the ability to call out any concerns.
What You Will Need
- Proven experience operating in a senior cyber security leadership role within a regulated financial services environment or similarly complex organisation.
- Demonstrable expertise in leading cyber protection, security engineering, security architecture, vulnerability management, identity and access management, or security operations functions.
- Strong track record of delivering significant cyber security control improvements, remediation programmes, and transformation initiatives across complex technology estates.
- Deep technical understanding of enterprise cyber security controls, including identity and access management, endpoint security, network security, cloud security, vulnerability management, logging and monitoring.
- Strong knowledge of industry-standard cyber security frameworks and methodologies, including NIST CSF, ISO 27001, CIS Controls, COBIT and MITRE ATT&CK.
- Experience communicating cyber risks, control effectiveness and investment recommendations to Executive Committees, senior leadership teams and governance forums.
- Proven ability to translate complex technical cyber risks into clear business impacts and actionable recommendations for non-technical stakeholders.
- Experience working with second and third lines of defence, external auditors and regulatory bodies, ensuring effective governance and regulatory compliance.
- Strong stakeholder management and influencing skills, with the ability to constructively challenge, build consensus and drive accountability across all levels of the organisation.
- Demonstrated experience managing security budgets, suppliers and third-party service providers, ensuring effective operational performance and value for money.
- Proven people leadership experience, including building high-performing teams, developing talent and fostering a culture of continuous improvement.
- Strong understanding of cyber threats, attack methodologies and emerging security trends across hybrid and cloud environments.
- Relevant professional cyber security qualification such as CISSP, CISM, CISA, CRISC, CCSP or equivalent.
- Understand the risks associated with your job and what that means for you, Metro Bank and all our stakeholders


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Our promise to you…
We will make sure that you are well-rewarded by providing you with a competitive salary, discretionary annual bonus, and a wide range of benefits, including generous holiday allowance, attractive pension scheme, healthcare, life assurance, and a number of colleague discounts! We will give you the training to ensure you succeed in your role and plenty of internal opportunities to progress your career (around 40% of our recruitment comes from internal promotions!
Important Footnote
Diverse teams really are the best teams. We know that candidates (especially women, research tells us) may be put off applying for a job unless they can tick every box. We also know that ‘normal’ office hours aren’t always doable, and while we can’t accommodate every flexible working request we are happy to be asked. So if you are excited about working with us and think you can do much of what we are looking for but aren’t sure if you are 100% there yet… why not give it a whirl? Good luck!
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location