Financial Conduct Authority
Regulating financial services firms and financial markets in the UK, https://www.fca.org.uk/careers
Requirements of the role
The Cyber and Operational Resilience directorate enables secure and resilient regulation across the FCA and PSR, supporting the protection of UK consumers and financial markets.
This Senior Associate sits within the Policy & Risk team, part of the wider Governance and Human Risk function. The role focuses on the management and maintenance of the Cyber & Information Resilience Policy Framework, including associated standards, procedures and guidance.
Role responsibilities
- Maintain and refresh the cyber policy framework by managing policy and standards updates in line with agreed review/refresh cycles and making out-of-cycle updates where material changes are required
- Modernise and simplify the policy & standards suite, exploring improved formats (e.g., “standards on a page”) to increase usability and adoption across the organisation
- Serve as the FCA-wide point of contact for policy requirements, handling BAU and project-related queries and providing clear, consistent interpretations of published requirements
- Manage and track policy non-compliance and exceptions, including owning and modernising the Policy Waiver process and ensuring issues are surfaced and understood by relevant stakeholders
- Conduct policy gap analysis and horizon scanning, identifying emerging risks, regulatory/industry changes and required updates to keep the framework current and effective
- Support articulation of the organisation’s Cyber Risk Appetite through the policy framework, ensuring requirements align to risk tolerance and are understood across the business
- Enable a new self-service policy model for low-risk projects, helping define requirements and controls that balance agility with the FCA’s risk appetite
- Provide reporting and governance support by assisting the Risk lead with controls performance measurement and supporting the GHR Manager/CISO with reporting on cyber issues, audit/risk engagements and organisational non-compliance; additionally supporting specialist investigation teams and HR with policy interpretation where needed
View on member website
ViewLocation
London, Edinburgh, LeedsContract type
Full time, Permanent
Profession
Financial Services, IT, Risk
Working pattern
Flexible working, Hybrid
Closing Date
14/05/2026