Manager - CCDI (Centre for Cyber Defence & Intelligence)

Posted Yesterday
Be an Early Applicant
3 Locations
In-Office
75K-125K Annually
Mid level
Fintech • Software • Financial Services
The Role
Leads the FCA’s Threat, Detection and Response function, overseeing threat intelligence, security operations, detection engineering and incident response. The role owns the detection improvement roadmap, manages internal teams and third-party providers, develops cyber performance metrics, improves monitoring and response effectiveness, and provides executive reporting. It also shapes cyber defence for AI-enabled technologies and ensures alignment with NIST, MITRE, INFORM and NCSC frameworks in a regulated environment.
Summary Generated by Built In

Job title: Manager - CCDI (Centre for Cyber Defence & Intelligence) 

Division: Operations 
Department: Cyber & Information Resilience (C&IR) 


  • Salary: National (Edinburgh and Leeds) ranging from £74,900 to 115,000 and London from £82,300 to £125,000 (salary offered will be based on skills and experience)
  • This role is graded as: Manager, Regulatory
  • Your external recruitment contact is Raimonda Stankute via [email protected]
  • Your internal recruitment contact is Lauren McHale via [email protected]
  • Applications must be submitted through our online portal. Applications sent via social media or email will not be accepted.

About the FCA and team 

We regulate financial services firms in the UK, to keep financial markets fair, thriving and effective. By joining us, you’ll play a key part in protecting consumers, driving economic growth and shaping the future of UK finance services. 

We are recruiting a Manager to lead the FCA's Threat, Detection & Response function, the Centre for Cyber Defence and Intelligence, part of Cyber & Information Resilience (C&IR) at the FCA. This is an exciting time to join the function as the FCA increases its adoption of AI and agent-based technologies. These developments create opportunities to modernise cyber defence, while also requiring a significant uplift in security monitoring, telemetry, detection engineering and response capabilities to manage new and evolving risks.

The FCA regulates over 35,000 financial services firms in the UK, setting standards for firms to meet and holding them to account if they do not. We enable a fair and thriving financial services market for the good of consumers and the UK economy. The CCDI Manager will operate and mature an intelligence-led cyber defence capability, translating current threat intelligence into monitoring priorities, detection improvements, exposure insight and measurable improvement in incident response. The role links Threat Intelligence, Security Operations, Detection Engineering, Cyber Assurance and Technology teams, including outsourced partners and maintains a data-driven view of detection effectiveness, response performance, service outcomes and coverage gaps.


Role responsibilities

  • Lead and develop the FCA's Threat Intelligence, Detection and Incident Response capability, delivering an intelligence-led approach to cyber defence and risk reduction
  • Drive continuous improvement of detection coverage, telemetry, response effectiveness and security operations through data-led insights, automation and effective stakeholder engagement.
  • Shape the security monitoring response to increased adoption of AI and agent-based technologies, ensuring that telemetry, detection logic and response capabilities evolve alongside the FCA’s technology environment.
  • Own the detection improvement roadmap, working closely with SOC providers, technology teams and cyber security stakeholders to deliver measurable outcomes
  • Lead and develop internal teams and third-party partners, ensuring effective performance, service quality and continuous professional growth
  • Establish meaningful cyber security metrics, KPIs and executive reporting to measure performance, resilience and risk reduction
  • Build trusted relationships across the FCA and external cyber security communities to improve threat awareness, influence priorities and share best practice
  • Ensure alignment with industry frameworks and guidance, including NIST CSF, MITRE ATT&CK, MITRE D3FEND, INFORM and NCSC standards

Skills required

Minimum:

  • Experience leading Cyber Security, Security Operations, Threat Intelligence or Detection Engineering teams, including developing people and delivering results through others
  • Solid knowledge of modern cyber threats, detection, threat intelligence and incident response, with experience managing cyber security partners and service providers
  • Effective stakeholder management and communication skills, with the ability to translate complex technical risks, security metrics and data into clear executive insights and recommendations
  • Advanced analytical and problem-solving skills, using data-driven approaches to improve security outcomes, operational effectiveness and cyber resilience

Essential:

  • Experience in one or more of Threat Intelligence, Security Operations, Detection Engineering, SOC Performance Management or Exposure Management, with a practical understanding of threat-informed defence methodologies, security monitoring, incident response and frameworks such as MITRE ATT&CK for adversary behaviour, D3FEND for defensive countermeasures, and INFORM for measuring defensive maturity.
  • Experience using security performance metrics, KPIs, KRIs, cyber maturity measures and operational reporting to support informed decision-making, continuous improvement and measurable cyber risk reduction
  • Experience delivering improvements to detection coverage, signal quality, response effectiveness and cyber resilience, including the use of automation, SOAR, telemetry enrichment, attack simulation or purple teaming approaches
  • Solid knowledge of cyber security controls across cloud, SaaS and enterprise environments, with experience using technologies such as Microsoft Defender, Microsoft Sentinel, CrowdStrike, AWS Security Services or similar security platforms
  • Demonstrated ability to influence senior stakeholders, communicate complex technical concepts to a range of audiences and produce high-quality governance papers and executive reporting
  • Knowledge of operational resilience, cloud security and regulatory expectations within complex or highly regulated environments
  • Relevant cyber security certifications such as CISSP, CISM, GIAC, SANS, Azure Security, AWS Security or equivalent are advantageous

Benefits

  • 28 days annual leave plus bank holidays
  • Non-contributory pension (8–12% depending on age) and life assurance at eight times your salary
  • Private healthcare with Bupa, income protection and 24/7 Employee Assistance
  • 35 hours of paid volunteering annually
  • Colleagues spend a minimum of 50% of their working time in the office each month (60% for Directors and Executive Directors) across our London, Leeds and Edinburgh offices. A flexible benefits scheme designed around your lifestyle

For a full list of our benefits and our recruitment process as a whole visit our benefits page.


Our values and culture

Our colleagues are the key to our success as a regulator. We are committed to fostering a diverse and inclusive culture: one that’s free from discrimination and bias, celebrates difference and supports colleagues to deliver at their best. We believe that our differences and similarities enable us to be a better organisation – one that makes better decisions, drives innovation and delivers better regulation.

If you require any adjustments due to a disability or condition, your recruiter is here to help - reach out for tailored support.

We welcome diverse working styles and aim to find flexible solutions that suit both the role and individual needs, including options like part-time and job sharing where applicable.


Disability confident: our hiring approach
We’re proud to be a Disability Confident Employer and therefore, people or individuals with disabilities and long-term conditions who best meet the minimum criteria for a role will go through to the next stage of the recruitment process. In cases of high application volumes we may progress applicants whose experience most closely matches the role’s key requirements.


Useful information and timelines

Timeline:

  • Job advert closes: Midnight, 20th October 2026
  • CV Review/Shortlist: 22nd October 2026
  • First stage interviews: w/c 26th October 2026
  • Assessments: w/c 2nd November 2026
  • Second stage interviews: w/c 16th November 2026
  • Your Recruiter will discuss the process in detail with you during screening for the role, therefore, please make them aware if you are going to be unavailable for any date during this time. 
  • SC Clearance is required for this role (SC Guidance) - you will hold or will be required to obtain Security Check (SC) level vetting 

Skills Required

  • Experience leading Cyber Security, Security Operations, Threat Intelligence or Detection Engineering teams
  • Experience developing people and delivering results through others
  • Knowledge of modern cyber threats, detection, threat intelligence and incident response
  • Experience managing cyber security partners and service providers
  • Strong stakeholder management and communication skills
  • Ability to translate technical risks, security metrics and data into executive insights and recommendations
  • Advanced analytical and problem-solving skills using data-driven approaches
  • Experience in Threat Intelligence, Security Operations, Detection Engineering, SOC Performance Management or Exposure Management
  • Understanding of threat-informed defence, security monitoring, incident response, MITRE ATT&CK, MITRE D3FEND and INFORM
  • Experience using security performance metrics, KPIs, KRIs, cyber maturity measures and operational reporting
  • Experience improving detection coverage, signal quality, response effectiveness and cyber resilience
  • Experience with automation, SOAR, telemetry enrichment, attack simulation or purple teaming
  • Knowledge of cyber security controls across cloud, SaaS and enterprise environments
  • Experience with Microsoft Defender, Microsoft Sentinel, CrowdStrike, AWS Security Services or similar platforms
  • Ability to influence senior stakeholders and produce governance papers and executive reporting
  • Knowledge of operational resilience, cloud security and regulatory expectations in complex or regulated environments
  • CISSP, CISM, GIAC, SANS, Azure Security, AWS Security or equivalent certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
5,214 Employees
Year Founded: 2013

What We Do

We work to ensure financial markets work well for individuals, for businesses and for the economy as a whole. We do this by: - regulating the conduct of approximately 50,000 businesses - prudentially supervising 48,000 firms - setting specific standards for around 18,000 firms We were set up on 1 April 2013, taking over conduct and relevant prudential regulation from the Financial Services Authority (FSA). Our Head Office is based in London, and we work across the UK, from our office in Edinburgh and via colleagues in Belfast and Cardiff. Firms and individuals must be authorised or registered by us to carry out certain activities. Before we grant authorisation, firms must demonstrate that they meet a range of requirements. We then supervise these firms to make sure they continue to meet our standards and rules after they’re authorised. If firms and individuals fail to meet these standards, we have a range of enforcement powers we can use. We work alongside the Prudential Regulation Authority (PRA), the prudential regulator of around 1,500 banks, building societies, credit unions, insurers and major investment firms.

Similar Jobs

Wise Logo Wise

Senior Software Engineer

Fintech • Mobile • Payments • Software • Financial Services
Hybrid
London, England, GBR
9000 Employees
88K-111K Annually
Hybrid
London, Greater London, England, GBR
15100 Employees

CDW Logo CDW

Architect

Information Technology
Hybrid
London, Greater London, England, GBR
15100 Employees

CDW Logo CDW

Architect

Information Technology
Hybrid
Peterborough, Cambridgeshire, England, GBR
15100 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account