Be at the heart of actionFly remote-controlled drones into enemy territory to gather vital information.

Apply Now

Head of Cyber Security

Sandy
2 weeks ago
Create job alert

Head of Cyber Security
Reference: OCT(phone number removed)
Location: Flexible in England
Contract: Permanent
Hours: Full-Time, 37.5 hours per week
Salary: £70,490.00 - £84,794.00 Per Annum
Benefits: Pension Scheme, Life Assurance Scheme, 26 days' Annual Leave. RSPB provides a flexible working policy.

We are seeking a proven cyber security leader to take full ownership of the RSPB’s cyber security strategy and operations. This is a critical, strategic role for someone who can make immediate impact, bringing deep technical and practical expertise, to confidently lead the organisation’s cyber security agenda.

You will be the go-to authority on cyber security, responsible for safeguarding our digital infrastructure, data, and services. Reporting directly to the Chief Digital Technology Officer, you will shape and deliver a forward-thinking cyber strategy that ensures resilience, compliance, and a strong security culture across the RSPB.

This is not a developmental role. We are looking for someone who has already led cyber security at scale, ideally in a complex, multi-stakeholder environment, and who can confidently operate at a senior level from day one.

Key Responsibilities

  • Lead the development, implementation, and continuous improvement of the RSPB’s cyber security strategy.

  • Act as the senior accountable executive for cyber risk, compliance, and incident response.

  • Provide expert advice to the CDTO, trustees, and executive board on cyber threats, risks, and mitigation strategies.

  • Embed a cyber-aware culture across the organisation through training, awareness campaigns, and policy enforcement.

  • Maintain oversight of cyber KPIs, threat intelligence, and incident response protocols.

  • Ensure compliance with relevant regulatory frameworks (e.g., PCI DSS, NIST, ISO 27001)

  • Build and maintain strategic relationships with external partners, including regulators and the National Cyber Security Centre.

  • Represent cyber security in major organisational change programmes and digital transformation initiatives.

    Essential Qualifications

  • Professional security certification such as CISSP, CISM, or equivalent.

  • Degree in Cyber Security, Information Security, or Digital Technology, or equivalent professional experience (minimum 10 years in cyber security roles, with at least 5 years in a senior leadership capacity).

  • Membership of a recognised professional body (e.g., (ISC)², ISACA, BCS).

    Essential Knowledge and Experience

  • Demonstrable experience leading cyber security in large, complex organisations.

  • Deep understanding of cyber security frameworks and standards (e.g., NIST, ISO 27001, PCI DSS).

  • Proven track record of developing and delivering cyber strategies and managing risk at an enterprise level.

  • Strong technical knowledge of modern security technologies and principles, including Azure, AWS, and SaaS environments.

  • Experience of governance, risk management, and compliance in regulated environments.

  • Evidence of leading cultural change and embedding cyber awareness across diverse teams.

  • Experience advising executive boards and trustees on cyber risk and resilience.

    Essential Skills

  • Strategic leadership and influence at executive and board level.

  • Ability to operate independently and take full ownership of the cyber function.

  • Strong communication skills with the ability to translate technical risk into business impact.

  • Decisive and calm under pressure, particularly in high-risk or incident scenarios.

  • Skilled in building high-trust relationships with internal and external stakeholders.

    Desirable

  • Experience in cyber leadership within the charity or not-for-profit sector.

  • Evidence of sector-wide advocacy, thought leadership, or contributions to national cyber policy or forums.

    Closing date: 23:59, Sunday 2nd November 2025
    Please note that we are actively recruiting for this vacancy, and reserve the right to close once sufficient applications have been received.
    We are seeking to commence interviews from the 17th of November, 2025.

    Interested?

    If you would like to find out more, please click the apply button. You will be directed to our website to complete your application for this position.

    We are committed to developing an inclusive and diverse RSPB, in which everyone feels supported, valued, and able to be their full selves. To achieve our vision of creating a world richer in nature, we need more people, and more diverse people, on nature’s side. People of colour and disabled people are currently underrepresented across the environment, climate, sustainability, and conservation sector. If you identify as a person of colour and/or disabled, we are particularly interested in receiving your application.

    The RSPB is an equal opportunities employer. This role is covered by the Rehabilitation of Offenders Act 1974.

    The RSPB is also a licenced sponsor. This role is eligible for UK Visa Sponsorship.

    To complete this application process you will be asked to provide a CV and Covering Letter. Contact us to discuss any additional support you may need to complete your application.

    No agencies please

Related Jobs

View all jobs

Head of Cyber Security

Systems Engineer – Security & M365

IT Manager

Information Security and Compliance Manager

Lead / Senior Information Security Analyst

Head of IT Security Incident and Threat Management

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Cyber Security Recruitment Trends 2025 (UK): What Job Seekers Must Know About Today’s Hiring Process

Summary: UK cyber security hiring has shifted from title‑led CV screens to capability‑driven assessments that emphasise incident readiness, cloud & identity security, detection engineering, governance/risk/compliance (GRC), measurable MTTR/coverage gains & secure‑by‑default engineering. This guide explains what’s changed, what to expect in interviews, & how to prepare—especially for SOC analysts, detection engineers, blue/purple teamers, penetration testers, cloud security engineers, DFIR, AppSec, GRC & security architecture. Who this is for: SOC & detection engineers, security operations leads, DFIR analysts, penetration testers/red teamers, purple teamers, AppSec/DevSecOps engineers, security architects, cloud security engineers, identity/IAM engineers, vulnerability managers, GRC/compliance specialists, product security & security programme managers targeting roles in the UK.

Why Cyber Security Careers in the UK Are Becoming More Multidisciplinary

Cyber security used to be viewed primarily as a technical discipline: firewalls, encryption, intrusion detection, penetration testing. In the UK today, it’s far broader. Organisations now face complex legal frameworks, ethical dilemmas, human-behaviour risks, communication challenges & usability hurdles. This shift means cyber security careers are becoming more multidisciplinary. From protecting NHS patient records to defending financial services, securing supply chains & safeguarding national infrastructure, cyber security now touches every sector. Employers increasingly want professionals who understand law, ethics, psychology, linguistics & design alongside traditional technical skills. In this article, we’ll explore why UK cyber security careers are expanding in this way, how these five disciplines shape the profession, and what job-seekers & employers need to know to thrive in this new landscape.

Cyber Security Team Structures Explained: Who Does What in a Modern Cyber Security Department

Cyber security has become a top priority for UK organisations of all sizes. From small businesses to financial institutions, healthcare providers, and government bodies, the risk of cyber attack is now a constant concern. Threats are more sophisticated, regulations more demanding, and customers more aware of data privacy than ever before. But defending against cyber threats isn’t simply about having the right tools — it’s about having the right team. A modern cyber security department relies on clearly defined roles and responsibilities to ensure that defences are proactive, incidents are managed swiftly, and compliance is maintained. This article explains the structure of a modern cyber security team, the roles you’ll typically find within it, how they collaborate, and what skills, qualifications, and salaries are expected in the UK job market.