Business Unit: Technology Operations and Cyber Security
Salary range: £48,000 - £60,000 per annum + Benefits
Location: UK Remote - work from anywhere within the UK, with occasional travel to Hub
Contract type: Permanent
Our Team
Are you passionate about cyber security and eager to make a real impact? At Virgin Money, we’re looking for a dynamic Cyber Project Specialist to join our Security Solutions team. We are championing being Secure by Design across all our change and delivery programmes, embarking on threat modelling and giving straight up advice for colleagues on security best practice and our regulatory requirements.
If you like a fast-paced and rewarding role that exposes you to exciting technology and will challenge you, then you may have just found it! We're looking for self-motivated enthusiastic individuals, who are ready to make a real difference to a successful team and play a key role in keeping our customers and colleagues safe.
What you’ll be doing
- Foster strong connections, help to shift our security culture and advocate for Secure by Design principles throughout our projects.
- Perform design reviews, threat modelling, and risk assessments to ensure robust security measures are incorporated from the outset.
- Offer expert advice and consultation on our policy & standards, industry regulations, frameworks, and best practices to support our change initiatives and operational teams.
- Ensure that security requirements and considerations are seamlessly integrated into our change solutions and evident.
- Identify and evaluate security risks, making recommendations to continuously improve Virgin Money’s security posture in an ever-changing threat landscape.
- Set clear objectives, boundaries, and focus areas for security tests to prevent vulnerabilities in our technical ecosystem.
- Ensure that any risks or findings from security scans or tests are addressed within risk appetite before changes are promoted to production.
We need you to have
- You know your Cyber Security Frameworks inside out and can explain their significance and impact to everyone from tech teams to senior business stakeholders.
- You’ve got good understanding across a range of Information Security domains, including Identity & Access Management, Network Security, Cryptography and Public Key Infrastructure, Mobile & API security, and more.
- Your strong analytical skills help you interpret how industry trends, regulations, and the threat landscape can affect our business.
- You’ve got experience in scoping penetration tests, conducting risk assessments, and overseeing remediation plans.
- You’re skilled at influencing, communicating, and collaborating with senior management and stakeholders.
- You’re well-versed in Cloud Service models like IaaS, PaaS, and SaaS and the security context when deploying solutions into them.
- You’ve got experience in a similar cyber role, information technology or governance / risk, bringing valuable insights and expertise to the table.
It’s a bonus if you have but not essential
- Experience working in a regulated industry and the financial services sector.
- Background and experience in threat modelling using techniques like STRIDE.
- knowledge and understanding of Microsoft Azure and 365 security products like Defender, Sentinel, Azure Information Protection, and Intune.
- Holding Information Security certifications such as CISM, CCSP, CRISC, or CompTIA Security+ and being actively involved in the cyber community through participation in working groups, forums, and facilitating knowledge-sharing sessions.
Red Hot Rewards
- Generous holidays - 38.5 days annual leave (including bank holidays and prorated if part-time) plus the option to buy more.
- Up to five extra paid well-being days per year.
- 20 weeks paid, gender-neutral family leave (52 weeks in total) for expectant parents and those looking to adopt.
- Market-leading pension.
- Free private medical cover, income protection and life assurance.
- Flexible benefits include Cycle to Work, wellness and health assessments, and critical illness.
And there's no waiting around, you'll enjoy these benefits from day one.
If we’re lucky to receive a lot of interest, we may close the advert early. Please ensure to submit your applications as soon as possible.
Say hello to Virgin Money
Virgin Money is so much more than just a bank. As part of the Nationwide group, together we're the UK's first full-service mutual bank serving millions of retail and business customers and all driven by our purpose; Banking but fairer, more rewarding and for the good of society. With us, you’ll be part of an organisation uniquely positioned to make a difference to the lives of customers, communities and broader society and embark on a collaborative, customer obsessed, and fun-filled career journey. Embrace the weekdays, enjoy fantastic perks, and make a meaningful positive difference. Time to discover what it means to be part of the first mutual full-service banking provider.
Be yourself at Virgin Money
At Virgin Money, we celebrate everyone. We have fun, think big, and relentlessly include each other, all in pursuit of our purpose: Banking – but fairer, more rewarding, and for the good of society. We’re committed to creating an inclusive culture where colleagues feel safe and inspired to contribute, speak up and be heard.
As a Disability Confident Leader, we're committed to removing any obstacles to inclusion. If you need any reasonable adjustments or support making your application, contact our Talent Acquisition team careers@virginmoney.com
Please note: If we receive a high volume of eligible applications, we may need to prioritise candidates whose skills and experience most closely align with the role, while still ensuring fair and equitable consideration for all applicants.
Now the legal bit
Although some of our roles allow you to be based anywhere in the UK, we'll need you to confirm you have the right to work in the UK.
If you're successful in securing a role with us, there are some checks you need to complete before starting. These include credit and criminal record checks and three years' worth of satisfactory references. If the role is part of the Senior Manager Regime and Certification Regime, it requires enhanced pre-employment checks – we'll ask for six years of regulatory references, and once in the role, you'll be subject to periodic employment checks.