About this role
Job Description
Arbuthnot Latham has been associated with banking since 1833. We combine private and commercial banking, wealth planning and investment management. We believe in traditional relationship and service-led banking powered by modern technology.
Job Purpose
To provide independent cyber security assurance that technology solutions are designed, implemented and operated securely. The role is responsible for cyber security architecture, secure-by-design governance, technical security standards, identity and access management governance, security assurance activities and cyber risk assessments, ensuring technology change aligns with the Bank's risk appetite, regulatory obligations and security requirements.
To place the interests of customers at the centre of all activities, act in a way that is consistent with achieving good outcomes for consumers; and to comply with the FCA and PRA’s Conduct Rules.
Job Description
Key Responsibilities
- Define and maintain the Bank's cyber security architecture principles, technical standards and security baselines.
- Provide governance and assurance over Identity & Access Management (IAM), Privileged Access Management (PAM), cloud security and security configuration standards.
- Lead security architecture reviews and provide independent assurance over technology solutions, projects and material technology change.
- Ensure security requirements are embedded within project, change and delivery lifecycles through secure-by-design principles and threat-led risk assessments.
- Oversee penetration testing, technical security assessments and vulnerability assurance activities, ensuring identified risks are appropriately assessed and managed.
- Provide cyber security expertise and advice to technology teams, architecture forums, suppliers and business stakeholders.
Key Interfaces
- Head of Cyber
- Cyber Governance & Compliance Manager
- Cyber Operations & Third-Party Security Manager
- Cyber Operations Analyst
- IT Infrastructure & Operations
- Digital Workplace
- Application Development and Change Teams
- Architecture and Design Authorities
- Third-party suppliers and technology partners
- Internal Audit and External Auditors
- Project Managers and Business Change Teams
Person Specification
Knowledge/**Experience/Skills
- Experience in Cyber Security Architecture, Security Engineering or Security Assurance.
- Experience conducting security architecture reviews and risk assessments.
- Experience within regulated environments.
- Experience with cloud security, identity services and security controls.
- Knowledge of ISO27001, NIST CSF, Cyber Essentials and security governance frameworks.
- Experience implementing secure-by-design and SSDLC practices.
- Experience with cloud security architecture within Azure and SaaS environments.
- Experience performing threat modelling and security design reviews.
- Experience supporting audit and regulatory assurance activities.
- Experience assessing technology risks in financial services environments.
Qualifications
Minimum of one below is required
- CISSP
- CCSP
- TOGAF
- Azure Security Engineer
Desirable
- ISO27001 Lead Implementer or Lead Auditor
Competencies
- Problem Solving and Judgment
- Customer Focus
- Planning and Reviewing
- Performance Focus
- Communication and Confidence
About Us
Life, Work and Benefits
At Arbuthnot Latham, we seek proactive individuals who embrace high standards and bring the energy needed to drive success. In return, you can thrive in a dynamic environment that values your innovative ideas and provides the stability and support for your personal and professional growth. Our human-scale ethos means that everyone is recognised as an individual, not just a number, creating a workplace where you truly belong and thrive.
As a service led, relationship driven bank, in-person collaboration and wellbeing are important to us and drives our inclusive culture. With this in mind we offer one day a week working from home.
Benefits
- Competitive holiday allowance with the ability to buy / sell / rollover up to five days per year
- Pension via market leading provider
- Private Healthcare cover
- 4x Life Assurance
- Discretionary Bonus
- Access to a suite of flexible benefits including Cycle to Work Scheme, Gym Scheme, Health Assessment, Season Ticket / Travel loans and Dental insurance as well as other discounts / vouchers
Data Privacy and Reasonable adjustments
We take keeping your data security seriously. For more detail on how we may keep your data please refer to our Privacy Notice
https://careers.arbuthnotlatham.co.uk/files/RecruitmentPrivacyNotice.pdf
Reasonable adjustments: Please let us know of any adjustments or arrangements that you may need to help you apply to this role or that will help you during the recruitment process. If you wish to discuss any particular requirements or concerns you have because of a disability or medical condition please contact us at recruitment@arbuthnot.co.uk. Information you provide about any disability or medical condition will remain confidential unless it is necessary to disclose it to other members of staff or outside agencies to ensure the health and safety of yourself and others, or to implement the adjustments you require. In these circumstances we will first discuss with you how and to whom the information may be disclosed.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in London →Why this fits a police background
- Risk & threat assessment
- Working to legislation & regulation
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |