Skip to main content
AfterDuty

Cybersecurity Lead

NATO · London, Greater London

Type
Full-time
Posted
17 days ago

Overview

This role is deeply technical, requiring hands-on expertise in cyber security architecture, ISO 27001, NIST frameworks, and cloud security — areas where standard policing experience does not directly translate. While your investigative discipline and evidence-handling mindset are valuable, you would typically need significant retraining and industry certifications to compete for this lead-level position.

About this role

The post is budgeted from 1 January 2027, and the successful candidate is expected to start employment as soon as possible thereafter.

1. OVERVIEW OF DIANA

NATO DIANA is the Defence Innovation Accelerator for the North Atlantic, a NATO body dedicated to finding and accelerating innovation to provide decisive defence and security effects for the Alliance, while fostering deep-tech innovation. NATO DIANA is comprised of a Board of Directors, representing all 32 nations, and an operational team referred to as the DIANA Executive (DX"). Operating from three offices in Europe and North America, the DX leverages a network of military end users, world-leading accelerator sites, test centres, professional mentors and experts, and Allied expertise to accelerate the most innovative technologies from across the NATO Alliance. DIANA is a dynamic, agile workplace, which strives for innovative thinking, diversity, and performance excellence across all teams. To achieve our mission, DIANA is committed to providing our people with an environment that is positive, inclusive and collaborative.

2. OVERVIEW OF THE ROLE

The Safety, Security & Resilience (SSR) Team is responsible for safeguarding DIANA's people, information, facilities, and digital assets. The team develops and maintains proportionate frameworks, policies, controls, and assurance arrangements across cyber security, information security, physical security, safety, and security risk management to enable secure, safe, and resilient operations across DIANA. The Cybersecurity Lead is responsible for delivering DIANA's cyber security activities, ensuring the secure and resilient operation of its cloud, digital, and business technology services, along with cyber security architectural design. The role combines hands-on technical expertise with responsibility for cyber governance, risk management, compliance, resilience, and assurance, embedding security by design across the organisation.

Reserve candidates may be considered for similar posts in Estonia or Canada, if appropriate.

Reporting to DIANA's Head of Safety, Security & Resilience

Duties of this role include

  • Lead the development, implementation and continual improvement of DIANA's cyber security, security architecture, governance framework, risk-management arrangements and assurance programme, building in security by design principles.
  • Establish and manage cyber security policies, standards, control frameworks, risk registers, security metrics, and assurance documentation.
  • Lead and oversee security risk assessments for DIANA Digital assets.
  • Provide second-line challenge, oversight and assurance across technology projects, suppliers, cloud platforms, SaaS applications, AI solutions and operational processes, ensuring that risks are identified, assessed, treated and escalated appropriately.
  • Lead cyber security incident response, assurance, and risk management activities, including for suppliers, service providers, and third-party technology partners.
  • Lead internal and external audit, assurance, accreditation, and certification activities against relevant standards and assurance frameworks, including ISO/IEC 27001, NIST Cybersecurity Framework, NIST SP 800-53, Cyber Essentials Plus, CIS Benchmarks and applicable NATO security-accreditation expectations.
  • Provide guidance, mentoring, or managerial leadership, as required , to enable collaboration, capability development, and successful delivery.
  • Perform any other related duties as may be required.

3. ROLE REQUIREMENTS, QUALIFICATIONS AND EXPERIENCE

ESSENTIAL

The incumbent must have

  • A minimum requirement of a Bachelor's degree at a nationally recognised/certified University in Cyber Security, Information Security, Computer Science, Information Technology, Engineering, Digital Forensics, Networks, or a closely related technical discipline and 3 years post-related experience OR exceptionally, the lack of a university degree may be compensated by at least 10 years extensive and progressive expertise in duties related to the function of the post.
  • A minimum of 3 years professional experience in cyber security, cloud security, security architecture, information assurance, or related technology-security roles.
  • A recognized cyber security qualification (e.g. CISSP, CCSP, CCSK, or equivalent).
  • Enterprise or security architecture qualifications (e.g. TOGAF or equivalent).
  • Proven experience working in government, defence, law-enforcement, national security, critical infrastructure, NATO, or equivalent high-assurance sectors handling sensitive, regulated or classified information.
  • Proven experience leading cyber security governance, risk management, assurance, security accreditation, audit, and control validation activities, including the application of recognised security standards, frameworks and principles.
  • Proven experience in taking an organisation through ISO 27001 certification and other benchmarks such as Cyber Security Plus.
  • Proven experience designing, implementing, securing, and assuring enterprise cloud and digital technology environments, particularly Microsoft Azure and Microsoft 365, including identity and access management, endpoint security, network security, monitoring and vulnerability management.
  • Demonstrable experience assessing and managing cyber security risks across cloud services, SaaS platforms, suppliers, infrastructure, enterprise technologies, and business change initiatives.
  • Experience providing disciplinary, project, or functional leadership, including setting priorities, managing resources, and delivering results through others.
  • Possess the following minimum levels of NATO's official languages (English/French): V (Advanced") in one; and I (Beginner") in the other.

NOTE: Most of DIANA's internal work is conducted in the English language.

DESIRABLE

The following would be considered an advantage

  • A relevant postgraduate qualification, such as an MSc in Cyber Security, Information Security, Computer Science, Engineering, Digital Forensics, Artificial Intelligence, Cloud Computing, Risk Management, or a closely related discipline.
  • Experience implementing advanced security technologies and capabilities, such as cloud security tooling, security monitoring and detection platforms, security automation, DevSecOps, AI governance, or enterprise security architecture.
  • Knowledge of NATO institutional framework, policies and procedures.

COMPETENCIES

  • The incumbent must demonstrate:
  • Organizational and Environmental Awareness: Understands the wider mission and considers the impact of their actions on others.
  • Initiative & Responsibility: Takes ownership and accountability .
  • Adaptability & Flexibility: Embraces change, adjusts priorities as needed, and continues to deliver results in evolving environments.
  • Impact & Influence: Builds trust and buy in through confident and persuasive communication.
  • Stakeholder Management: Builds strategic relationships and drives collaborative outcomes.
  • Leading & Developing Other: Leads and develops others through coaching, empowerment, and feedback.
  • Self-awareness and a Learning Mindset: Seeks opportunities to learn, reflects on experience, and applies learning to improve outcomes.

4. WHAT WE OFFER

  • Genuinely meaningful work as part of the newest unit within the most successful alliance in history.
  • Tax-free salary.
  • Household and children's allowances and privileges for expatriate staff including expatriation and educational allowances (where applicable) and additional home leave.
  • Excellent private health insurance scheme.
  • NATO pension scheme.
  • Generous annual leave of 30 days plus official holidays.
  • Flexible working conditions and a smoke-free office in London.
  • Opportunities for learning and development.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Incident command & response
  • Digital forensics & cybercrime
  • Multi-agency & police liaison
  • Risk & threat assessment
  • Working to legislation & regulation

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your experience managing operational risk and leading incident reviews translates directly into shaping security culture and resilience.

    Posted 2 days ago

  • Information Security Analyst

    Europa Worldwide Group · London

    Full-time

    £40,000 – £45,000Estimated

    Your experience managing evidence, compliance, and risk under ISO standards translates directly into this security assurance role.

    Posted 2 days ago

  • Cyber Security & Compliance Analyst

    Shivom Consultancy Ltd · London

    Full-time

    Your incident management, evidence handling, and risk assessment from policing transfer directly to this role.

    Posted 2 days ago

  • £570 a dayEstimated

    Your experience managing security incidents and coordinating multi-agency responses transfers directly to this governance role.

    Posted 2 days ago