Cybersecurity Lead
Indexed description
- Own and maintain baseline cybersecurity policies, standards and minimum security controls applicable across Town Councils and EM Group where applicable.
- Translate cybersecurity expectations into practical standards that can be implemented by IT Officers and vendors across varying Town Council environments.
- Define and maintain cybersecurity governance artefacts, such as control checklists and compliance reporting templates, to support consistent implementation and auditability.
- Provide guidance on cybersecurity requirements that can be embedded into IT tenders and vendor scopes, including incident response obligations, security monitoring expectations and baseline configurations.
- Coordinate incident response protocols and act as the escalation point for cybersecurity events affecting EM and Town Council-related operations.
- Establish and maintain incident response runbooks, escalation paths and communication templates aligned to vendor operating models.
- Lead cybersecurity incident triage, containment coordination and post-incident reviews, including recommendations for remediation and prevention of recurrence.
- Coordinate with external incident response providers to ensure timely mobilisation, clear handover and effective delivery during major incidents.
- Advise on cybersecurity compliance expectations, including risk assessments, gap analysis and remediation planning.
- Maintain a consolidated view of cybersecurity risks and recurring control gaps across Town Councils to inform prioritisation and uplift planning.
- Support Town Councils and IT Officers in preparing evidence and responding to cybersecurity audits, reviews and governance queries.
- Support IT Officers in implementing security controls and conducting awareness initiatives, including coaching and technical guidance on baseline controls such as identity security, endpoint hygiene, access governance and incident reporting discipline.
- Define a structured approach for cybersecurity awareness and uplift across on-site colleagues, leveraging practical scenarios and recurring lessons from incidents.
- Partner with the IT Service Delivery Manager to ensure cybersecurity policies are operationalised through standard service processes, ticketing, change discipline and escalation governance.
- Liaise with vendors to ensure alignment on cybersecurity expectations, reporting and incident coordination.
- Participate in vendor governance on cybersecurity-related matters, ensuring vendors understand and meet required security baselines and incident response obligations.
- Provide cybersecurity input into service reviews, tender specifications and scope discussions where cybersecurity responsibilities and boundaries require clarification.
- Where applicable, lead or co-lead EMHQ cybersecurity programme planning, including group-level governance, awareness, incident readiness and capability development.
- Build and mature cybersecurity operating rhythms, such as quarterly posture reviews, incident simulations/tabletop exercises and periodic control uplift campaigns, to improve resilience over time.
- Degree in Cybersecurity, Information Security, Computer Science, Information Technology or a related discipline.
- At least 7 years of experience in cybersecurity, cyber governance, incident response or security operations, including ownership of security programmes, cybersecurity awareness initiatives and incident coordination.
- Hands-on experience developing security policies and standards and translating them into implementable controls across multi-site or multi-entity environments.
- Proven experience coordinating cybersecurity incidents with internal stakeholders and external service providers or vendors.
- Experience operating in regulated, public-facing or multi-stakeholder environments is highly desirable.
- Strong knowledge of cybersecurity governance, policies, standards and security controls.
- Experience in cybersecurity risk assessments, gap analysis and remediation planning.
- Knowledge of incident response, triage, containment and post-incident review processes.
- Experience working with cybersecurity vendors and external service providers.
- Ability to develop security awareness programmes and practical cybersecurity guidelines.
- Cybersecurity Leadership & Ownership – Takes accountability for cybersecurity posture, readiness and outcomes.
- Governance & Structure – Able to define standards, controls, evidence and assurance processes across multiple entities.
- Incident Command & Calm Execution – Able to lead triage, escalation and coordination under pressure.
- Stakeholder & Vendor Management – Effective communicator across Town Councils, vendors and coordinating stakeholders.
- Pragmatism & Risk-Based Judgement – Balances security requirements with operational realities and prioritisation.
- Enablement Mindset – Coaches IT Officers and operational teams to implement controls consistently.
At EM Services, we deliver integrated facilities management and maintenance solutions that keep buildings, infrastructure and communities operating safely and efficiently. Our people are at the heart of everything we do, ensuring reliable service and operational excellence every day.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search