Jobs at LINK
Jobs at LINK
Location
Hybrid Working, with a minimum of one day a week in the Head Office located in Harrogate, North Yorkshire.
Candidates must be within reasonable commuting distance of Harrogate.
Contract Length
Permanent
Who we are
LINK is a not-for-profit company governed by an independent Board and is the UK's largest cash machine network, connecting virtually all the UK’s ATMs and providing communities with access to cash through services such as cashback at retailers’ tills and Banking Hubs. While many consumers are now embracing digital payments, there are still millions of people who rely on cash every day. At LINK, we are passionate about protecting access to cash on the UK’s High Streets and ensuring it is maintained for as long as it is needed through the operation of our well-established Financial Inclusion Programme. LINK is regulated by the Payments Systems Regulator and the Bank of England and have a great track record of delivering results for communities.
What does the role involve?
The Cyber Security Manager will support the continued security, resilience and trust of the LINK Scheme by providing cyber security and risk oversight of critical third parties and Scheme Members. The role will assess cyber security risks, review the effectiveness of controls, monitor remediation activity and ensure that reporting is timely, accurate and suitable for informed decision-making. The postholder will provide specialist advice and constructive challenge to third parties, Scheme Members and internal stakeholders, helping to identify and manage risks that could affect LINK’s assets, data, services or Scheme operations. Working collaboratively across the Information Security and Technology team and other business areas, the Cyber Specialist will contribute to effective governance, assurance, regulatory engagement and the ongoing development of LINK’s cyber security and operational resilience arrangements.
This role is responsible for:
- The Cyber Security Manager’s primary responsibility is to provide cyber security and risk oversight of LINK’s critical third parties and Scheme Members. The role will focus on ensuring that critical third parties provide timely, accurate and actionable reporting on security, resilience, incidents, control performance, remediation and emerging risks. It will also provide subject matter expertise to support the oversight of Scheme Membership compliance with required cyber security, operational resilience and control obligations, supporting the continued security, resilience and trust of the LINK Scheme.
- The role is responsible for developing, maintaining and improving the oversight framework for critical third party cyber security risk and Scheme Member control compliance. This includes risk assessment methods, reporting requirements, control evaluation approaches, assurance evidence, key risk indicators, escalation routes, governance packs and management information to support effective oversight by management, Risk and Audit Committees and the Board.
- As part of a relatively small team, the individual will operate across governance, risk, assurance, third party oversight and Scheme Member engagement. The role sits within the Information Security and Technology Team and reports to the Head of Department. It will work closely with Operational Risk, Second Line Risk, Legal, Operations and Scheme governance stakeholders to ensure critical third parties and Member oversight is aligned with the Enterprise Risk Management Framework and Scheme obligations.
- The individual will lead oversight of cyber security risks arising from critical third parties, including service providers, infrastructure providers and other suppliers whose failure could materially affect the Scheme. This includes reviewing third party reporting, challenging control effectiveness, assessing residual risk, monitoring remediation, identifying concentration and dependency risks, and escalating material weaknesses, incidents or exceptions through the appropriate governance channels.
- The role will oversee the cyber security and risk information received from critical third parties, ensuring reports are complete, credible, risk-based and suitable for governance decision-making. This includes reporting on incidents, vulnerabilities, control failures, audit or assurance findings, resilience testing, remediation progress, service dependencies and emerging threats that may affect LINK or the wider Scheme.
- The role will provide subject matter expertise to support oversight of Scheme Membership from a cyber security and risk perspective, ensuring Members understand and comply with the controls, standards and obligations required to participate securely in the Scheme. This includes reviewing the cyber component of Member Assurance Statement returns, changes, assurance evidence, exceptions, remediation activity and risk exposure, and supporting escalation where members do not meet required standards or where risks could affect Scheme security or resilience.
- The Cyber Security Manager will support the protection of LINK’s assets, data, services and Scheme operations by ensuring cyber security risks linked to critical third parties and Scheme members are identified early, assessed consistently, managed proportionately and escalated appropriately. The role will ensure oversight outputs support internal governance, audit, external assurance, regulatory engagement and ongoing monitoring of the Scheme’s cyber security and operational resilience posture.
- The role will provide support and subject matter expertise with IS&T and relevant stakeholders on critical third party oversight, Member control compliance, cyber security risk reporting and governance escalation. It will support the setting of priorities for oversight activity and build strong relationships across first and second line teams, and Scheme governance functions.
What will I need to know?
Experience
- A minimum of five years’ demonstrable experience in information security, cyber security risk management, third-party risk, supplier assurance, operational resilience or a closely related discipline.
- Practical experience of reviewing third-party security and resilience reporting, assessing control effectiveness, monitoring remediation, producing governance reporting and engaging with senior stakeholders in regulated, critical service or financial services environments.
- Experience of payment systems, Scheme governance, member control frameworks, critical third-party oversight or critical national infrastructure would be advantageous.
- Knowledge of ISO 27001, NIST, CIS Controls or equivalent cyber security frameworks.
Education
- CIISP or CISM or similar required. Industry relevant degree desirable, Information security audit qualification also desirable.
Skills
- Strong analytical and problem-solving skills, with the ability to assess complex information and identify material risks or control weaknesses.
- Sound professional judgement and the ability to make balanced, evidence-based recommendations.
- Clear and effective written and verbal communication skills.
- The ability to explain technical cyber security issues in accessible language for non-technical and senior audiences.
- The confidence to provide constructive challenge when evidence, reporting or control performance is insufficient.
- The ability to develop positive working relationships while maintaining professional independence and objectivity.
- Strong organisational skills, with the ability to manage competing priorities and deliver high-quality work within agreed timescales.
- A collaborative approach and the ability to work effectively across organisational and professional boundaries.
- Attention to detail, combined with the ability to understand the wider business, operational and strategic context.
- The ability to produce concise, accurate and decision-focused governance reports and management information.
- A proactive approach to identifying emerging risks and opportunities to improve oversight and assurance arrangements.
- A commitment to integrity, accountability, confidentiality and professional standards.
- An inclusive approach that values different experiences, perspectives and ways of working.
- A commitment to ongoing learning and professional development.
What is in it for me?
You will be joining a not-for-profit business with a lovely working culture, and our employees are at the centre of our focus.
In addition to the base salary, LINK operates a bonus scheme and offers a wide range of employee benefits including group life and income protection, company pension scheme, private medical and dental insurance, hybrid working and learning opportunities. Our Harrogate office has an on-site café, gym, free car parking including electric charging points and bike parking facilities as well.
We will be interviewing as we receive CVs so if you are interested in this role, please apply as soon as possible.