Senior Associate – Cloud and Platform Assurance Specialist
London, England, United Kingdom · Hybrid
$53k–$75k/yr
Senior
Senior Associate – Cloud and Platform Assurance Specialist Division: Operations Department: Cyber & Information Resilience (C&IR) Salary: National (Edinburgh and Leeds) ranging from £53,000 to £69,000 and London from £59…
Skills: Cloud security, Microsoft Azure, AWS, SaaS security, CSPM
Job Title: Senior Capital Markets Policy Advisor Division: Infrastructure & Exchanges Department: Capital Markets Salary: National (Edinburgh and Leeds) ranging from £53,800 to £64,000 and London £59,200 to £70,000 (sala…
Senior Associate Assistant Private Secretary to the Executive Director of Authorisations
London, England, United Kingdom · Hybrid
$52k–$75k/yr
Senior
Job Title: Assistant Private Secretary (APS) to either the Executive Director (ED) of Authorisations or the Chief Operating Officer (COO) Division: Authorisations/Operations Salary: London from £59,200 to £75,000 per ann…
Skills: Stakeholder management, Briefing preparation, Organizational skills, Prioritization, Time management
Lead Speechwriter Division: Communications Department: Strategic Communications and News Salary: National (Edinburgh and Leeds) ranging from £49,000 to £65,000 and London from £54,000 to £70,000 (salary offered will be b…
Skills: Speechwriting, Strategic communications, Stakeholder management, Storytelling, Tone of voice
Job title: Operational and Cyber Resilience Lead Division: Supervision, Policy and Competition Department: Technology, Resilience and Cyber Salary: National (Edinburgh and Leeds) ranging from £60,700 to £80,766 and Londo…
FCA Financial Services Consumer Panel Vacancies for Panel Members Help shape the future of financial services regulation in the UK. We are seeking experienced individuals who can bring an independent consumer perspective…
Job title: IOSCO Associate Division: Supervision, Policy and Competition Department: International Salary: National (Edinburgh and Leeds) ranging from £43,100 to £50,000 and London £47,300 to £55,000 per annum (Salary of…
Skills: Stakeholder management, International engagement, Policy development, Regulatory analysis, Communication skills
Business Operations Analyst – Capabilities & Controls Team
Leeds, England, United Kingdom · Hybrid
$54k–$69k/yr
Mid level
Job Title: Business Operations Analyst – Capabilities & Controls Team Division: Authorisations Department: Register & Authorisations Services Salary: National (Edinburgh and Leeds) ranging from £53,800 to £62,733 and Lon…
Skills: Governance, Risk management, Controls, Quality assurance, Business improvement
Regulatory Lawyer – 12 months fixed term contract (maternity leave cover) Division: Legal Division Department: Payment Systems and Competition Salary: National (Edinburgh and Leeds) ranging from £60,900 to £81,000 per an…
Crypto Policy Implementation Manager Division: Supervision, Policy and Competition Department: Payments & Digital Assets Directorate Salary: National (Edinburgh and Leeds) ranging from £74,900 to £88,900 and London £82,3…
Job title: Business Change Manager Division: Change Directorate Department: Supervision, Policy and Competition (SPC) and Authorisations (Auths) Change department Salary: National (Edinburgh and Leeds) ranging from £59,4…
Skills: Business change management, Stakeholder management, Leadership, Agile, Waterfall
Job Title: ServiceNow Technical Architect Division: Data Technology and Innovation Department: Core Technology Salary: National (Edinburgh and Leeds) ranging from £74,900 to £85,000 and London from £82,300 to £95,000 per…
Job Title: Senior Data Analyst – Consumer Credit Division: SPC Department: Consumer Finance Salary: National (Edinburgh and Leeds) ranging from £53,800 to £68,400 and London from £59,200 to £75,000 (salary offered will b…
Skills: SQL, Python, Data Analysis, Data Visualization, Stakeholder Management
Job Title: Technical Lead Division: Data Technology and Innovation Department: Digital Delivery Hub Salary: National (Edinburgh and Leeds) ranging from £74,900 to £105,000 and London from £82,300 to £115,000 per annum (s…
Job Title: AI Benefits & Value Technical Specialist Division: Data, Technology and Innovation Department: AI Product Development Salary: National (Edinburgh and Leeds) ranging from £74,900 to £85,700 and London from £82,…
Skills: Benefits Management, Business Change, Stakeholder Engagement, Value Realisation, Communication Strategy
Executive Assistant Division: Operations Department: Change Directorate Salary: National (Edinburgh and Leeds) ranging from £43,300 to £54,000 and London £46,400 to £58,000 (salary offered will be based on skills and exp…
Skills: Stakeholder Management, Organizational Skills, Diary Management, Strategic Coordination, Written Communication
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
$53k–$75k/yr
Full-time
Annual leave, Bank holidays, Non-contributory pension, Life assurance, Private healthcare, Income protection
Posted 1d ago
Apply by Aug 24
~35 hrs/week
Responsibilities
The role involves providing independent security assurance across cloud-hosted and SaaS services, focusing on control effectiveness and risk-based remediation. You will act as a subject matter expert to guide cloud architecture design and validate security findings across various platforms.
Requirements
Candidates must have strong technical security knowledge of at least one major public-cloud platform, preferably Microsoft Azure, and experience in conducting risk-based security assurance. Essential qualifications include familiarity with security frameworks like NIST and CIS, along with the ability to translate technical risks for senior stakeholders.
Full job description
Senior Associate – Cloud and Platform Assurance Specialist
Division: Operations Department: Cyber & Information Resilience (C&IR)
Salary: National (Edinburgh and Leeds) ranging from £53,000 to £69,000 and London from £59,000 to £75,000 (salary offered will be based on skills and experience)
This role is graded as: Senior Associate - Regulatory
Applications must be submitted through our online portal.
Applications sent via social media or email will not be accepted.
About the FCA and team
We regulate financial services firms in the UK, to keep financial markets fair, thriving and effective. By joining us, you’ll play a key part in protecting consumers, driving economic growth, and shaping the future of UK finance services.
We are recruiting a Senior Associate – Cloud and Platform Assurance Specialist to join the Platform Assurance team within Cyber & Information Resilience.
The role will provide independent security assurance across the FCA’s cloud-hosted and SaaS services, with a particular focus on public-cloud security, Cloud Security Posture Management, SaaS Security Posture Management and cloud control effectiveness.
This role is positioned at Senior Associate level and is suited to an experienced security professional with solid technical knowledge of at least one major public-cloud platform, ideally Microsoft Azure and the ability to apply assurance principles consistently across Azure, AWS, SaaS and other cloud-hosted services.
You will combine architectural understanding with an assurance-led mindset, independently reviewing control design and effectiveness, validating security findings and helping platform and engineering teams make proportionate, risk-based remediation decisions. The position will remain independent from the ownership and implementation of the controls it assesses.
Although cloud assurance will be the principal focus, the role may also support assurance across identity, network, endpoint, secure software development and wider platform controls where these intersect with cloud services.
Role responsibilities
Acting as a cloud assurance SME, providing self-directed feedback and guidance on cloud architecture, control design, implementation and effectiveness, while reviewing cloud architectures, data flows, trust boundaries and control dependencies to identify material design weaknesses, systemic control gaps and unmanaged exposure
Supporting and contributing to risk-based assurance reviews across public-cloud and SaaS services, with particular emphasis on Microsoft Azure, while applying consistent, cloud-agnostic assurance principles.
Providing assurance over CSPM, CNAPP, SSPM and related exposure-management capabilities, including assessing coverage, configuration, findings, exceptions, risk prioritisation and remediation outcomes, and validating whether identified exposures represent genuine risk through root-cause analysis and assessment of underlying control effectiveness.
Assessing cloud security controls, baselines, policies and guardrails across identity and privileged access, network security, workload protection, configuration management, data protection, logging and monitoring, vulnerability management and resilience, ensuring appropriate and consistent control coverage.
Working collaboratively with cloud platform owners, engineering teams, security teams and service owners to agree pragmatic remediation, validate compensating controls and support proportionate risk-based decisions.
Supporting assurance activities across broader cyber security domains, including identity, network, endpoint security and secure software delivery controls, where these underpin cloud services or cloud-hosted workloads
Producing clear, evidence-based assurance conclusions, metrics, KPIs and KRIs for management and risk forums, covering control effectiveness, exposure, remediation and residual risk
Contributing to the continuous improvement of cloud assurance methodologies, standards, testing approaches and tooling, aligned with relevant NCSC, NIST, CIS and CSA guidance
Monitoring developments in cloud technologies, threat patterns and security practices, assessing their relevance to the FCA's cloud risk profile and assurance approach.
Skills required
Minimum:
Strong technical security knowledge of at least one major public-cloud platform, ideally Microsoft Azure, with practical experience across identity and access management, privileged access, network security, workload and data protection, configuration governance, logging and monitoring, vulnerability management, and resilience.
Demonstrable experience independently assessing cloud architectures and security controls, including evaluating control design, implementation, and operating effectiveness, while remaining independent from ownership or implementation of the controls being assessed.
Experience leading or conducting end-to-end, risk-based cloud security assurance activities, including scoping, evidence gathering, control testing, reporting findings, making remediation recommendations, and validating that actions have been completed effectively.
Practical experience using or assuring CSPM, CNAPP, SSPM or comparable cloud security posture and exposure-management capabilities, including validating findings, assessing coverage, identifying root causes, and distinguishing isolated issues from wider systemic control weaknesses.
Strong communication and stakeholder-management skills, with the ability to translate technical issues into clear business and security risks, produce concise assurance conclusions and constructively challenge technical teams, control owners, and senior stakeholders
Essential:
Experience evaluating cloud security baselines, policies, guardrails, exceptions, and compensating controls, including identifying gaps in configuration governance and control implementation.
Strong knowledge of recognised security and assurance frameworks, with experience applying standards such as NCSC guidance, the NIST Cybersecurity Framework, CIS Benchmarks, and the CSA Cloud Controls Matrix.
Experience applying cloud security and assurance principles across Azure, AWS, SaaS, hybrid or other cloud-hosted services, including identifying control inconsistencies, shared-responsibility gaps and duplicated or unclear ownership between environments.
Experience assessing material cloud exposures, including attack paths, excessive permissions, toxic combinations, and risks introduced through cloud-native delivery, infrastructure as code, CI/CD pipelines, containers, or platform-engineering controls.
Experience working in a regulated or similarly complex environment, with the ability to contribute to cloud-assurance methodologies and produce meaningful metrics, KPIs or KRIs covering control effectiveness, security exposure, assurance coverage, and remediation progress
Benefits
25 days annual leave plus bank holidays
Non-contributory pension (8–12% depending on age) and life assurance at eight times your salary
Private healthcare with Bupa, income protection, and 24/7 Employee Assistance
35 hours of paid volunteering annually
Hybrid model where employees work a minimum of 40% in the office each month (expectation of 50% for senior leaders). Changing from September to a minimum of 50% in the office each month (expectation of 60% for Directors and Executive Directors)
A flexible benefits scheme designed around your lifestyle
For a full list of our benefits, and our recruitment process as a whole visit our benefits page.
Our values and culture
Our colleagues are the key to our success as a regulator. We are committed to fostering a diverse and inclusive culture: one that’s free from discrimination and bias, celebrates difference, and supports colleagues to deliver at their best. We believe that our differences and similarities enable us to be a better organisation – one that makes better decisions, drives innovation, and delivers better regulation.
If you require any adjustments due to a disability or condition, your recruiter is here to help - reach out for tailored support.
We welcome diverse working styles and aim to find flexible solutions that suit both the role and individual needs, including options like part-time and job sharing where applicable.
Disability confident: our hiring approach We’re proud to be a Disability Confident Employer, and therefore, people or individuals with disabilities and long-term conditions who best meet the minimum criteria for a role will go through to the next stage of the recruitment process. In cases of high application volumes we may progress applicants whose experience most closely matches the role’s key requirements.
Useful information and timelines
Timeline:
Job advert closes: Midnight, 23rd August 2026
CV Review/Shortlist: 25th August 2026
Interview: w/c 31 August 2026
Your Recruiter will discuss the process in detail with you during screening for the role, therefore, please make them aware if you are going to be unavailable for any date during this time.
SC Clearance is required for this role (SC Guidance) - you will hold or will be required to obtain Security Check (SC) level vetting
Related keywords
Cloud SecurityPlatform AssuranceCyber ResilienceMicrosoft AzureAWSSaaSCSPMCNAPPSSPMNCSCNISTCIS BenchmarksCSA Cloud Controls MatrixIdentity and Access ManagementInfrastructure as CodeCI/CD
We enable a fair and thriving financial services market for the good of consumers and the economy.
Industry
Financial Services
Company size
1,001-5,000 employees
Founded
2013
Headquarters
Stratford, London
LinkedIn followers
445,097
We enable a fair and thriving financial services market for the good of consumers and the economy.
We do this by:
- Regulating the conduct of approximately 50,000 businesses
- Prudentially supervising 48,000 firms
Our Head Office is based in London, and we have offices in Edinburgh and Leeds.
Firms and individuals must be authorised or registered by us to carry out certain activities. Before we grant authorisation, firms must demonstrate that they meet a range of requirements. We then supervise these firms to make sure they continue to meet our standards and rules after they’re authorised. If firms and individuals fail to meet these standards, we have a range of enforcement powers we can use.
We enable a fair and thriving financial services market for the good of consumers and the economy.
Industry
Financial Services
Company size
1,001-5,000 employees
Founded
2013
Headquarters
Stratford, London
LinkedIn followers
445,097
We enable a fair and thriving financial services market for the good of consumers and the economy.
We do this by:
- Regulating the conduct of approximately 50,000 businesses
- Prudentially supervising 48,000 firms
Our Head Office is based in London, and we have offices in Edinburgh and Leeds.
Firms and individuals must be authorised or registered by us to carry out certain activities. Before we grant authorisation, firms must demonstrate that they meet a range of requirements. We then supervise these firms to make sure they continue to meet our standards and rules after they’re authorised. If firms and individuals fail to meet these standards, we have a range of enforcement powers we can use.