Skip to content
// ← EVERY SEATTHE FUNCTIONS

Cyber Security Analyst

Defends the bank and its customers against people who are actively trying to take money or data.

// 01 — THE WORK

Monitoring, detection, response and the unglamorous half — access, patching, third parties and the controls that stop an incident being a headline. The adversary here is funded and persistent, and the regulator expects the bank to be able to prove what it did and when.

// 02 — WHO ARRIVES HERE

Security, networking and infrastructure backgrounds, technology graduates, and people from defence and intelligence.

// 03 — WHAT THE INTERVIEW ASKS

These are the shapes the round takes, not a question bank — banks phrase them differently and the wording is never the point.

  1. 01You see this alert. What are your first three steps?
  2. 02How would you attack us?
  3. 03How do you decide what to patch first?
  4. 04Explain an incident to an executive in two minutes.
  5. 05How do you secure something you do not control, like a vendor?
  6. 06What is the difference between compliant and secure?

What the panel is listening for. Prioritisation under incomplete information, and whether you can communicate urgency without losing accuracy.

// 04 — WHY CREDIT PAYS IN THIS SEAT

The bank's largest concentrated exposures are its own systems and its vendors; the same question a lender asks about a borrower — what happens if this stops — is the question that ranks the work here.

That is the general case as well as this one. A bank's technology is not ordinary technology and its finance is not ordinary finance, and the second and third lines of defence — risk, compliance, financial crime, model validation and internal audit — recruit heavily out of the functions, taking the people who can already read a business. The case drills are free and are the cheapest way to build that, whichever column you sit in.

// ALSO IN THE FUNCTIONS

The whole board, and how the four blocks fit together, is on what jobs banks hire for.