Home Industries Financial services
FINANCIAL SERVICES & BANKING
Cyber security recruitment for financial services
Banks run the largest and most scrutinised security functions in both our markets. They also hire on the longest timelines and reject on the narrowest criteria, which means most of the work in a financial services search happens before the first CV is sent.
What these teams hire
- SECURITY OPERATIONS
- Mature, often 24/7 SOC functions with dedicated detection engineering and hunting capability.
- SECOND-LINE RISK
- Information security officers and cyber risk managers providing independent challenge to first-line security.
- REGULATORY & RESILIENCE
- Operational resilience, DORA and third-party risk specialists — the fastest-growing area of demand in UK banking.
- IDENTITY
- Large, legacy-heavy IAM and PAM estates with multi-year remediation programmes.
- FRAUD & INTELLIGENCE
- Threat intelligence and fraud analytics teams, most common in the large South African banks.
- LEADERSHIP
- CISO, deputy CISO and divisional head mandates, usually confidential.
What is different about hiring here
Financial services hiring is governed by process. Vetting, credit and criminal checks, regulatory references and internal approval gates routinely add four to six weeks after a verbal offer, and candidates who are not warned about that will accept something faster in the meantime. We manage that expectation from first contact rather than at offer stage.
The second difference is the shape of the interview. Banks assess for control mindset and audit-readiness as much as technical skill: can this person evidence what they did, defend it to a regulator, and work inside a change process they cannot bypass. Excellent engineers from product companies frequently fail that panel, and we say when a candidate is at risk of it.
The market, honestly
Supply is unusually good at analyst and risk level and thin everywhere it matters most: detection engineering, cloud security in regulated estates, and second-line officers with genuine technical depth. South African banks lose candidates to offshore remote offers; UK banks lose them to consultancies and vendors offering variety.
The other constraint is internal pay banding. Where a band cannot move, the realistic candidate is one grade below the brief with room to grow, and it is better to plan for that deliberately than to discover it in month two.
If the role requires full vetting and a six-week approval chain, tell candidates in the first conversation. It is the most common reason financial services offers are declined late.
Where we recruit
Cape Town and Johannesburg across South Africa, and London and the wider United Kingdom.
Common questions
Do you recruit for both South African and UK banks?
Yes. We work with South African banks, insurers and asset managers directly, and we place candidates into UK financial services roles from Cape Town. Regulatory context differs sharply and we brief candidates accordingly.
Which regulations shape these briefs?
In South Africa, POPIA and the Joint Standard on IT governance and risk management. In the UK, DORA, NIS2, UK GDPR and FCA and PRA operational resilience expectations. Candidates who have evidenced controls to a regulator are valued well above those who have only read the standard.
Can you handle vetted and confidential searches?
Yes. Confidential leadership mandates and vetting-heavy hires are routine for us, and we run them without advertising the role.
Do banks accept candidates from outside financial services?
Sometimes, and we push for it where the skill is scarce. It works best in engineering and detection roles and least well in second-line risk, where regulatory fluency is most of the job.
Explore further
Talk to us about your search
A short conversation is usually enough to tell you whether we can help.