Defence Business Services (DBS) - DDaT ITMS Cyber Security Assurance and Risk Assessor
Ministry of Defence · Thornton-Cleveleys, England
Defence Business Services (DBS) - DDaT ITMS Cyber Security Assurance and Risk Assessor at Ministry of Defence, based in Thornton-Cleveleys, England, paying £61,630 - £67,750 per annum. This is a permanent role.
- Salary
- £61,630 - £67,750 per annum
- Location
- Thornton-Cleveleys, England
- Contract
- Permanent
- Posted
- 3 days ago
- Closes
- 3 Aug 2026
- Sector
- Lecturer
About 56% above the going rate for lecturer
Reference 9648d6cb7b64f421f5b8278351c7b79f2e299f8c
About the role
Job summary
Are you a dedicated person who is passionate about making a difference?
Would you like to work for the Ministry of Defence?
Defence Business Services (DBS) is one of the largest shared service organisations in Europe that provides a wide range of corporate services, to over 1.2 million end users, including serving and past military and families, as well as MoD civil servants and industry. DBS delivers large scale administration and smaller specialist services to enable the wider MOD to focus on its core aims, maintaining the UK’s Defence and Security. Services include Human Resources, Pay, Veterans, Finance and Procurement.
- Our Vision - To support UK defence customers with outstanding service every time.
- Our Mission – Together we will proudly support Defence, continuously improving and delivering flexible, timely, sustainable and value for money services that underpin the whole force and enhance operational capability.
DBS is committed to creating a great place to work for all our colleagues. We are building an inclusive culture and respectful environment that reflects the diversity of the society.
We want to maximise the potential of everyone who chooses to work for us through opportunities to develop your skills and experience. We also offer a range of flexible working patterns and support to make a fulfilling career accessible to you and offer a Civil Service pension with an average employer contribution of 28.97%. Where your role permits, we support a blended working approach alternatively known as hybrid working.
Where business needs allow, some roles may be suitable for a combination of office and home-based working. This is a non-contractual arrangement where all office-based employees will be expected to spend a minimum of 60% of their working time in office, subject to capacity and any required workplace adjustments. Requirements to attend other locations for official business, or work in another MOD office, will also count towards this level of attendance. Applicants can request further information regarding how this may work in their team from the Vacancy Holder (see advert for contact details). Defence Business Services cannot respond to any questions about working arrangements.
Come and join the DBS community today!
Job description
DBS DIT provides digital capability that supports corporate services across the Ministry of Defence, including Finance, Commercial, Payroll and Human Resources for Military Personnel, Civilian Personnel and Veterans. Cyber Security Assessors are responsible for independent assessment of Delivery Teams’ adherence to Secure by Design and the NCSC Cyber Assurance Framework, relevant risk and security policies and standards. They coordinate between Delivery Teams dealing with similar security challenges to optimise solutions and minimise duplication of effort. They are responsible for consistent, coherent advice and support to relevant capabilities. They identify, understand and mitigate cyber-related risks. They provide risk or service owners with advice to help them make well informed risk-based decisions.
As Cyber Security Assurance and Risk Assessor within the DBS Cyber Team you will manage all day to day IT Security and System Information Assurance, and, applying Secure by Design, ensure that security is embedded in all stages of the application development life cycle, and that there is continuous monitoring through use. You will also advise on and test the efficacy of measures to build security into continuous integration and deployment with specific responsibilities for the day to day IT security for multiple Military and Civilian HR systems and Finance systems. The role will require you to demonstrate a talent for solving complex problems and for effective communication at all levels. You will be able to advise on complex risk balance decisions, propose innovative solutions and to explain MOD’s security policy, governance and technology controls to non-IT/security experts. Senior Responsible Owners and Project Leads will rely on your expertise to ensure they have an accurate understanding of through-life cyber security risks, so they can make informed decisions. Projects may involve complex technical and security challenges and you will need a good understanding of technical controls and policy.
The Key Responsibilities are:
- Lead the embedment of Secure by Design (SbD) principles into application development by providing advice and internal consultancy on highly complex criteria and contexts for multiple systems.
- Lead multi-team assessment of application resilience throughout the DBS IT estate, reviewing regular application security reports, holding accountability and responsibility for secure design implementation; supporting delivery of main gate assurance of all projects and changes; ensuring compliance with Information Assurance Policy and Security Principles
- Lead and assure processes, and provide specialist advice though leadership on tooling and dynamic and static analysis in the product development life cycle.
- Work with Delivery Team Security Leads (previously Security Assurance Co-ordinator (SACs)) and Cyber Risk Leads alongside senior decision makers to embed secure development life cycle and security awareness.
As a Principal Cyber Security Risk Manager, you will:
- Conduct cyber security risk assessments
- Implement continuous risk management; Lead and undertake risk management activities against the hardest or more novel scenarios, while applying the fundamental principles of risk management to a range of complex scenarios and lead regulatory or legislative compliance activities.
- Guide and direct specialist activities or others, actively promoting development in the applicable skills, providing leadership and sharing best practice widely across government, the public sector, and industry.
- Lead the analysis and derivation of complex security needs.
- Lead Cyber Security related risk assessments and other expert risk management activities, including providing guidance on establishing the organisation’s Cyber Security related governance arrangements.
- Provide guidance to ensure on-going confidence that fundamental organisational security needs have been met, including integrating a range of assurance approaches and techniques to give continued confidence to the risk, service or system owner.
- Shape leadership decision-making through
- Effective reporting and communication regarding the effectiveness of security processes across an organisation
- Providing recommendations to highly complex problems
- Acting as an SME for complex cyber risk management concerns, issues and problems
Person specification
- Knowledge/experience of implementing Secure by Design Principles.
- Knowledge and experience of risk management
Desirable Qualification
CISSP/CISM would be considered an advantageous qualification to hold
Behaviours
We'll assess you against these behaviours during the selection process:
- Seeing the Big Picture
- Making Effective Decisions
- Developing Self and Others
Technical skills
We'll assess you against these technical skills during the selection process:
- Government Security Professions Career Framework
Benefits
Alongside your salary of £61,630, Ministry of Defence contributes £17,854 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).- <
Reference: 9648d6cb7b64f421f5b8278351c7b79f2e299f8c · Posted 3 days ago · Closes 3 Aug 2026 · Listed via Ministry of Defence
Apply for this job
This role is listed via Ministry of Defence. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.