Lead Cyber Security Risk Manager
Crown Prosecution Service · Wales, England
Lead Cyber Security Risk Manager at Crown Prosecution Service, based in Wales, England, paying £58,330 - £73,520 per annum. This is a permanent role.
- Salary
- £58,330 - £73,520 per annum
- Location
- Wales, England
- Contract
- Permanent
- Posted
- 13 hours ago
- Closes
- 3 Sep 2026
- Sector
- Security Officer
About 31% above the going rate for security officer
Reference 57260b45890443c7cad977595476081857548c96
About the role
Job summary
This is a senior cyber security leadership role at the heart of protecting the Crown Prosecution Service’s people, information, systems and public trust. As Lead Cyber Security Risk Manager, you will play a critical role in strengthening the CPS’s cyber resilience, ensuring that security risks are understood, managed and embedded into the way the organisation delivers its services.
You will lead the development and implementation of effective cyber security risk management strategies, provide expert advice and assurance across major change and transformation programmes, and help ensure that security requirements are built in from the outset. This includes supporting strategic initiatives such as the replacement of the Case Management System, where cyber risk, compliance and resilience will be central to successful delivery.
Working closely with senior leaders, Information Asset Owners, digital teams, government partners and external bodies, you will provide constructive challenge, clear guidance and practical solutions that enable the CPS to make balanced, risk-based decisions. You will also play a key role in shaping cyber security policies, improving organisational awareness, and promoting a positive security culture across the CPS.
The role requires strong judgement, technical credibility and the ability to translate complex cyber risks into clear recommendations for senior stakeholders. You will need to be confident operating in a complex environment, responding decisively to incidents, and ensuring that controls, standards and assurance activities remain effective against an evolving threat landscape.
This is an excellent opportunity for an experienced cyber security risk professional who wants to lead, influence and make a tangible contribution to the security, resilience and integrity of a nationally important public service.
The Crown Prosecution Service is based in England and Wales. If you’re applying for this role and live in Scotland or Northern Ireland, you must let us know when accepting this offer as you need permission to work from your home address if hybrid working is part of your role. There’s no guarantee that we will grant this approval.
You must be aged 16 or over at the point of starting in this role. The expected start date is approximately 8–12 weeks after the application closing date. Candidates are expected to commence employment as soon as possible following the expiry of their notice period. Requests for significantly later start dates may not be accommodated.
As part of this role, you are expected to undertake direct line management responsibilities.
Job description
Your roles and responsibilities
- Provide independent cyber security assurance across CPS services, programmes and major transformation initiatives, ensuring risks are identified, controls are effective, and security requirements are embedded throughout the delivery lifecycle.
- Lead the assessment, reporting and oversight of cyber security risks across the organisation, providing expert advice and constructive challenge to enable informed risk-based decision making.
- Develop and maintain cyber security policies, standards and assurance frameworks, ensuring compliance with government security requirements, legislation and recognised industry standards.
- Provide assurance to senior leaders, governance boards and Information Asset Owners on the effectiveness of cyber security controls, resilience measures and risk mitigation activities.
- Lead the review of cyber security incidents, emerging threats and areas of non-compliance, ensuring lessons identified are translated into improvements that strengthen the CPS security posture.
A copy of the full job description is attached.
Person specification
To be eligible to apply, you need to:
- Have substantial experience leading cyber security risk, assurance or governance functions within a large, complex organisation, with responsibility for identifying, assessing and managing cyber security risk at an enterprise level.
- Demonstrate experience of providing independent cyber security assurance, constructive challenge and expert advice to senior leaders, governance boards and major business change or digital transformation programmes.
- Possess a strong understanding of cyber security frameworks, standards and regulatory requirements, including government security standards, NIST, ISO 27001, the Cyber Assessment Framework (CAF), and data protection legislation.
- Have experience of developing and implementing cyber security policies, control frameworks, assurance activities and risk management processes that support organisational compliance and resilience.
- Ideally hold, or be working towards, a recognised cyber security, risk management or information assurance qualification (such as CISSP, CISM, CRISC or equivalent) and have experience leading and influencing multidisciplinary teams and stakeholders.
Behaviours
We'll assess you against these behaviours during the selection process:
- Managing a Quality Service
- Making Effective Decisions
- Developing Self and Others
- Leadership
Benefits
Alongside your salary of £58,330, Crown Prosecution Service contributes £16,898 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).Join the Crown Prosecution Service and find your purpose.
The Crown Prosecution Service is passionate about ensuring that we're a top performing organisation and a great place to work. We're a committed equal opportunities employer, creating a culture where you can bring your whole self to work, and individuality is truly appreciated.
This culture of inclusion is underpinned by our staff networks covering disability, faith and belief, LGBTQI+, race, social mobility alongside our mental health first aiders programme and wellbeing sessions.
The Crown Prosecution Service commits to offer its employees the following experience.
- You can do impactful, purposeful work that’s making a difference to your local communities.
- You are able to learn and grow, with access to the right opportunities and resources.
- We care about your wellbeing.
- We want you to feel valued, trusted and included.
We also offer the following range of benefits:
- Civil Service contributory pension of up to 28.9%
- 25 days’ leave, increasing to 30 days after 5 years
- £350 each year to spend on personal development
- lawyer training programme for all new prosecutors
- an extra privilege day to mark the King's birthday
- competitive maternity, paternity and parental leave
- flexible working including flexitime, and a family friendly approach to work
- Cycle2Work scheme, employee savings.
Diversity at the Crown Prosecution Service is about inclusion, embracing differences and ensuring our workforce truly reflects the communities we serve. We want you to feel that you belong and can thrive, whatever your background, identity or culture. As a Disability Confident employer, we're happy to support requests for reasonable adjustments and improve your recruitment experience. If you'd like any reasonable adjustments made to our recruitment process, let us know within your application or contact [email removed]
We want to ensure our employees can thrive at work and home and offer a range of support to achieve a balance. This includes flexibility of working hours, flexibility to s
Reference: 57260b45890443c7cad977595476081857548c96 · Posted 13 hours ago · Closes 3 Sep 2026 · Listed via Crown Prosecution Service
Apply for this job
This role is listed via Crown Prosecution Service. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.