Lead Cyber Security Risk Manager

Home Office · GB

Lead Cyber Security Risk Manager at Home Office, based in GB, paying £62,732 - £69,706 per annum. This is a permanent role.

Salary
£62,732 - £69,706 per annum
Location
GB
Contract
Permanent
Posted
3 days ago
Closes
4 Sep 2026
Sector
Security Officer

About 31% above the going rate for security officer

Reference f100c37ff99b53a71ce4fb5efa70bb6378ad17b8

About the role

Job summary

Are you a skilled and experienced professional, ready to lead on safeguarding digital infrastructure in a large government department?

Will you join us in embedding robust governance, risk management and compliance practices across the Home Office?

In this critical role, you will identify, understand and mitigate cyber-related risks and evaluate the risks to our critical national infrastructure and business critical systems. You will use your expertise to draw on a range of evidence to proactively advise stakeholders, enabling well-informed, risk-based decision making.

You’ll be joining an expert team of cyber professionals, committed to reducing the exposure to cyber-attack of new and existing digital systems. You’ll be aided in your role by a diverse and supportive organisational culture, and a commitment to further your continuous development.

Where business needs allow, some roles may be suitable for a combination of office and home-based working. Where this is the case, employees will be expected to spend a minimum of 60% of their working time in the office. Applicants can raise any queries to the email address at the bottom of the advert.

Watch this short video to hear from members of Home Office Digital talking about the projects they work on and their experience of working here: Working for Home Office Digital.

Job description

The Lead Cyber Risk Manager supports, plans and develops the implementation and management of organisation-wide processes and procedures for the management, assurance or governance of cyber risk.

They will provide tailored expert support and advice that highlights cyber security risks to a range of stakeholders, projects, business teams and service owners, helping them to remedy identified risks by enabling well-informed and auditable decisions, using published guidance and standards, and drawing on a range of experts as well as personal expertise.

Person specification

Main Responsibilities

  • Independently and impartially undertaking risk management activities within a given area of practice or expertise, usually within established security and risk management governance structures. You will lead the independent derivation and analysis of security needs and conduct tailored threat assessments, security audits, or other risk management activities, ensuring consistency with regulations and legislation.
  • Developing risk management-related policy and assure the ongoing appropriateness of policy in accordance with regulation and wider organisational and government policies.
  • Communicating effectively with senior stakeholders to ensure they recognise the importance of security considerations and advising senior stakeholders on their approach to risk assessment in the context of their organisational outcomes.
  • Managing risk management processes, reviewing their efficiency and effectiveness, and leading recommendations for continuous improvement. This includes reviewing internal controls following any security breach, providing advice on how to remediate any vulnerabilities discovered, and agreeing and overseeing remedial solutions, controls and safeguards.
  • Assessing reviews and risk assessments and ensuring identified risks are managed in accordance with Home Office risk management policies.
  • This role currently is responsible for leading a small team of Civil Service Cyber Risk Managers.

Working Pattern

Due to the business requirements of this role, it is only available on a full-time basis. However, compressed hours are available.

Essential Skills

  • Information or cyber security including threat and risk analysis for complex, high-risk and/or mission critical systems, preferably involving the Home Office, Cabinet Office, NCSC or within industry Security Operations Centres (SOCs) and departments.
  • Proficiency analysing or implementing technical or security policies in a large organisation. Skilled in balancing security requirements with business impact to ensure practicality and effectiveness.
  • Ability to champion cybersecurity risk and ensure ongoing appropriateness or practices.
  • Proven track record in implementing cybersecurity risk, assurance or governance processes and procedures.
  • Proven ability to lead and mentor a diverse team of governance, risk or assurance specialists.
  • Ability to design and implement security controls aligned with organisational requirements, whilst navigating changes and proactively responding to evolving risks.
  • Strong ability to present technical information to non-technical stakeholders and the ability in influencing decision-making processes at senior leadership levels, promoting security priorities.

SFIA capability framework

Skills for the Information Age (SFIA) version 8 is the technical framework that sets the standard capability and development of all levels in the Home Office. This is a link to the capability framework: All skills A - Z English (sfia-online.org).

We use set SFIA technical skills to form our interview questions and we will assess you against these technical skills during the selection process.

The essential skills listed above are reflective of the Home Office Government Digital and Data Profession Career Framework (based on the industry standard SFIA framework). Use the SFIA Levels of responsibility to understand what would be expected for each technical skills listed below.

Security and Privacy

Governance, Risk and Compliance

Advice and Guidance

Stakeholder Management

Behaviours

We'll assess you against these behaviours during the selection process:

  • Leadership
  • Making Effective Decisions
  • Changing and Improving
  • Communicating and Influencing

Technical skills

We'll assess you against these technical skills during the selection process:

  • Information Assurance (INAS

Reference: f100c37ff99b53a71ce4fb5efa70bb6378ad17b8 · Posted 3 days ago · Closes 4 Sep 2026 · Listed via Home Office

Know someone who'd be great for this? Get a shareable card

Apply for this job

This role is listed via Home Office. Applications are handled on the employer's site.

Apply on employer site

Opens the employer's website in a new tab.

Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.

Report this job
Salary £62,732 - £69,706 per annum
Apply now