Cyber & Corporate Risk Officer

UK Health Security Agency · GB

Cyber & Corporate Risk Officer at UK Health Security Agency, based in GB, paying £33,422 - £45,353 per annum. This is a permanent role.

Salary
£33,422 - £45,353 per annum
Location
GB
Contract
Permanent
Posted
1 day ago
Closes
15 Sep 2026
Sector
Security

34% below the typical rate for security

Reference 670b840a325780ffe50498bdae8f7481813f5681

About the role

Job summary

We are seeking a Cyber & Corporate Risk Officer to join the UKHSA Cyber Security team. This is an exciting opportunity to become a central part of this build and support the continuous development of the Cyber Governance Risk & Compliance function, provide strategic direction whilst managing the challenges and drive improvement and delivery of services.

Cyber is building on its capability to provide a critical function in the protection of the UKHSAs digital assets, working closely with wider UKHSA security teams and stakeholders Government Security Group, National Cyber Security Centre (NCSC) and National Protective Security Authority (NPSA) to build a resilient infrastructure, supporting the organisation in reaching its ambition to become a global leader for health security and become a critical component of our national security infrastructure.

For this role successful candidates must meet the security requirements before they can be appointed. The level of security needed is Security Check (SC).

For meaningful National Security Vetting checks to be carried out individuals need to have lived in the UK for a sufficient period of time. You should normally have been resident in the United Kingdom for the last 5 years as the role requires SC clearance. UK residency less than the outlined periods may not necessarily bar you from gaining national security vetting and applicants should contact the Resourcing Support listed in this advert for further advice.

Job description

The Cyber & Corporate Risk Officer will coordinate and deliver security risk management activity within enabling a clear and realistic view of security risk across Cyber.

They will support the delivery of Second Line Cyber Risk Assurance (CRA) across the UKHSA, reporting to the SEO Senior Cyber Risk Officer. The role will require a level of independent oversight, and work stream responsibility for focussing on a particular business area to include IACS and Harlow, supporting the programmes in the creation of a single overview of the cyber risk helping to ensure that they are clearly understood and managed in line with UKHSA’s risk appetite, government standards, and public sector assurance expectations, managing escalation in line with UKHSA processes.

As second line assurance, the role does not implement or operate cyber security controls, but helps to support UKHSA leadership by:

  • Providing confidence that cyber risks are identified, understood, and escalated appropriately
  • Strengthening transparency, governance, and assurance
  • Protecting the Agency’s ability to deliver vital health security outcomes

This role offers experience of cyber risk in a complex field presenting a number of learning and developmental opportunities, all of which support UKHSA’s critical health security mission.

The Cyber & Corporate Risk Officer must be comfortable to work flexibly and operate in a highly ambiguous environment while the Agency continues its transformation journey and defines its organisational culture. The ability to identify and understand challenges to find creative solutions will be critical as will strength in managing and building relationships across the organisation, undertaking effective collaboration at fast pace, both internally and externally to UKHSA. They will be expected to work on their own initiative without micro-management but know when to revert to seek a steer or decision.

This is a dynamic and challenging environment, and they will need to be confident in managing complexity, applying judgement, and making decisions whilst collaborating effectively with other members of the team and across the organisation.

This role will requires working with cyber team members of staff who are predominantly home-based workers.

Second Line Cyber Risk Support
  • Support the delivery of Second Line oversight and challenge of cyber and technology risks
  • Assist in reviewing First Line cyber risk assessments, control documentation, and mitigation plans
  • Ensure cyber risks are recorded clearly and consistently within UKHSA risk registers and tooling
  • Help differentiate between risk ownership (First Line) and risk assurance (Second Line) activities
Cyber Risk Framework & Standards
  • Support the maintenance of UKHSA’s Cyber Risk Management Framework
  • Assist in assessing cyber risks against:
    • Government Security Policy Framework (SPF)
    • DSPT Cyber Assurance Framework
    • NCSC guidance
    • ISO 27001 / NIST aligned approaches
  • Promote a proportionate, risk based approach to cyber security across the organisation
Governance & Reporting
  • Contribute to cyber risk reporting for senior management and assurance forums
  • Analyse cyber risk data, trends, and Key Risk Indicators (KRIs)
  • Help translate technical cyber security issues into clear risk narratives focused on business and health impact
  • Support preparation of papers and briefing materials for senior stakeholders
Change & Third Party Risk Assurance
  • Support cyber risk assurance activities related to:
    • Digital and data change initiatives
    • Cloud services and shared platforms
    • Third party and supplier arrangements
  • Assist with identifying emerging cyber risks early in the change lifecycle
Learning, Assurance & Continuous Improvement
  • Support post incident reviews and lessons learned activities from a risk perspective
  • Contribute to assurance exercises, internal reviews, and audit engagement
  • Build cyber risk knowledge and capability through on the job learning, mentoring, and formal development

The above is only an outline of the tasks, responsibilities and outcomes required of the role. You will carry out any other duties as may reasonably be required by your line manager.

The job description and person specification may be reviewed on an ongoing basis in accordance with the changing needs of the organisation.

Person specification

Essential Criteria

  • Experience or strong interest in Cyber Risk Management, Information Security, Technology Risk, or GRC
  • Awareness of cyber security threats, vulnerabilities, and controls
  • Ability to analyse information and present risks clearly and concisely
  • Strong written and verbal communication skills
  • Willingness to provide constructive challenge while building effective working relationships

Desirable Criteria

  • Knowledge of:
    • Government Security Policy Framework
    • NCSC principles
    • Risk registers and assurance reporting
    • DSPT Cyber Assessment Framework
    • Industrial Automated Control Systems

Benefits

Alongside your salary of £33,422, UK Health Security Agency contributes £9,682 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).
  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • A Civil Service pension with an employer contribution of 28.97%

We pride ourselves as being an employer of choice, where Everyone Matters promoting equality of opportu

Reference: 670b840a325780ffe50498bdae8f7481813f5681 · Posted 1 day ago · Closes 15 Sep 2026 · Listed via UK Health Security Agency

Know someone who'd be great for this? Get a shareable card

Apply for this job

This role is listed via UK Health Security Agency. Applications are handled on the employer's site.

Apply on employer site

Opens the employer's website in a new tab.

Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.

Report this job
Salary £33,422 - £45,353 per annum
Apply now