Salary: £68,000 - 108,000 per year
Requirements:- We require experience in information or cyber security, including threat and risk analysis for complex, high-risk and/or mission-critical systems.
- We prefer experience involving the Home Office, Cabinet Office, NCSC, or industry Security Operations Centres (SOCs) and departments.
- We require proficiency in analysing or implementing technical or security policies in a large organisation.
- We require the ability to balance security requirements with business impact to ensure practicality and effectiveness.
- We require a proven track record in implementing cybersecurity risk, assurance, or governance processes and procedures.
- We require proven ability to lead and mentor a diverse team of governance, risk, or assurance specialists.
- We require the ability to design and implement security controls aligned with organisational requirements while responding proactively to evolving risks.
- We require strong ability to present technical information to non-technical stakeholders and influence decision-making at senior leadership level.
- We assess candidates against SFIA capability framework skills in Information Assurance (INAS) Level 3, Information security (SCTY) Level 4, Risk management (BURM) Level 3, Audit (AUDT) Level 4, Specialist advice (TECH) Level 4, and Stakeholder relationship management (RLMT) Level 4.
- We assess candidates against the behaviours of Leadership, Making Effective Decisions, Changing and Improving, and Communicating and Influencing.
- We independently and impartially undertake risk management activities within our area of practice or expertise, typically within established security and risk management governance structures.
- We lead the independent derivation and analysis of security needs and conduct tailored threat assessments, security audits, or other risk management activities.
- We develop risk management-related policy and assure the ongoing appropriateness of policy in accordance with regulation and wider organisational and government policies.
- We communicate effectively with senior stakeholders to ensure they recognise the importance of security considerations and advise them on their approach to risk assessment.
- We manage risk management processes, review their efficiency and effectiveness, and lead recommendations for continuous improvement.
- We review internal controls following any security breach, provide advice on remediating vulnerabilities, and agree and oversee remedial solutions, controls, and safeguards.
- We assess reviews and risk assessments and ensure identified risks are managed in accordance with our risk management policies.
- We lead a small team of Civil Service Cyber Risk Managers.
- Support
- Security
- MS Teams
More:
We are the Home Office, recruiting for a Lead Cyber Risk Manager role based across London Borough of Croydon, Salford, Sheffield, and Glasgow City. This is a full-time IT position with a salary of 62,732 to 69,706 per year, and we offer benefits including a Civil Service Pension with employer contribution rates of at least 28.97%, an in-year reward scheme, 25 days annual leave rising with service, and 8 days of public holidays plus one privilege day. We support a hybrid working approach where business needs allow, with employees expected to spend a minimum of 60% of their time in the office. You will join an expert team of cyber professionals committed to reducing cyber-attack exposure across new and existing digital systems, within a supportive culture that values continuous development.
last updated 34 week of 2026
Be the first to know aboutnew jobs every week
Get 8 new jobs with salaries, once per week! Sign up here so you don't miss a single newsletter.