Senior Cyber Security Risk Manager
Home Office
Apply before 11:55 pm on Wednesday 22nd January 2025
Details
Reference number
Salary
You may be eligible for an additional non-pensionable allowance, pending a Capability and Skills assessment, with a value of up to £12,680 (location dependent).
Job grade
Contract type
Business area
Type of role
Working pattern
Number of jobs available
Contents
Location
About the job
Job summary
The first duty of Government is to protect the public. Since 1782, the Home Office has led work to keep the country safe from those who seek to do it harm.
The Home Office covers three systems: Homeland Security, Public Safety and Borders, and Immigration and Citizenship. These systems work collaboratively to deliver our cross-cutting priorities, whilst providing increasingly efficient and secure services for the public.
Digital Data and Technology (DDaT) enables the Home Office to keep citizens safe and the country secure, as well as at the front line of making the Home Office a modern and capable department at a time of unprecedented global change.
Within DDaT, End User Compute & Collaborate (EUC&C) develop, maintain, and support End User Devices, Collaboration tools and Voice and Video products and services to approximately 67,000 users from across the Home Office, including the Private office, operational arms of Border force and Immigration Enforcement. EUC&C also offer users the ability to collaborate efficiently, on joint documentation, with other government departments. The Programme vision is: ''to empower Home Office Staff by providing an outstanding designed user experience through the right IT products.''
We embrace diversity and inclusion to ensure we represent the public we serve, and we are passionate about fair treatment and the wellbeing of our colleagues as part of our ambitions to be a brilliant Civil Service.
EUC&C is geographically spread across three primary locations (Croydon, Manchester and Southport) with most staff working in line with the Department’s hybrid working arrangements (a minimum of 60% of time in an office location, with the remainder working from home). You will need to agree a base location of either Croydon, Manchester, Liverpool OR Southport, and there will be a requirement for occasional travel to other locations. Due to the nature of this role this post is available on a full-time only basis.
Job description
The Cyber Security Risk Manager identifies, understands and mitigates cyber-related risks. They identify and evaluate security risks to information, systems and processes owned by the organisation, and proactively provide appropriate advice, drawing on a wide variety of sources, to stakeholders across the organisation and at a variety of levels. They provide risk or service owners with advice to help them make well informed risk-based decisions.
Main responsibilities:
Deliver Level one assurance assessments and reports, ensuring measures align with risk levels, Data Protection, and Government Policy. Conduct and communicate risk assessments to stakeholders, advising on risk management strategies tied to business outcomes.
Operate within established security governance structures under supervision to support and perform basic risk management tasks, including analysing security needs, conducting cyber risk and threat assessments, and other related activities.
Interpret and contribute to risk management policies, ensuring alignment with regulations and departmental/government policies, with a clear understanding of applicable legislation.
Offer advice to address cyber security risks using appropriate standards, guidance, or expertise. Validate risk mitigation measures and recommend improvements, including leveraging assurance activities like penetration testing.
Support risk and service owners with clear security advice, contributing to reports or established reporting processes. Assess the security of systems, devices, and software applications.
Note: An employee may be required to carry out other duties within the scope of the grade and within the limits of their skill, competence and training.
Person specification
Essential Skills
Please note that this role requires Security Clearance, which would normally need 5 years’ UK residency in the past 5 years.
You’ll have a demonstrable passion for Managing Security risk with the following skills or experience in:
- Analysis - apply appropriate rigour to ensure a full solution is designed and achieves the business outcome.
- Enabling and informing risk based decisions - describe different risk methodologies and how these are applied, as well as the proportionality of risk. Proven ability to communicate effectively with stakeholders and teams to ensure there is an understanding of the importance of security compliance.
- Understanding Security Implications of Transformation - interpret and apply an understanding of policy and process, business architecture, and legal and political implications to assist the development of technical solutions or controls. Understanding of Lean, Agile and DevOps principles within a Product-centric delivery model.
SFIA capability framework
Skills for the Information Age (SFIA) is the technical framework that sets the standard capability and development of all IT Operations levels in the Home Office. This is a link to the capability framework: All skills A - Z English (sfia-online.org)
We use set SFIA technical skills to form our interview questions and we will assess you against these technical skills during the selection process.
SFIA levels of responsibility – Use the SFIA Levels of responsibility to understand what would be expected for each Technical Skill listed below.
SFIA Technical Skills
The essential technical skills listed above are reflective of the Home Office Government Digital and Data Profession Career Framework. Please see below for the relevant skills required for your role.
Strategy and architecture:
- Security and Privacy
- Information Assurance (INAS) – Level 3
- Information security (SCTY) – Level 3
- Governance, Risk and Compliance
- Risk management (BURM) – Level 3
- Audit (AUDT) – Level 3
- Advice and Guidance
- Specialist advice (TECH) – Level 3
Relationships and Engagement
- Stakeholder Management
Behaviours
We'll assess you against these behaviours during the selection process:
- Making Effective Decisions
- Changing and Improving
- Communicating and Influencing
Technical skills
We'll assess you against these technical skills during the selection process:
- Information and Assurance
- Information Security
- Risk Management
- Specialist Advice
- Audit
- Stakeholder relationship management
Benefits
Why work for us...
- A highly competitive pension with an employer contribution of 28.97%.
- 25 days annual leave on appointment rising 1 day per year up to 30 days, plus 8 days public holidays and 1 day for the King’s Birthday.
- Flexible working options to enable you to achieve the work life balance that is right for you including: Full time, part-time, flexi time, compressed hours and job sharing.
- A hybrid working model of a minimum 60% of your contracted hours in the workplace and 40% remote.
- Training and development opportunities tailored to your role, including access to technical and professional accreditations.
- Access to funded qualifications (subject to approval).
- A capability allowance reviewed annually.
- A culture encouraging inclusion and diversity.
- Enhanced parental leave schemes.
- Annual performance-based bonus and recognition awards.
This link is to a short guide to employee benefits: Benefits - Home Office Careers.
Capability & Skills Allowance
The advertised role is part of the Home Office Government Digital and Data Profession. This role has access to a Digital Capability-Based Allowance. Applicants who are successful at interview will be invited to complete a Capability and Skills Assessment post-interview. Any allowance awarded will be based on the assessment of your capability against the six skills advertised for this role. Please see the attached candidate pack for more information.
The allowance values are set by the Home Office, subject to remaining in a qualifying role, and are non-pensionable. This allowance is non-contractual, subject to an annual review and could be withdrawn at any time.
For both new entrants and existing civil servants, the total compensation offer is a combination of base salary and, if applicable, a capability-based allowance. New entrants to the Civil Service will start on the pay range minimum. For existing civil servants, our policies on level transfer and promotion will apply.
Things you need to know
Selection process details
As part of the application process you will be asked to complete a CV and 1000 word Personal Statement. Further details around what this will entail are listed on the application form.
Please note your CV and Personal Statement should include all relevant experience that relates to our essential skills criteria listed in the advert and role description. Use STAR format in your examples.
Remove information that identifies you (for example your name, age or place of education) so that you will be judged on merit alone and not your personal background, circumstances, race or gender.
(Do NOT include e-mail addresses or links to online profiles, resumés, or prior work, either personal or business. Active links or e-mail addresses will result in your application being rejected).
Please ensure that all examples provided in your application are taken directly from your own experience and that you describe the examples in your own words. All applications are screened for plagiarism, copying, and generating of examples/answers from internet sources including Artificial intelligence. If detected, the application may be withdrawn from the process.
Further action, including disciplinary action, may be considered in such cases involving civil servants. Providing false or misleading information would be contrary to the core values of honesty and integrity expected of all civil servants.
Sift Stage
The sift will be held on the CV and Personal Statement. Please read the Essential skills for this position carefully. We will only consider those who meet the listed requirements.
In the event of a high number of applications, the sift will be conducted on the Personal Statement.
Interview Stage
Candidates reaching the required standard will then be invited to attend a final interview. The interview will assess your Technical Skills (SFIA Framework) and experience using technical and experience-based questions.
Sift and interview dates
Sift will be conducted week commencing 27/01/2025.
Interviews will be held week commencing 10/02/2025. (Subject to the Panel’s operational requirements/priorities).
Interviews will be conducted remotely via MS Teams.
We will try to meet the dates set out in the advert. There may be occasions when these dates will change. You will be provided with sufficient notice of the confirmed dates.
Reserve list
A reserve list of successful candidates will be kept for 12 months. Should another role become available within that period you may be offered this position.
Job offers to this post are made on the basis of merit. We often have similar roles available at different grades. If a candidate is suitable for a similar role or a lower grade than they have applied for, we may offer the candidate that role without the need to go through a further selection process providing the role has the same competencies and essential skills.
Further information
In order to process applications without delay, we will be sending a Criminal Record Check to Disclosure and Barring Service on your behalf. However, we recognise in exceptional circumstances some candidates will want to send their completed forms direct.
If you will be doing this, please advise Government Recruitment Service of your intention by emailing Pre-EmploymentChecks.grs@cabinetoffice.gov.uk stating the job reference number in the subject heading.
If you are invited to an interview, you will be required to bring documentation for the purposes of establishing your identity.
You will need to meet the nationality requirements for this role and obtain the necessary security clearance to take it up.
For meaningful security checks to be carried out, individuals need to have lived in the UK for a sufficient period of time. Learn more on our website. Security Checks - Home Office Careers
For further information on National Security Vetting please visit the following page https://www.gov.uk/government/publications/demystifying-vetting
Visa sponsorship
We do not sponsor individuals via Skilled Worker Sponsorship / Tier 2 (General) work visas.
Reasonable Adjustments
If a person with disabilities is at a substantial disadvantage compared to a non-disabled person, we have a duty to make reasonable changes to our processes.
If you need a change to be made so that you can make your application, you should:
- Contact Government Recruitment Service via HOrecruitment.grs@cabinetoffice.gov.uk as soon as possible before the closing date to discuss your needs
- Complete the “Assistance Required” section in the “Additional Requirements” page of your application form to tell us what changes or help you might need further on in the recruitment process. For instance, you may need wheelchair access at interview, or if you're deaf, a language service professional
If you are experiencing accessibility problems with any attachments on this advert, please contact the email address in the ‘Contact point for applicants’ section.
Feedback
Feedback will only be provided if you attend an interview or assessment.
Security
Nationality requirements
Working for the Civil Service
We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).
Diversity and Inclusion
Apply and further information
Contact point for applicants
Job contact :
- Name : AC Recruitment Team
- Email : acrecruitment@homeoffice.gov.uk
Recruitment team
- Email : HOrecruitment.grs@cabinetoffice.gov.uk
Further information
principles, and wish to make a complaint, then you should contact in the first instance
HORecruitment.GRS@cabinetoffice.gov.uk. If you are not satisfied with the response that you receive, then you can contact the Civil Service Commission.