
Senior Security and Fraud Risk Manager
Department for Work and Pensions
Senior Security and Fraud Risk Manager at Department for Work and Pensions in United Kingdom
About the role
Job summary
Please note this role requires you to pass Security Check clearance. For further information, please see 'Selection process details'.
Come and help us secure one of the biggest digital transformation projects in Europe.
We are looking for Security/Fraud Risk Managers who can use their expertise in fraud & error, security and digital delivery to help design public services that are secure by design, resilient to fraud & error and trusted by the people who rely on them.
This is an opportunity to play a visible and influential role in safeguarding public money, protecting citizens from identity theft and shaping how Universal Credit (UC) and Working Age Services respond to emerging security and fraud & error risks.
You will join a multi-disciplinary group of fraud & error, and security specialists supporting more than 25 agile portfolio and feature teams. Working closely with delivery, product, fraud & error and security colleagues, you will help ensure new features are designed to be inherently secure and resilient to fraud & error from the outset.
You will identify, assess and respond to security and fraud & error risks across Universal Credit and Working Age Services feature teams, provide clear and pragmatic risk advice, and maintain the UC Security and Fraud risk register to support well-informed decision making.
We are looking for people with strong analytical skills, excellent attention to detail, sound judgement and the confidence to explain complex issues clearly. You will be collaborative, independent in thought and able to influence others while valuing the strength of a multi-disciplinary team over hierarchy.
Depending on experience, successful candidates will be supported to work towards a Certified in Risk and Information Systems Control (CRISC) qualification.
You must have one of the following qualifications to be eligible to apply for the role: Certified Information Systems Security Manager (CISSP), (Certified Information Security Manager (CISM), Governance, Risk and Compliance Professional (GRCP) or an equivalent security qualification.
Job description
This is a critical role co-ordinating and delivering a Digital security and fraud risk management programme of work, with risk driving delivery priorities. The role forms a vital first line capability within the HMG three-lines of defence model.
To be successful, the postholder requires a unique combination of knowledge of citizen identity, counter fraud measures, business security practices and technical security including vulnerabilities, threat, secure design principles as well as personnel security.
The post holder needs to be able to interpret a range of sometimes conflicting technical and esoteric information and present it in a format that is understood by a wide range of audiences. They also need strong facilitation, interpersonal and negotiation skills. Reducing fraud & error is one of our core principles and therefore a priority activity.
Specifically you will:
- Ensure that all areas identify fraud & error, information security risks, technical security risks and vulnerabilities, issues and incidents are identified, triaged, prioritised, actioned and continually managed within the risk management lifecycle.
- Support and ensure consistency in approach for risk-informed decisions regarding prioritisation of deliverables, protection of assets and security architecture.
- Manage and lead the identification, assessment and remediation of business security/technical security/fraud & error risks.
- Identify, capture or contextualise risks, enabling risk owners and risk managers to take responsibility for the management and maintenance of their security and fraud & error risks.
- Work closely with business/technical security and fraud stakeholders contributing to the delivery of common goals.
- Work closely with delivery managers to design out fraud & error and minimise business/technical security risks at every level of design and delivery.
- Identify, assess and measure emerging business/technical security and fraud risks, or report to programme and senior stakeholders based on current trends and issues across DWP and the external environment.
- Provide risk expertise, advice and support to business managers, Senior Risk Owners and Executive Team Leads within UC/Working Age Services and the wider DWP.
- Ensure the implementation of the Governance Risk and Compliance methodology and day to day utilisation of the risk management toolset.
Knowledge of working age benefit systems would be beneficial to the role.
Person specification
See selection process for further details.
If you would like to learn more about the role, please contact Natalie.Selby1@dwp.gov.uk
Qualifications
Certified Information Systems Security Manager (CISSP), (Certified Information Security Manager (CISM), Governance, Risk and Compliance Professional (GRCP) or an equivalent security qualification.
Technical skills
We'll assess you against these technical skills during the selection process:
- Threat Intelligence and Threat Assessment
Benefits
Alongside your salary of £57,946, Department for Work and Pensions contributes
£16,786 towards you being a member of the Civil Service Defined Benefit Pension scheme.
Find out what benefits a Civil Service Pension provides (opens in a new window).
We also have a broad benefits package built around your work-life balance which includes:
- Working patterns to support work/life balance such as job sharing, term-time working, flexi-time and compressed hours.
- Generous annual leave – at least 25 days on entry, increasing up to 30 days over time (pro–rata for part time employees), plus 9 days public and privilege leave.
- Support for financial wellbeing, including interest-free season ticket loans for travel, a cycle to work scheme and an employee discount scheme.
- Health and wellbeing support including our Employee Assistance Programme for specialist advice and counselling and the opportunity to join HASSRA a first-class programme of competitions, activities and benefits for its members (subscription payable monthly).
- Family friendly policies including enhanced maternity and shared parental leave pay after 1 year’s continuous service.
- Funded learning and development to support progress in your role and career. This includes industry recognised qualifications and accreditations, coaching, mentoring and talent development programmes.
- An inclusive and diverse environment with opportunities to join professional and interpersonal networks including Women’s Network, National Race Network, National Disability Network (THRIVE) and many more.
Hybrid Working
This role may be suitable for hybrid working, which is where an employee works part of the week in their DWP office and part of the week from home. This is a voluntary, non-contractual arrangement and your office will be your contractual place of work.
If a hybrid working arrangement is suitable for the role and for you, you will normally be required to spend a minimum of 60% of your contracted working hours from your DWP office.
If you have a disability, caring responsibilities, or other circumstances that may affect your ability to meet the minimum office attendance requirement, please discuss this with us using the contact details in this advert.
Salary Information
New entrants to the Civil Service will join on band minimum.
Existing Civil Servants who secure a new role on lateral transfer will maintain their current substantive salary.
Existing Civil Servants who gain promotion will move to the bottom of the grade pay scale or receive a 10% increase applied to their current substantive salary, whichever is greater.
Any temporary allowances that you are currently in receipt of will not form part of the calculation to determine your pay. Any allowances that are in payment will cease when you move into your new role.
Things you need to know
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.
Selection process details
This vacancy is using Success Profiles (opens in a new window) , and will assess your Experience and Technical skills.
Stage 1: Application
Your application will consist of four parts:
1. A Personal Details application form.
2. Employment history - this should contain your work experience and any skills, qualifications and accomplishments relevant to the jobs you have completed.
3. Technical statement (up to 250 words). The following statement is aligned to the required technical skill of Threat Intelligence and Threat Assessment. This statement should be used to provide example(s) of how you meet the criterion below:
- Please describe your experience of using security and/or fraud & error strategies, principles and threat assessment approaches to identify, assess and respond to risks. In your answer, explain how you used threat intelligence or emerging risk information to inform decisions, prioritise activity, and support secure or fraud-resilient outcomes.
4. Personal statement - up to 1000 words. This statement should be used to provide examples of how you meet the essential criteria below:
- Demonstrable knowledge and practical experience of risk management, including risk identification, assessment, mitigation, response, control monitoring and reporting.
- Practical experience of policy and criminal law (Nexus, Non Repudiation, PACE etc.)
- Practical experience of negotiating with stakeholders at senior levels and translating business and strategic risk requirements into secure solutions through improvements in information systems, data management, practices and procedures.
- Experience and understanding of working with digital projects and of Agile project methodology.
Ensure that all examples provided in your statements are taken directly from your own experience and that you describe the examples in your own words. If you choose to use gen-AI to support your statements, you must follow the guidelines outlined in the Artificial intelligence and recruitment guide.
The sift panel will use the information in your employment history, personal statement, and technical statement to assess your experience, skills and knowledge.
An initial sift will be conducted using the technical statement. Candidates who pass the initial sift will be progressed to a full sift.
If you do progress to a full sift, you will be provided with one combined overall assessment score for both your employment history and Personal Statement.
For Hints and Tips on completing your application visit Applying for jobs at DWP Digital.
Important Information
- You will be asked to complete your employment history. Any information that you would customarily share on a CV should therefore be entered onto the application form.
- Personal details that could be used to identify you including your name, contact details and address must be removed for your application to be considered.
- If your employment history, personal statement or technical statement contain any personal details your application will be withdrawn.
Stage 2: Interview
If you’re successful at the sift stage, you’ll be invited to a video interview via Microsoft Teams. During the interview, you’ll be assessed against the experience criteria listed under both the essential criteria and technical skill.
You will be asked to do a 10 minute presentation on a spec
