
Senior Cyber Security Risk Manager - Home Office Cyber Security
Senior Cyber Security Risk Manager - Home Office Cyber Security at Home Office in Croydon, Glasgow, Salford, Sheffield
About the role
Job summary
Home Office Digital designs, builds and develops services for the rest of the department and for government. Every year our systems support up to 3 million visa applications, checks on 100 million border crossings, up to 8 million passport applications and deliver 140 million police checks on people, vehicles and property.
As a Senior Cyber Security Risk Manager, you will support the identification, assessment and mitigation of cyber-related risks. You will help evaluate security risks to information, processes, critical national infrastructure and business-critical systems, drawing on a range of evidence to provide advice to stakeholders across the organisation and support informed, risk-based decision- making. You will also contribute to the development, maintenance and continuous improvement of risk systems, processes and frameworks.
You’ll be joining an expert team of cyber professionals, committed to reducing the exposure to cyber-attack of new and existing digital systems. You’ll be aided in your role by a diverse and supportive organisational culture, and a commitment to further your continuous development.
Where business needs allow, some roles may be suitable for a combination of office and home-based working. Where this is the case, employees will be expected to spend a minimum of 60% of their working time in the office . There may be a requirement for occasional travel to other locations. Applicants can raise any queries to the email address at the bottom of the advert.
Watch this short video to hear from members of Home Office Digital talking about the projects they work on and their experience of working here: Working for Home Office Digital.
Recruitment Event
Join our free online recruitment events on Tuesday 8th September at 1pm & Thursday 10th September at 1pm to learn more about current opportunities, hear directly from our Lead Technical Recruiters for Home Office Digital and gain valuable insight into the application and recruitment process.
Register your interest here: https://lnkd.in/e6y4JqaS . https://lnkd.in/eswtB822
Job description
The Senior Cyber Security Risk Manager plans and implements organisation-wide processes and procedures for the management of risk. They monitor the efficiency and effectiveness of the risk management processes across the organisation and make recommendations for continuous improvement.
As a Senior Cyber Security Risk Manager , your main day to day responsibilities will be:
- Developing risk management-related policy and assuring the ongoing appropriateness of policy in accordance with regulation and wider organisational and government policies.
- Supporting the embedding of risk management systems, processes, and frameworks, communicating these across the business to a range of stakeholders.
- Working within established security and risk management governance structures, usually under supervision to support, review and undertake risk management activities such as: undertaking cyber security related risk assessments; threat assessments and other risk management activities.
- Communicating the risk assessment outcomes to stakeholders in ways that support effective security, risk management and decision-making.
- Providing advice to address straight-forward cyber security risks by applying a variety of security capabilities, which may include using published guidance or standards, and validating the effectiveness of risk mitigation measures.
- Helping risk or service owners to make decisions that are well informed by providing clear security advice, including contributing to reports or working within established reporting chains in a security team.
- Providing risk-oriented training to a range of stakeholders, including preparation of training materials, to ensure that relevant stakeholders are equipped to use standard risk management frameworks.
Working Pattern
Due to the business requirements of this role, it is only available on a full-time basis. However, compressed hours are available.
Person specification
Essential Skills
You’ll have a demonstrable experience in, and passion for, Cyber Security including the
following skills or experience in:
- Reviewing and performing risk assessments, developing risk treatment plans and communicating those risks to others.
- Identifying typical risk indicators and explaining prevention measures.
- Adopting a structured approach to executing and documenting audits, following agreed standards.
- Maintaining integrity of records to support and satisfy audit trails.
- Ability to champion cyber security risk and ensure ongoing appropriateness or practices.
- Communicating technical requirements effectively to both technical and non technical stakeholders.
SFIA capability framework
Skills for the Information Age (SFIA) version 8 is the technical framework that sets the standard capability and development of all levels in the Home Office.
This is a link to the capability framework: All skills A - Z English (sfia-online.org) . We use set SFIA technical skills to form our interview questions and we will assess you against these technical skills during the selection process.
The essential skills listed above are reflective of the Home Office Government Digital and Data Profession Career Framework (based on the industry standard SFIA framework). Use the SFIA Levels of responsibility to understand what would be expected for each technical skills listed below.
Strategy and architecture:
- Security and Privacy
- • Information Assurance (INAS) – Level 3
- • Information security (SCTY) – Level 3
- Governance, Risk and Compliance
- • Risk management (BURM) – Level 3
- • Audit (AUDT) – Level 3
- Advice and Guidance
- • Specialist advice (TECH) – Level 3 ( Generic Level 3 descriptor)
Relationships and Engagement:
- Stakeholder Management • Stakeholder relationship management (RLMT) – Level 3 ( Generic Level 3 descriptor)
Behaviours
We'll assess you against these behaviours during the selection process:
- Changing and Improving
Technical skills
We'll assess you against these technical skills during the selection process:
- Information Assurance (INAS) – Level 3
- Information security (SCTY) – Level 3
- Risk management (BURM) – Level 3
- Specialist advice (TECH) – Level 3
- Stakeholder relationship management (RLMT) – Level 3
Benefits
Alongside your salary of £49,850, Home Office contributes
£14,441 towards you being a member of the Civil Service Defined Benefit Pension scheme.
Find out what benefits a Civil Service Pension provides (opens in a new window).
Why work for us...
Find out more information at : Benefits - Home Office Careers, but some of the primary ones are:
- A Civil Service Pension with employer contribution rates of at least 28.97%.
- In-year reward scheme for one-off or sustained exceptional personal or team achievements.
- 25 days annual leave on appointment, rising with service.
- 8 days of public holidays, plus 1 additional privilege day.
- Where business needs allow, some roles may be suitable for a combination of office and home-based working. This is a non-contractual arrangement where all employees will be expected to spend a minimum of 60% of their working time in an office.
Sign-up on our website to receive emails with information about careers at the Home Office.
Things you need to know
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.
Selection process details
This vacancy is using Success Profiles (opens in a new window) , and will assess your Behaviours, Experience and Technical skills.
As part of the application process, you will be asked to complete a CV and 1000 word personal statement :
- CV – include a brief employment history outlining for each role, the organisation, job title, dates in post, and key responsibilities and achievements. Any recent employment gaps should be explained. A second section should set out the skills and experience most relevant to this role, drawing on your career, training, and other relevant activities without repeating the employment history. Focus on the evidence that best demonstrates your capability to meet the role requirements.
- Personal statement - this should present a clear and coherent narrative explaining why you are applying, what you would bring to the role, and how your experience meets the essential criteria. Use well ‑ chosen examples to illustrate your impact, drawing on STAR ‑ style thinking where helpful, but ensure the statement reads as a single, flowing document rather than a set of isolated responses.
To ensure you are assessed on merit alone, we ask you to anonymise your application. This means removing personal identifiers such as your name, age, and place of education. You do not need to remove your employment history, job titles, or any information about your work.
Watch our three short videos on how to apply for our roles: Applying - Home Office Careers.
Problems during the application process
If you experience problems accessing this advert, or you think you’ve made a mistake on an initial application, please contact hocandidates.grs@cabinetoffice.gov.uk, including the vacancy reference, at least two working days before the vacancy closes. Further information can be found on our website .
Do not create or attempt to submit another application, online test or use a different Civil Service Jobs account to proceed as this would be in violation of the candidate declaration.
Sift Stage
The sift will be held on the CV and Personal Statement . Please read the essential skills for this position carefully. We will only consider those who meet the listed requirements.
In the event of a high number of applications received, the sift will be held on the Personal Statement only.
Interview Stage
Candidates reaching the required standard will then be invited to attend an interview. The interview will assess your Technical Skills (SFIA Framework) and Behaviours, using technical & behaviour-based questions.
If you are invited to an interview, you will be required to bring a range of documentation for the purposes of establishing identity and to aid any pre-employment checks. Please see the attached list of Home Office acceptable ID documents.
Sift and Interview dates
The sift will commence from 15/09/ 2026.
Interviews are expected to take place from 05/10/2026. (Subject to the Panel’s operational requirements/priorities).
Interviews will be conducted remotely via MS Teams.
We will try to meet the dates set out in the advert. There may be occasions when these dates will change. You will be provided with sufficient notice of the confirmed dates.
Further information
If you have previously made an unsuccessful application for a role with the same essential skills and are not able to demonstrate how you have developed these skills since your last application, please reconsider applying as your application is unlikely to be successful.
In order to process applications without delay, we will be sending a Criminal Record Check to Disclosure and Barring Service on your behalf. However, we recognise in exceptional circumstances some candidates will want to send their completed forms directly. If you are doing this, please advise Government Recruitment Service of your intention by e