Website Home Office
About the role
Home Office Digital designs, builds, and maintains all IT services for the department as well as a number of its Arms Length Bodies, wider government organisations and for the public. Every year Home Office systems support up to three million visa applications, checks on 100 million border crossings, up to eight million passport applications and deliver 140 million police checks on people, vehicles, and property.
As a Senior Cyber Security Risk Manager within Home Office Cyber Security, you will play a key role in embedding Secure by Design across our organisation, driving the cultural change needed to create a strong and positive security culture. You will work with project teams to ensure cyber security is considered from the outset and recognised as a shared responsibility throughout the delivery lifecycle.
You will ensure Secure by Design activities are part of the organisation’s government gate review life cycle so that security risks are addressed early and escalated in the right way. You will help escalate projects with low security confidence for extra support or oversight. You will also promote a standardised approach to Secure by Design activities across project, programmes and portfolios. Additionally you will encourage the use of templates, tools, and checklists (like the Secure by Design self assessment tracker) to help teams apply Secure by Design principles consistently.
You will join an expert team of cyber professionals, committed to reducing exposure to cyber-attack of new and existing digital systems. You will be aided by a diverse and supportive organisational culture, and a commitment to further your continuous development.
Where business needs allow, some roles may be suitable for a combination of office and home-based working. Where this is the case, employees will be expected to spend a minimum of 60% of their working time in the office. Applicants can raise any queries to the email address at the bottom of the advert.
Watch this short video to hear from members of Home Office Digital talking about the projects they work on and their experience of working here: Working for Home Office Digital.
Job description
The Senior Cyber Security Risk Manager within Secure by Design plans and implements organisation-wide processes and procedures for the embedding of Secure by Design as a framework approach to increasing the organisations Cyber Security. They monitor the uptake, adoption and effectiveness of utilising the Secure by design principles and activities across the organisation and make recommendations for continuous improvement.
As a Senior Cyber Security Risk Manager you will:
- Ensure Secure by Design activities are part of your organisation’s government gate review life cycle so that security risks are addressed early and escalated in the right way.
- Help escalate projects with low security confidence for extra support or oversight.
- Promote a standardised approach to Secure by Design activities across project,programmes and portfolios.
- Encourage the use of templates, tools, and checklists (like the Secure by Design self assessment tracker) to help teams apply Secure by Design principles consistently.
Person specification
Main Responsibilities
As a Senior Cyber Security Risk Manager your main day to day responsibilities will be:
- Explaining how you have incorporated Secure by Design into digital delivery within your own organisation. Include governance processes and the role each team plays in delivering Secure by Design activities.
- Working within established security and risk management governance structures in support of Secure by Design, usually under supervision to support, review and undertake straightforward risk management activities.
- Keeping awareness high by regularly using the Secure by Design communications toolkit to educate delivery, security, and supporting teams on their roles and the benefits of adopting Secure by Design practices.
- Attending government Secure by Design webinars and encourage your teams to join, sharing key takeaways across your organisation to reinforce shared learning and continuous improvement.
- Embedding Secure by Design into your onboarding process to help new staff understand its importance from day one. Consider adding guidance to your organisation’s intranet or knowledge hub as a permanent reference.
- Reviewing and actioning feedback from projects and the spend control process.
- Liaising with colleagues to update your internal processes and guidance based on what’s working well and where challenges have emerged.
- Staying up to date with the latest Secure by Design developments.
Working Pattern
Due to the business requirements of this role, it is only available on a full-time basis. However, compressed hours are available.
Essential criteria
You’ll have a demonstrable passion for Cyber Security with the following skills or experience in:
- Overseeing risk reviews, developing risk treatment plans and communicating those risks to others.
- Planning and delivery of project level activities.
- Adopting a structured approach to executing and documenting audits, following agreed standards.
- Maintaining integrity of records to support and satisfy audit trails.
- Communications and executive stakeholder engagement and management.
Desirable criteria
A strong understanding of the UK Government’s Secure by Design policy and principles, with the ability to apply them effectively to support the delivery of secure Cyber Security solutions and services.
To apply for this job please visit www.civilservicejobs.service.gov.uk.