Skip to main content
AfterDuty

Deputy Director of Enterprise Security & Risk Management

Department for Work and Pensions (DWP) · London, Greater London

Salary
£86,000 – £104,000Estimated
Type
Full-time
Posted
18 days ago

Overview

Your security risk management and incident command experience directly prepares you for this senior leadership role.

About this role

Details

Existing Civil Servants will be appointed in line with the Civil Service pay rules in place on the date of their appointment, this will usually be the salary minimum or within 10% of their existing salary for those applying on promotion. Individuals appointed on level transfer will retain their existing base salary.

A Civil Service Pension with an employer contribution of 28.97%

GBP

Job grade

SCS Pay Band 1

Business area

DWP - Finance

Type of role

Risk Management

Security

Working pattern

Flexible working, Full-time, Job share

Number of jobs available

1

Contents

  • Location
  • About the job
  • Benefits
  • Things you need to know
  • Apply and further information

About the job

Job summary

Shape how one of the UK's largest organisations understands and responds to security risk.

This is a unique opportunity for an experienced governance, risk and assurance leader to shape how DWP understands, manages and acts on security risk. We are looking for someone who can bring clarity, pace and innovation to enterprise security risk management; who is confident working with complex evidence, assurance and threat information; and who can translate that insight into decisions that influence senior leaders across the whole organisation. The function is already mature and well-respected; you will have the opportunity to build and shape the credibility of the function across the Department, Government and the wider industry.

You will be a natural relationship builder, comfortable operating in a large, complex delivery organisation in either the public or private sector. You will need to inspire confidence with Ministers, the Permanent Secretary, the Departmental Audit, Risk and Assurance Committee, senior colleagues and your own teams through the quality of your judgement, the strength of your evidence, and your ability to help the organisation act on the risks that matter most. This is a role for someone who cares deeply about impact: not simply reporting risk and assurance, but changing behaviour, improving resilience and enabling better outcomes for millions of citizens.

We are looking for an inclusive, credible and ambitious senior leader to support me in leading the teams that provide proportionate, well-informed security and risk advice to the Department and its senior leaders. Values and making Security & Data Protection Directorate within DWP a brilliant place to work will be important to you. You’ll thrive on delivering outcomes and making wider contributions to Government Security and the Civil Service.

To learn more about this opportunity, hear directly from Mike Fell, Chief Security Officer and vacancy holder.

For more information about DWP and this role, please see the Candidate Pack attached.

Hear more about DWP

Job description*

As Deputy Director of Enterprise Security & Risk Management, the accountabilities of the postholder include:

  • Enterprise Risk Management - Lead the organisation’s security risk function, ensuring enterprise-level security risks are identified, assessed, prioritised and effectively managed in alignment with the organisation's risk appetite or agreed risk tolerance.
  • Security Oversight – Develop and deliver the department’s enterprise security governance model and associated boards, ensuring alignment with corporate strategy, governance, regulatory requirements and risk appetite.
  • Governance, Risk & Compliance - Lead Governance Risk & Compliance (GRC) activities, ensuring it is aligned, proportionate, transparent, compliant and business-centric. Provide programme and service-specific risk advice aligned to policy and risk appetite. Work closely with Security Policy & Awareness teams to deliver joined up security.
  • Third‑Party Security Assurance - Responsible for the organisation’s multi-tiered supplier assurance programme, ensuring all third‑party security risks are assessed, monitored and actively managed throughout the contract lifecycle in a proportionate, risk-based manner.
  • IT Security Assurance - Deliver a holistic, balanced programme of independent assurance over IT security architecture and associated controls providing confidence in technology‑driven risk including mandatory external and internal assurance and compliance activity.
  • Physical Security Assurance - Responsible for evaluating, testing and verifying the organisation’s physical security measures across circa 850 locations ensuring site- and enterprise-level resilience measures are robust, risk-aligned and compliant with external requirements.
  • Regulatory & Audit Engagement - Acts as the primary interface with internal audit, external auditors, and wider government bodies, ensuring clear evidence of security risk management and control effectiveness.
  • Leadership of a Dispersed Workforce - Lead a team of 90 security, risk and assurance professionals across multiple UK locations, building a unified culture, clear accountability and high performing team.
  • Strategic Advisor - Advises the Chief Security Officer, Executive Team and other boards on systemic risks and strategic investment priorities to manage those risks.
  • Management – Accountable for the efficient running of the team, including a multi-million-pound budget, accurate forecasting, and HR, finance and commercial compliance.

Person specification

The successful candidate must be able to demonstrate their knowledge, experience and skills against the following essential criteria:

  • Proven senior security leadership experience, with a track record of leading and inspiring large, geographically dispersed teams through an engaging, authentic and adaptable leadership style. The successful candidate will demonstrate exceptional interpersonal and influencing skills, with the credibility to build trusted relationships at all levels of the organisation. They will possess high levels of emotional intelligence, sound judgement, executive presence, diplomacy and adaptability.
  • Security Governance, Risk & Compliance (GRC) expertise – recognised expertise in security GRC, with experience establishing and leading enterprise-wide, cross-domain security governance, risk management and compliance frameworks within complex organisations. This will include deep knowledge of relevant regulations, frameworks and standards, together with experience of managing risk across both legacy and modern technology environments. This expertise should be evidenced through relevant professional qualifications and memberships (e.g. CISM, CISA, CISSP, CRISC, GRC(A), Chartered Security/Cyber Profession status).
  • Excellent communication and stakeholder management skills, with the ability to influence senior leaders and communicate complex security and risk issues clearly to both technical and non-technical audiences.

Experience leading security assurance across complex supply chains and outsourced service models, ensuring effective governance, risk management and resilience across third-party environments.

  • Behaviours

We'll assess you against these behaviours during the selection process:

  • Leadership
  • Seeing the Big Picture
  • Changing and Improving
  • Delivering at Pace

Benefits

Alongside your salary of £86,000, Department for Work and Pensions contributes £24,914 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides .

DWP have a broad benefits package built around your work-life balance which includes:

  • Working patterns to support work/life balance such as job sharing, term-time working, flexi-time and compressed hours.
  • Generous annual leave – at least 25 days on entry, increasing up to 30 days over time (pro–rata for part time employees), plus 9 days public and privilege leave.
  • Support for financial wellbeing, including interest-free season ticket loans for travel, a cycle to work scheme and an employee discount scheme.

About security roles for ex-police

Security management, operations and consultancy roles. Years of operational policing — command, incident response, public order — translate directly into corporate security, and employers in this sector actively rate police experience.

See all security jobs in London

Why this fits a police background — match score 75/100

  • Working to legislation & regulation
  • Security operations

What security roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Security officer (SIA)£24,000–£29,000
Security supervisor / team leader£28,000–£34,000
Site / security manager£38,000–£52,000
Regional / operations security manager£50,000–£65,000
Full security salary guide →

More security jobs for ex-police

  • Duty Security Manager

    Birkbeck, University of London · London

    Full-time

    Your incident command and team leadership from policing transfer directly into managing campus security operations.

    Posted 2 days ago

  • Duty Security Officer

    The Ned & Ned's Club · London

    Full-time

    Your threat detection, CCTV monitoring and conflict de-escalation skills from policing are directly applicable to this security role.

    Posted 3 days ago

  • Full-time

    Your patrol, conflict management, and incident response experience from policing translates directly.

    Posted 3 days ago

  • Security Officer

    Unitrust Protection · London

    Full-time

    Your incident command and conflict management skills transfer directly to protecting people and premises.

    Posted 4 days ago