Skip to main content
AfterDuty

Senior Cyber Security Risk Manager - Home Office Cyber Security

Home Office · Glasgow, Scotland

Salary
£53,850 – £56,850Estimated
Type
Full-time
Posted
18 days ago

Overview

Your risk assessment and threat management experience from policing applies directly to cyber security risk management.

About this role

Details

New entrants to the Civil Service will start their role on the salary band minimum £49,850 for National roles and £53,850 for London roles.

You may be eligible for an additional non-pensionable allowance, pending a Capability and Skills Assessment, with a value of up to £7,750.

A Civil Service Pension with an employer contribution of 28.97%

GBP

Job grade

Senior Executive Officer

Business area

HO - Home Office Digital - Cyber Security

Type of role

Digital

Information Technology

Security

Working pattern

Full-time, Compressed hours

Number of jobs available

3

Contents

  • Location
  • About the job
  • Benefits
  • Things you need to know
  • Apply and further information

About the job

Job summary

Home Office Digital designs, builds and develops services for the rest of the department and for government. Every year our systems support up to 3 million visa applications, checks on 100 million border crossings, up to 8 million passport applications and deliver 140 million police checks on people, vehicles and property.

As a Senior Cyber Security Risk Manager, you will support the identification, assessment and mitigation of cyber-related risks. You will help evaluate security risks to information, processes, critical national infrastructure and business-critical systems, drawing on a range of evidence to provide advice to stakeholders across the organisation and support informed, risk-based decision- making. You will also contribute to the development, maintenance and continuous improvement of risk systems, processes and frameworks.

You’ll be joining an expert team of cyber professionals, committed to reducing the exposure to cyber-attack of new and existing digital systems. You’ll be aided in your role by a diverse and supportive organisational culture, and a commitment to further your continuous development.

Where business needs allow, some roles may be suitable for a combination of office and home-based working. Where this is the case, employees will be expected to spend a minimum of*60% of their working time in the office*. There may be a requirement for occasional travel to other locations. Applicants can raise any queries to the email address at the bottom of the advert.

Watch this short video to hear from members of Home Office Digital talking about the projects they work on and their experience of working here: Working for Home Office Digital.

Recruitment Event

Join our free online recruitment events on Tuesday 8th September at 1pm*& *Thursday 10th September at 1pm to learn more about current opportunities, hear directly from our Lead Technical Recruiters for Home Office Digital and gain valuable insight into the application and recruitment process.

Register your interest here: https://lnkd.in/e6y4JqaS. https://lnkd.in/eswtB822

Job description

The *Senior Cyber Security Risk Manager*plans and implements organisation-wide processes and procedures for the management of risk. They monitor the efficiency and effectiveness of the risk management processes across the organisation and make recommendations for continuous improvement.

As a Senior Cyber Security Risk Manager, your main day to day responsibilities will be:

• Developing risk management-related policy and assuring the ongoing appropriateness of policy in accordance with regulation and wider organisational and government policies.

• Supporting the embedding of risk management systems, processes, and frameworks, communicating these across the business to a range of stakeholders.

• Working within established security and risk management governance structures, usually under supervision to support, review and undertake risk management activities such as: undertaking cyber security related risk assessments; threat assessments and other risk management activities.

• Communicating the risk assessment outcomes to stakeholders in ways that support effective security, risk management and decision-making.

• Providing advice to address straight-forward cyber security risks by applying a variety of security capabilities, which may include using published guidance or standards, and validating the effectiveness of risk mitigation measures.

• Helping risk or service owners to make decisions that are well informed by providing clear security advice, including contributing to reports or working within established reporting chains in a security team.

• Providing risk-oriented training to a range of stakeholders, including preparation of training materials, to ensure that relevant stakeholders are equipped to use standard risk management frameworks.

Working Pattern

Due to the business requirements of this role, it is only available on a full-time basis. However, compressed hours are available.

Person specification

Essential Skills

You’ll have a demonstrable experience in, and passion for, Cyber Security including the

following skills or experience in

  • Reviewing and performing risk assessments, developing risk treatment plans and communicating those risks to others.
  • Identifying typical risk indicators and explaining prevention measures.
  • Adopting a structured approach to executing and documenting audits, following agreed standards.
  • Maintaining integrity of records to support and satisfy audit trails.
  • Ability to champion cyber security risk and ensure ongoing appropriateness or practices.
  • Communicating technical requirements effectively to both technical and non technical stakeholders.

SFIA capability framework

Skills for the Information Age (SFIA) version 8 is the technical framework that sets the standard capability and development of all levels in the Home Office.

This is a link to the capability framework: All skills A - Z English (sfia-online.org). We use set SFIA technical skills to form our interview questions and we will assess you against these technical skills during the selection process.

The essential skills listed above are reflective of the Home Office Government Digital and Data Profession Career Framework (based on the industry standard SFIA framework). Use the SFIA Levels of responsibility to understand what would be expected for each technical skills listed below.

Strategy and architecture

  • Security and Privacy

Information Assurance (INAS) – Level 3

Information security (SCTY) – Level 3

  • Governance, Risk and Compliance

Risk management (BURM) – Level 3

Audit (AUDT) – Level 3

  • Advice and Guidance

Specialist advice (TECH) – Level 3 (Generic Level 3 descriptor)

Relationships and Engagement

  • Stakeholder Management
  • Stakeholder relationship management (RLMT) – Level 3 (Generic Level 3 descriptor)

Behaviours

We'll assess you against these behaviours during the selection process:

  • Changing and Improving

Technical skills

We'll assess you against these technical skills during the selection process:

  • Information Assurance (INAS) – Level 3
  • Information security (SCTY) – Level 3
  • Risk management (BURM) – Level 3
  • Specialist advice (TECH) – Level 3
  • Stakeholder relationship management (RLMT) – Level 3

Benefits

Alongside your salary of £49,850, Home Office contributes £14,441 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides .

Why work for us...

Find out more information at: Benefits - Home Office Careers, but some of the primary ones are:

  • A Civil Service Pension with employer contribution rates of at least 28.97%.
  • In-year reward scheme for one-off or sustained exceptional personal or team achievements.
  • 25 days annual leave on appointment, rising with service.
  • 8 days of public holidays, plus 1 additional privilege day.
  • Where business needs allow, some roles may be suitable for a combination of office and home-based working. This is a non-contractual arrangement where all employees will be expected to spend a minimum of 60% of their working time in an office.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Glasgow

Why this fits a police background — match score 70/100

  • Risk & threat assessment
  • Working to legislation & regulation

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Information Security Specialist

    Clyde & Co · Glasgow

    Full-time

    Department: Information Security Role: Information Security Specialist Key Responsibilities Training, Awareness & Human Risk The chosen candidate will be accountable for the successful delivery and continuous improvement of Clyde & Co's security awareness programme, owning the relationship with…

    Posted 7 days ago

  • Security Analyst - Risk

    student · Glasgow

    Full-time

    £38,314 – £45,176Estimated

    Your threat assessment and multi-agency coordination experience from policing directly enables this risk analysis role.

    Posted 22 days ago

  • Information Security Officer

    Police Scotland · Glasgow

    Contract

    Police Scotland is seeking an experienced Information Security professional to join our Information Security and Records Management team with a specialist focus on Data Loss Prevention (DLP).x This is an exciting opportunity for an individual with strong Information Security, Governance, Risk and…

    Posted 29 days ago

  • Full-time

    Your digital forensics and evidence-handling discipline from policing maps directly onto this insider risk investigation role.

    Posted 35 days ago