- Company Name
- Manchester Digital
- Job Title
- Principal Cyber Risk Management and Assurance Advisor - GDS - G6
- Job Description
-
Job Title: Principal Cyber Risk Management and Assurance Advisor – GDS – G6
**Role Summary**
Lead cyber risk management, assurance, and architectural advisory for large‑scale government digital services. Oversee risk assessment, secure design, and compliance throughout the software development lifecycle, provide senior leadership briefings, and build internal capabilities for risk management.
**Expectations**
- Deliver detailed, high‑quality cyber security risk assessments and IT Health Checks for multi‑platform digital services, including SaaS tooling.
- Provide expert assurance across portfolio projects, aligning with business risk appetite.
- Act as a trusted advisor to senior stakeholders, delivering clear, actionable recommendations.
- Mentor and train cross‑disciplinary teams on secure design, threat modelling, and regulatory compliance.
- Facilitate and oversee Security Working Groups, ensuring risks are tracked, logged, and addressed.
**Key Responsibilities**
- Conduct and document formal risk assessments and risk treatment plans (RTPs) for all digital services and associated tooling.
- Perform IT Health Checks and deliver critical security assessments against NCSC Cloud Security Principles.
- Develop, review, and advise on Secure by Design policies/practices (e.g., OWASP, DPIA, GovAssure, safe AI use).
- Coordinate cross‑platform secure delivery, incident management, and continuous improvement of live service security.
- Produce regular risk briefings to senior leadership, mapping exposure, and recommending mitigations.
- Support implementation and maintenance of risk management tooling (e.g., SureCloud risk register).
- Build and sustain cross‑functional relationships, influence initiatives, and promote a security‑first culture.
- Lead training and mentoring of digital service teams and Information Security staff.
**Required Skills**
- Proven experience delivering comprehensive cyber security risk assessments and assurance in large, complex digital environments (government preferred).
- Deep knowledge of cyber risk management, threat modelling, security architecture, and SaaS/cloud security principles.
- Ability to interpret and apply cyber security standards, regulatory frameworks, and secure‑by‑design principles.
- Strong analytical, written, verbal, and interpersonal communication skills; capable of translating technical findings for executive audiences.
- Demonstrated capability to lead cross‑functional initiatives, brief senior stakeholders, and influence decision‑making.
- Commitment to continuous learning, mentoring, and capability building.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent professional experience).
- Professional certifications such as CISSP, CISA, CRISC, or equivalent cyber security credentials preferred.
Manchester, United kingdom
On site
Senior
25-11-2025