Cyber Security Risk Manager

Cyber Security Risk Manager

Newcastle upon Tyne Full-Time 35000 - 60000 £ / year (est.) Home office (partial)
Go Premium
H

At a Glance

  • Tasks: Lead security for HMRC's Cloud Environment, ensuring risks are managed and compliance is maintained.
  • Company: Join HMRC, a diverse team dedicated to redefining digital services in the UK.
  • Benefits: Enjoy flexible working, generous leave, and a strong pension contribution.
  • Why this job: Be part of a dynamic team making a real impact in cyber security.
  • Qualifications: Experience with cloud tech, security governance, and vulnerability scanning tools required.
  • Other info: Office presence needed 60% of the time; travel to Telford expected.

The predicted salary is between 35000 - 60000 £ per year.

Discover a career in your hands at HMRC. Whether you’re seeking purpose, growth, or a workplace that gives you a true sense of belonging, hear from some of our employees as they share their story about what it’s really like to work at HMRC.

Within HMRC’s Chief Digital & Information Group (CDIO), specifically in the Enterprise Cloud Services (ECS) team we are redefining and growing a team of outstanding people to improve its HMRC Cloud Centre of Excellence offering. We are already a diverse team of 80+ individuals, creating a dynamic and inclusive working environment whose skills cover Architecture, Development, Service Design, Operation and Governance.

We are looking for someone who will be responsible for the security aspects for supporting the development and operations of HMRC’s Cloud Environment. This is a key role that will undertake and feed into governance and compliance activities of HMRC Cloud Services and delivery activities within the ECS Security and other processes. You will work directly with the Security Lead and the Security Architect, Cyber Security Technical Services (CSTS) team, and across the ECS capability functions to ensure that security is built into and maintained within HMRC cloud services, including the identification, and management of our risks. Travel to Telford is expected as part of this role, and 60% of your working time will need to be office based.

As the Cyber Security Risk Manager within HMRC’s Enterprise Cloud Services (ECS), you’ll be a central figure in driving security excellence. Acting as the first point of contact for all internal ECS security queries, advice, and guidance, you’ll also lead vulnerability assessments across ECS products, ensuring risks are identified, communicated, and addressed effectively. You’ll play a hands-on role in shaping ECS security policies, supporting penetration testing, and guiding teams on secure service delivery. With a deep understanding of security and risk management, you’ll use evidence, data, and experience to make well-informed decisions that protect HMRC’s cloud infrastructure.

Key Responsibilities:

  • Serve as the primary contact for ECS security advice, guidance, and support.
  • Lead the review, assessment, and reporting of vulnerabilities in ECS products.
  • Support penetration testing activities and advise on ECS service request risks.
  • Develop and maintain ECS-specific security policies and procedures.
  • Monitor compliance with governance controls and produce Risk Treatment Plans.
  • Report and manage security incidents in line with HMRC and ECS procedures.
  • Support internal and external audits.

We’re looking for a motivated self-starter who thrives both independently and as part of a small team. You’ll have a strong technical background in security and be able to mentor others, translating complex security concepts into clear guidance for a range of stakeholders.

Essential Criteria:

  • Experience working with cloud technologies, particularly AWS and Azure.
  • Proven background in security governance, compliance, and audit practices.
  • Familiarity with ISO 27001, Risk Management, and GDPR frameworks.
  • Proficient in vulnerability scanning tools such as Microsoft Defender for Cloud, Tenable.sc, and AWS Security Hub.
  • Strong stakeholder management skills, with experience working across diverse teams.

Desirable Criteria:

  • Knowledge of technical, procedural, physical, and personnel-based security controls.
  • Experience in security monitoring, testing, and incident response.
  • Familiarity with risk assessment methodologies and security management systems.

Desirable Qualifications (or Willingness To Work Towards):

  • AWS: Cloud Practitioner, Security Specialty.
  • Azure: Fundamentals, Security Engineer.
  • Security Frameworks: EU/UK GDPR, ISO 27001, ISO 27005 Risk Manager.
  • Certifications: CISMP (Certificate in Information Security Management Principles).

Must already hold or be eligible to obtain Security Check (SC) clearance.

Behaviours:

  • Changing and Improving
  • Communicating and Influencing
  • Making Effective Decisions

Alongside your salary of £44,110, HM Revenue and Customs contributes £12,778 towards you being a member of the Civil Service Defined Benefit Pension scheme. HMRC operates both Flexible and Hybrid Working policies, allowing you to balance your work and personal commitments. We welcome applications from those who need to work a more flexible arrangement and will agree to requests where possible, considering our operational and customer service needs.

We offer a generous leave allowance, starting at 25 days and increasing by a day for every year of qualifying service up to a maximum of 30 days. Pension - We make contributions to our colleagues’ Alpha pension equal to at least 28.97% of their salary. Family friendly policies. Personal support. Coaching and development.

To find out more about HMRC benefits and find out what it’s really like to work for HMRC hear from our insiders or visit Thinking of joining the Civil Service.

Selection process details:

This vacancy is using Success Profiles, and will assess your Behaviours and Experience.

How To Apply:

As part of the application process, you will be asked to provide the following:

  • A name-blind CV including your job history and previous experiences.
  • Your CV will be scored against the experience required outlined in the advert.
  • A 500-word personal statement outlining how your skills and experience match the specification detailed in the job description and the essential criteria.
  • A separate statement (Max 250 words) for the Desirable Criteria where applicable.

Further details around what this will entail are listed on the application form.

We acknowledge that AI can assist you in your application. Find our guidelines here.

Sift:

At sift, your CV and Personal Statement will be assessed, with the successful candidates being invited to interview. We may also raise the score required at any stage of the process if we receive a high number of applications.

Interview:

The interview will be based on behaviours and the skills and experience outlined within the Job Specification and suitability for the role. You will also be assessed against the Essential Criteria. Interviews will take place virtually. Sift and interview dates to be confirmed.

Eligibility:

Please Take Extra Care To Tick The Correct Boxes In The Eligibility Sections Of Your Application Form.

A reserve list may be held for up to 6 months from which further appointments may be made for the same or similar roles.

Applications received from candidates with a criminal record are considered fairly in accordance with the DBS Code of Practice and the Recruitment of ex-offenders Policy.

We want to make sure no one is put at a disadvantage during our recruitment process. To assist you with this, we will reduce or remove any barriers where possible and provide additional support where appropriate.

If you need a change to be made so that you can make your application, you should contact the UBS Recruitment team as soon as possible before the closing date to discuss your needs.

Please note: in addition to the standard pre-employment checks for appointment into the Civil Service, all candidates must also obtain National Security Vetting at Security Check (SC) clearance level for this vacancy.

Important information for existing HMRC contractual homeworkers: This role is unsuitable for contractual homeworkers due to the nature and/or requirements of the role.

We are looking into ways to enhance the applicant experience. As part of our legitimate interests, we are testing the use of new technologies such as automation and/or Artificial Intelligence in the assessment for CV, personal statement and behaviour statement.

Customer facing roles in HMRC require the ability to converse at ease with members of the public and provide advice in accurate spoken English and/or Welsh where required.

The Civil Service values honesty and integrity and expects all candidates to abide by these principles.

Any instances of plagiarism or other forms of cheating will be investigated and, if proven, the relevant application(s) will be withdrawn from the process.

Recording of interviews is prohibited unless explicit agreement is sought in line with the UK General Data Protection Regulations.

Successful candidates must undergo a criminal record check.

Successful candidates must meet the security requirements before they can be appointed.

This Job Is Broadly Open To The Following Groups: UK nationals, nationals of the Republic of Ireland, nationals of Commonwealth countries who have the right to work in the UK, nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS).

The Civil Service embraces diversity and promotes equal opportunities.

Cyber Security Risk Manager employer: HM Revenue & Customs

At HMRC, we pride ourselves on being an exceptional employer, offering a dynamic and inclusive work culture that fosters personal and professional growth. As a Cyber Security Risk Manager in our Enterprise Cloud Services team, you'll benefit from flexible and hybrid working policies, generous leave allowances, and a robust pension scheme, all while contributing to the security of vital government services. Join us in Bristol, Newcastle-upon-Tyne, or Telford, where your expertise will be valued, and your career aspirations supported in a meaningful way.
H

Contact Detail:

HM Revenue & Customs Recruiting Team

unitybusinessservicesrecruitmentresults@hmrc.gov.uk

StudySmarter Expert Advice 🤫

We think this is how you could land Cyber Security Risk Manager

✨Tip Number 1

Familiarise yourself with HMRC's Cloud Centre of Excellence and its current security policies. Understanding their specific needs and challenges will help you tailor your approach during interviews and discussions.

✨Tip Number 2

Network with current or former employees of HMRC, especially those in the ECS team. They can provide valuable insights into the company culture and expectations, which can be beneficial for your application.

✨Tip Number 3

Stay updated on the latest trends and technologies in cloud security, particularly around AWS and Azure. Being able to discuss recent developments or case studies can demonstrate your expertise and enthusiasm for the role.

✨Tip Number 4

Prepare to showcase your stakeholder management skills. Think of examples where you've successfully communicated complex security concepts to diverse teams, as this is a key aspect of the Cyber Security Risk Manager role.

We think you need these skills to ace Cyber Security Risk Manager

Cloud Security Management
Risk Assessment and Management
Vulnerability Assessment
Security Governance
Compliance Monitoring
Incident Response Management
Stakeholder Engagement
Penetration Testing Support
Knowledge of ISO 27001
Familiarity with GDPR Framework
Proficiency in Vulnerability Scanning Tools
Technical Writing for Security Policies
Data Analysis for Risk Reporting
Strong Communication Skills
Team Leadership and Mentoring

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights your experience with cloud technologies, security governance, and compliance. Use specific examples from your previous roles that align with the key responsibilities of the Cyber Security Risk Manager position.

Craft a Strong Personal Statement: In your 500-word personal statement, clearly outline how your skills and experiences meet the essential criteria listed in the job description. Be specific about your background in security risk management and your familiarity with relevant frameworks like ISO 27001 and GDPR.

Address Desirable Criteria: If applicable, write a separate statement (max 250 words) addressing the desirable criteria. Highlight any additional qualifications or experiences that could set you apart from other candidates, such as certifications in AWS or Azure.

Proofread and Format: Before submitting your application, proofread all documents for spelling and grammatical errors. Ensure your CV is formatted neatly and is easy to read. A well-organised application reflects professionalism and attention to detail.

How to prepare for a job interview at HM Revenue & Customs

✨Understand the Role

Make sure you thoroughly understand the responsibilities of a Cyber Security Risk Manager. Familiarise yourself with HMRC's Cloud Services and the specific security challenges they face. This will help you articulate how your skills align with their needs.

✨Showcase Your Technical Skills

Be prepared to discuss your experience with cloud technologies, especially AWS and Azure. Highlight your familiarity with security governance frameworks like ISO 27001 and GDPR, as well as any tools you've used for vulnerability scanning.

✨Prepare for Behavioural Questions

Since the interview will assess your behaviours, think of examples that demonstrate your ability to change and improve processes, communicate effectively, and make sound decisions under pressure. Use the STAR method (Situation, Task, Action, Result) to structure your responses.

✨Ask Insightful Questions

Prepare thoughtful questions about HMRC's approach to security and risk management. This shows your genuine interest in the role and helps you gauge if the company culture aligns with your values.

Cyber Security Risk Manager
HM Revenue & Customs
Location: Newcastle upon Tyne
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

H
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>