Head of Cyber Security Risk Management, Digital Identity in London

Head of Cyber Security Risk Management, Digital Identity in London

London Full-Time 75600 - 92400 £ / year (est.) No working from home possible
Government Digital Service

At a Glance

  • Tasks: Lead cyber security risk management for digital identity, ensuring safety and compliance.
  • Company: Join the Government Digital Service, shaping a modern digital government.
  • Benefits: Hybrid work, competitive salary, and opportunities for professional growth.
  • Other info: Collaborate with top digital professionals in a dynamic, impactful environment.
  • Why this job: Make a real impact on the UK's digital identity ecosystem and public services.
  • Qualifications: Experience in security governance and risk management; relevant certifications preferred.

The predicted salary is between 75600 - 92400 £ per year.

Location: Bristol, London, Manchester (HYBRID)

About the job

This role will require the post holder to have SC clearance to start and may be required to undergo Developed Vetting (DV) once in post, therefore successful candidates will be expected to either hold this or be willing to undertake the DV clearance process once in post.

The Government Digital Service (GDS) is the digital centre of government. We are responsible for setting, leading and delivering the vision for a modern digital government. Our priorities are to drive a modern digital government, by:

  • joining up public sector services
  • harnessing the power of AI for the public good
  • strengthening and extending our digital and data public infrastructure
  • elevating leadership and investing in talent
  • funding for outcomes and procuring for growth and innovation
  • committing to transparency and driving accountability

We are home to the Incubator for Artificial Intelligence (I.AI), the world-leading GOV.UK and at the forefront of coordinating the UK’s geospatial strategy and activity. We lead the Government Digital and Data function and champion the work of digital teams across government. We’re part of the Department for Science, Innovation and Technology (DSIT) and employ more than 1,000 people all over the UK, with hubs in Manchester, London and Bristol.

The Government Digital Service is where talent translates into impact. From your first day, you’ll be working with some of the world’s most highly-skilled digital professionals, all contributing their knowledge to make change on a national scale. Join us for rewarding work that makes a difference across the UK. You'll solve some of the nation’s highest-priority digital challenges, helping millions of people access services they need.

As Head of Cyber Security Risk Management for One Login and Digital Identity you will play a central role in protecting the UK’s current and future digital identity ecosystem. At scale, One Login will be the front door for millions of users to access digital public services. Security, reliability and resilience are absolutely critical to delivering our mission. This is a high profile role, suited to an experienced security leader with a track record of setting direction and running security risk, governance and assurance for a complex area.

As Head of Cyber Security Risk Management you will have oversight for the Digital Identity Cyber Information Assurance team, taking responsibility for the governance, risk management, compliance and 3rd party assurance. In addition, you will be responsible for:

  • Governance, risk and assurance leadership: building civil servant capability to run a mature, responsive cyber assurance team, working in collaboration with One Logins dedicated Security Operations, Security Design & Architecture, Pods (developer teams) and wider GDS and DSIT cyber teams. Work in partnership with GDS (Privacy, Information Assurance, Security Architecture, Cyber), GSG, CDIO Cyber, NCSC and other government departments.
  • Governance, risk and assurance: lead design, implementation and operating of information security governance frameworks aligned to DSIT and regulatory context. Ensure the team provides independent information assurance across the One Login Programme but work closely with the GDS Infosec team for second line assurance. Build and lead the third party and supply chain assurance strategy. Maintain and innovate the current risk management board ensuring present risk positions are clearly communicated to the senior leadership team (SLT).
  • Multi tier assurance: work closely with the GDS Infosec Team to support 2nd line assurance. Build and manage an integrated governance process which has a unified risk perspective enabling both first and second line assurance to work on a common understanding of the risk posture. Drive proactive engagement across both teams to stop any siloed forming and make sure the risk development lifecycle is balanced.
  • Policy & standards: develop and maintain security policies, standards frameworks, and governance processes aligned to government and industry best practice for complex cloud-native environments.
  • Assurance & remediation: drive security assurance activities across One Login programmes, suppliers, and operational services, including audits, assessments, and ensuring timely remediation within required SLOs.
  • Stakeholder collaboration: build strong relationships with key stakeholders—including GDS (Privacy, Information Assurance, Security Architecture), GSG, CDIO Cyber, and NCSC—to embed security into delivery, architecture, procurement, and operational decision making.
  • Compliance & frameworks: ensure all operations meet stringent UK Government security requirements by supporting regulatory and contractual compliance activities, including alignment to standards such as NIST, CAF, and GovAssure.
  • Governance & reporting: establish and maintain operational metrics to produce clear, meaningful reporting and dashboards that measure the programme's threat posture and support executive decision making.
  • Security culture leadership: working in close collaboration with the Head of Product Security and Head of Security Operations for One Login and the GDS CISO, take responsibility for embedding a robust security culture across the programme.

Person specification

We’re interested in people who have experience and knowledge of most of the following:

  • a strong track record of experience leading security governance, assurance, risk, or compliance functions, ideally for a Critical National Infrastructure (CNI) or comparable risk/profile/impact level product.
  • in-depth knowledge of government security standards, frameworks, and assurance approaches, with demonstrable success applying frameworks such as CAF, NIST 800-53, GovAssure, and Secure by Design Principles.
  • experience developing and implementing security policies and control frameworks in complex cloud-native environments and serverless architectures.
  • ability to communicate complex security concepts clearly and establish effective working relationships with key security stakeholders, including technical and non-technical specialists across organisational boundaries.
  • strong analytical, reporting, and risk management capabilities, including building governance dashboards and executive-level assurance reporting.
  • understanding of supplier assurance, vulnerability management, and experience integrating governance with security operational integration.
  • hold recognised cyber security certifications such as CISSP, CISM, or CRISC.

Note: DSIT cannot offer Visa sponsorship to candidates through this campaign. DSIT holds a Visa sponsorship licence but this can only be used for certain roles and this campaign does not qualify.

Head of Cyber Security Risk Management, Digital Identity in London employer: Government Digital Service

The Government Digital Service in Manchester is an exceptional employer, offering a dynamic work culture that prioritises innovation and collaboration. Employees benefit from opportunities for professional growth through mentorship and hands-on experience in cutting-edge cloud-native technologies, all while contributing to meaningful projects that enhance public services across the UK.

Government Digital Service

Contact Details:

Government Digital Service Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of Cyber Security Risk Management, Digital Identity in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Government Digital Service, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Government Digital Service

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Government Digital Service. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Head of Cyber Security Risk Management, Digital Identity in London

SC Clearance
Developed Vetting (DV) Clearance
Cyber Security Governance
Risk Management
Compliance Management
Information Assurance
Third Party Assurance

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Government Digital Service insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Government Digital Service that you’re committed to staying ahead in the game.

How to prepare for a job interview at Government Digital Service

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Government Digital Service to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Government Digital Service.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.