Cyber Security Supply Chain Risk Manager - Government Digital Service - G7 in Manchester

Cyber Security Supply Chain Risk Manager - Government Digital Service - G7 in Manchester

Manchester Full-Time 56070 - 64040 £ / year (est.) No working from home possible
Manchester Digital

At a Glance

  • Tasks: Manage cybersecurity risks in the supply chain and ensure compliance with industry standards.
  • Company: Join the Government Digital Service, leading digital transformation across the UK.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Dynamic role with excellent career advancement opportunities in a supportive environment.
  • Why this job: Make a real impact on national security while working with top digital professionals.
  • Qualifications: Experience in cybersecurity and supply chain management is essential.

The predicted salary is between 56070 - 64040 £ per year.

The Government Digital Service (GDS) is the digital centre of the government. We are responsible for setting, leading and delivering the vision of a digital modern government. Our priorities are to drive a modern digital government, by:

  • joining up public sector services
  • harnessing the power of AI for the public good
  • strengthening and extending our digital and data public infrastructure
  • elevating leadership and investing in talent
  • funding for outcomes and procuring for growth and innovation
  • committing to transparency and driving accountability

We are home to the Incubator for Artificial Intelligence (I.AI), the world-leading GOV.UK and at the forefront of coordinating the UK’s geospatial strategy and activity. We lead the Government Digital and Data function and champion the work of digital teams across government.

The Cyber Security Supply Chain Risk Manager is responsible for ensuring the security, integrity, and resilience of the organisation's supply chain in relation to cybersecurity risks. This role involves identifying and assessing cybersecurity risks within the supply chain, identifying suitable tender/contract security requirements/obligations to mitigate these risks, managing third-party vendor compliance with GDS’ specified security terms, and ensuring compliance/alignment with regulatory requirements and industry standards respectively. The Cyber Security Supply Chain Risk Manager will work cross-functionally with procurement, commercial, IT, risk management, engineering operations and legal departments to ensure that cybersecurity risks in the supply chain are understood and effectively managed throughout the supply chain lifecycle.

What you’ll do:

  • Cybersecurity Risk Assessment: conduct and manage comprehensive risk assessments of suppliers, vendors, and partners to identify and mitigate cybersecurity threats in the supply chain
  • Service Team Collaboration: support and assist Service Teams with the security aspects of their procurement needs, ensuring that appropriate information and cyber security requirements are included in tender documents, specifications and contracts; liaise with Commercial and Legal functions to ensure the requirements are included in tender and contract documentation
  • Vendor Due Diligence: collaborate with procurement and legal teams to assess vendor security practices during onboarding and throughout the vendor lifecycle to ensure third-party vendors comply with the organisation’s cybersecurity policies and standards
  • Supply Chain Risk Management (SCRM): develop and maintain a robust cybersecurity supply chain risk management (SCRM) program, including standardised supply chain risk logging, continuous monitoring, auditing, and evaluating third-party risk exposure individually, by category and in aggregate
  • Compliance and Standards: ensure supply chain activities comply with relevant cybersecurity frameworks and regulations (e.g., NCSC Cyber Assessment Framework, GovS007, ISO 27001, GDPR/DPA), implement best practices from industry standards to secure supply chain operations
  • Third-Party Contract Management: work with the legal and commercial teams to ensure cybersecurity clauses are included in supplier contracts; define key performance indicators (KPIs) and service level agreements (SLAs) around vendor cybersecurity responsibilities; periodically audit contracts for security terms, in order to understand any gaps in live contracts
  • Incident Response: support the development of processes and protocols for managing third-party cybersecurity incidents, including coordinating with vendors during a breach, ensuring timely communication, and mitigating the impact on the organisation
  • Vendor Cybersecurity Audits: lead or co-ordinate periodic cybersecurity audits of vendors and third parties to ensure they maintain high security standards, identify gaps and work with vendors to implement remediation plans
  • Training and Awareness: provide training and support to internal stakeholders on supply chain cybersecurity risks and vendor management best practices; increase awareness of supply chain threats and trends within the organisation
  • Collaboration and Communication: work closely with IT, risk, and procurement teams to communicate findings and recommended mitigations; ensure transparency and alignment between teams on cybersecurity risks and strategies
  • ‘Intelligent customer’ supply chain management: contribute to the working relationship and management of inter-government supply chain, for example, internal services provided by another government department
  • Supply Chain Resilience: develop strategies to ensure supply chain resilience in the face of cybersecurity threats, including supply chain mapping and diversification to mitigate risk
  • Monitoring and Reporting: continuously monitor the security posture of the supply chain and provide regular reports to leadership on third-party risk exposure, incidents, and mitigation efforts

Person specification:

We’re interested in people who have:

  • significant demonstrable experience in cybersecurity, supply chain management, and vendor/third-party risk management, including supply chain risk assessments and audits
  • experience working with cybersecurity frameworks, risk management methodologies, and compliance requirements (e.g., NCSC CAF, ISO 27001, SOC 2), with strong information and cyber security risk knowledge and experience
  • experience in managing cybersecurity for complex supply chains in sectors such as technology, healthcare, finance, or critical infrastructure, with the ability to identify and assess potential cybersecurity risks across the supply chain
  • in-depth knowledge of cybersecurity principles and how they apply to supply chain and third-party risk management, including familiarity with emerging threats such as cyber-physical risks, counterfeit hardware/software, and compromised components
  • strong understanding of supply chain operations, global supply chain regulations, and their intersection with cybersecurity policies, including integration of cybersecurity practices into procurement processes and supplier lifecycle/third-party vendor risk management
  • knowledge of cloud service providers, managed service providers (MSPs), and other third-party IT service ecosystems, and experience working with vendor management systems, supply chain management tools, and cybersecurity risk platforms
  • excellent communication and negotiation skills, with the ability to manage complex relationships with suppliers and vendors, and strong analytical skills to translate complex cybersecurity issues into actionable business terms
  • indicative professional qualifications / accreditations: a degree in Information Security, Information Technology, Business, or a related discipline (or equivalent professional experience), complemented by preferred professional certifications such as CISSP, CISM, CTPRP, or CSCP, with ISO 27001 Lead Auditor or Implementer qualifications considered advantageous

Cyber Security Supply Chain Risk Manager - Government Digital Service - G7 in Manchester employer: Manchester Digital

The Government Digital Service (GDS) is an exceptional employer, offering a dynamic work environment where talented professionals collaborate to drive impactful digital transformation across the UK. With a strong commitment to employee growth, GDS provides opportunities for continuous learning and development, alongside competitive salaries and benefits tailored to support a healthy work-life balance. Working in vibrant hubs located in Bristol, London, and Manchester, employees are part of a forward-thinking team dedicated to harnessing technology for public good, making every role meaningful and rewarding.

Manchester Digital

Contact Details:

Manchester Digital Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Security Supply Chain Risk Manager - Government Digital Service - G7 in Manchester

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Manchester Digital, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Manchester Digital

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Manchester Digital. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cyber Security Supply Chain Risk Manager - Government Digital Service - G7 in Manchester

Cybersecurity Risk Assessment
Supply Chain Risk Management (SCRM)
Vendor Due Diligence
Compliance and Standards
Incident Response
Vendor Cybersecurity Audits
Training and Awareness

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Manchester Digital insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Manchester Digital that you’re committed to staying ahead in the game.

How to prepare for a job interview at Manchester Digital

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Manchester Digital to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Manchester Digital.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.