Cyber & Corporate Risk Officer in Birmingham

Cyber & Corporate Risk Officer in Birmingham

Birmingham Full-Time No working from home possible
Slide to start your application
Start application
N

Job summaryWe are seeking a Cyber & Corporate Risk Officer to join the UKHSA Cyber Security team. This is an exciting opportunity to become a central part of this build and support the continuous development of the Cyber Governance Risk & Compliance function, provide strategic direction whilst managing the challenges and drive improvement and delivery of services.Cyber is building on its capability to provide a critical function in the protection of the UKHSAs digital assets, working closely with wider UKHSA security teams and stakeholders Government Security Group, National Cyber Security Centre (NCSC) and National Protective Security Authority (NPSA) to build a resilient infrastructure, supporting the organisation in reaching its ambition to become a global leader for health security and become a critical component of our national security infrastructure.For this role successful candidates must meet the security requirements before they can be appointed. The level of security needed is Security Check (SC).For meaningful National Security Vetting checks to be carried out individuals need to have lived in the UK for a sufficient period of time. You should normally have been resident in the United Kingdom for the last 5 years as the role requires SC clearance. UK residency less than the outlined periods may not necessarily bar you from gaining national security vetting and applicants should contact the Resourcing Support listed in this advert for further advice.Main duties of the jobThe Cyber & Corporate Risk Officer will coordinate and deliver security risk management activity within enabling a clear and realistic view of security risk across Cyber. They will support the delivery of Second Line Cyber Risk Assurance (CRA) across the UKHSA, reporting to the SEO Senior Cyber Risk Officer. The role will require a level of independent oversight, and work stream responsibility for focussing on a particular business area to include IACS and Harlow, supporting the programmes in the creation of a single overview of the cyber risk helping to ensure that they are clearly understood and managed in line with UKHSA's risk appetite, government standards, and public sector assurance expectations, managing escalation in line with UKHSA processes.As second line assurance, the role does not implement or operate cyber security controls, but helps to support UKHSA leadership by:Providing confidence that cyber risks are identified, understood, and escalated appropriatelyStrengthening transparency, governance, and assuranceProtecting the Agency's ability to deliver vital health security outcomesThis role offers experience of cyber risk in a complex field presenting a number of learning and developmental opportunities, all of which support UKHSA's critical health security mission.This is not an exhaustive list.About usWe pride ourselves as being an employer of choice, where Everyone Matters promoting equality of opportunity to actively encourage applications from everyone, including groups currently underrepresented in our workforce.UKHSA ethos is to be an inclusive organisation for all our staff and stakeholders. To create, nurture and sustain an inclusive culture, where differences drive innovative solutions to meet the needs of our workforce and wider communities. We do this through celebrating and protecting differences by removing barriers and promoting equity and equality of opportunity for all.Please visit our careers site for more information https://gov.uk/ukhsa/careersDetailsDate posted01 September 2026Pay schemeOtherSalary 33,422 to 45,353 a year Per annum, pro-rata ContractPermanentWorking pattern Full-time, Part-time, Job share, Flexible working Reference number919-SH-62190973-EXTJob locationsHybrid working based at any core HQBirmingham, Leeds, Liverpool, London Canary WharfE14 4PUUnited KingdomJob descriptionJob responsibilitiesThe Cyber & Corporate Risk Officer must be comfortable to work flexibly and operate in a highly ambiguous environment while the Agency continues its transformation journey and defines its organisational culture. The ability to identify and understand challenges to find creative solutions will be critical as will strength in managing and building relationships across the organisation, undertaking effective collaboration at fast pace, both internally and externally to UKHSA. They will be expected to work on their own initiative without micro-management but know when to revert to seek a steer or decision. This is a dynamic and challenging environment, and they will need to be confident in managing complexity, applying judgement, and making decisions whilst collaborating effectively with other members of the team and across the organisation. This role will requires working with cyber team members of staff who are predominantly home-based workers.Second Line Cyber Risk SupportSupport the delivery of Second Line oversight and challenge of cyber and technology risksAssist in reviewing First Line cyber risk assessments, control documentation, and mitigation plansEnsure cyber risks are recorded clearly and consistently within UKHSA risk registers and toolingHelp differentiate between risk ownership (First Line) and risk assurance (Second Line) activitiesCyber Risk Framework & StandardsSupport the maintenance of UKHSAs Cyber Risk Management FrameworkAssist in assessing cyber risks against: Government Security Policy Framework (SPF)DSPT Cyber Assurance FrameworkNCSC guidanceISO 27001 / NIST aligned approachesPromote a proportionate, risk-based approach to cyber security across the organisationGovernance & ReportingContribute to cyber risk reporting for senior management and assurance forumsAnalyse cyber risk data, trends, and Key Risk Indicators (KRIs)Help translate technical cyber security issues into clear risk narratives focused on business and health impactSupport preparation of papers and briefing materials for senior stakeholdersChange & Third Party Risk AssuranceSupport cyber risk assurance activities related to: Digital and data change initiativesCloud services and shared platformsThird party and supplier arrangementsAssist with identifying emerging cyber risks early in the change lifecycleLearning, Assurance & Continuous ImprovementSupport post incident reviews and lessons learned activities from a risk perspectiveContribute to assurance exercises, internal reviews, and audit engagementBuild cyber risk knowledge and capability through on the job learning, mentoring, and formal developmentThe above is only an outline of the tasks, responsibilities and outcomes required of the role. You will carry out any other duties as may reasonably be required by your line manager.The job description and person specification may be reviewed on an ongoing basis in accordance with the changing needs of the organisation.Essential CriteriaExperience or strong interest in Cyber Risk Management, Information Security, Technology Risk, or GRCAwareness of cyber security threats, vulnerabilities, and controlsAbility to analyse information and present risks clearly and conciselyStrong written and verbal communication skillsWillingness to provide constructive challenge while building effective working relationshipsDesirable CriteriaKnowledge of: Government Security Policy FrameworkNCSC principlesRisk registers and assurance reportingDSPT Cyber Assessment FrameworkIndustrial Automated Control SystemsSelection Process DetailsThis vacancy is using Success Profiles Success Profiles - GOV.UKand will assess your Behaviours, Experience and Technical Skills.Stage 1: Application & SiftAt sift stage you will be assessed against the 5 Essential Criteria listed in this job advert. You will be required to complete:An Application Form (Employer/Activity history section on the application)A 1000 word Supporting Statement - do not exceed 1000 words as we will not consider any words over and above this numberThis should outline how you consider your skills, experience and knowledge provide evidence of your suitability for the role, with reference to the 5 Essential Criteria listed in this advert.You will receive a joint score for your application form and statement. The application form is the kind of information you would put into your CV please note you will not be able to upload or email us your CV. Please complete the application form in as much detail as possible.LonglistingIn the event of a large number of applications, we may longlist into 3 piles of:Meets all Essential CriteriaMeets some Essential CriteriaMeets no Essential CriteriaOnly those that 'Meets all Essential Criteria' will progress to Shortlisting.ShortlistingIn the event of a large number of applications, we may conduct an initial sift on the following Essential Criteria:Experience or strong interest in Cyber Risk Management, Information Security, Technology Risk, or GRCDesirable criteria may be used in the event of a large number of applications/successful candidates.If you are successful at this stage, you will progress to interview and assessment.Feedback will not be provided at this stage.Stage 2: InterviewYou will be invited to a single remote interview. Interview date(s) to be confirmed.Behaviours and Technical Skills will be tested at interview.The Behaviours being tested at interview stage will be:Working Together - Lead BehaviourCommunication and InfluencingMaking Effective DecisionsDeveloping Self and OthersYou will be required to give a 10-minute technical presentation on a cyber risk management topic. The exact title will be confirmed when successful candidates are invited to interview.Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.Eligibility CriteriaOpen to all external applicants (anyone) from outside the Civil Service (including internal applicants).Salary InformationCivil Service: Higher Executive Officer (HEO)HEO Inner: 37,749 - 45,353HEO Outer: 35,587 - 43,244HEO National: 33,422 - 40,731Per annum, pro-rataPlease be aware that the salary is based on the office location.If you are successful at interview, and are moving from another government department, NHS, or Local Authority, the relevant starting salary principles for level transfers or promotions will apply. Otherwise, roles are offered at the pay scale minimum for the grade, but in exceptional circumstances there may be flexibility if you are able to demonstrate you are already in receipt of an existing, higher salary. Pay increases are through the relevant annual pay award for the role and terms.LocationThis role is being offered as hybrid working based at any of our core HQs in Birmingham, Leeds, Liverpool, London Canary Wharf.Travel to our Scientific Campus in Porton, Didcot and North London will be required when needed.We offer great flexible working opportunities at UKHSA and operate using a hybrid working model where business needs allow. This provides us with greater flexibility about how and where we work, to get the best from our workforce. As a hybrid worker, you will be expected to spend a minimum of 60% of your contractual working hours (approximately 3 days a week pro rata, (averaged over a month) working at one of UKHSA's core HQs (Birmingham, Leeds, Liverpool, and London).Our core HQ offices are modern and newly refurbished with excellent city centre transport links and benefit from co-location with other government departments such as the Department for Health and Social Care (DHSC).Security Clearance Level RequirementSuccessful candidates must pass a basic disclosure and barring security check.For this role successful candidates must meet the security requirements before they can be appointed. The level of security needed is Security Check (SC).For meaningful National Security Vetting checks to be carried out individuals need to have lived in the UK for a sufficient period of time. You should normally have been resident in the United Kingdom for the last 5 years as the role requires SC clearance. UK residency less than the outlined periods may not necessarily bar you from gaining national security vetting and applicants should contact the Resourcing Support listed in this advert for further advice. Job description Job responsibilitiesThe Cyber & Corporate Risk Officer must be comfortable to work flexibly and operate in a highly ambiguous environment while the Agency continues its transformation journey and defines its organisational culture. The ability to identify and understand challenges to find creative solutions will be critical as will strength in managing and building relationships across the organisation, undertaking effective collaboration at fast pace, both internally and externally to UKHSA. They will be expected to work on their own initiative without micro-management but know when to revert to seek a steer or decision. This is a dynamic and challenging environment, and they will need to be confident in managing complexity, applying judgement, and making decisions whilst collaborating effectively with other members of the team and across the organisation. This role will requires working with cyber team members of staff who are predominantly home-based workers.Second Line Cyber Risk SupportSupport the delivery of Second Line oversight and challenge of cyber and technology risksAssist in reviewing First Line cyber risk assessments, control documentation, and mitigation plansEnsure cyber risks are recorded clearly and consistently within UKHSA risk registers and toolingHelp differentiate between risk ownership (First Line) and risk assurance (Second Line) activitiesCyber Risk Framework & StandardsSupport the maintenance of UKHSAs Cyber Risk Management FrameworkAssist in assessing cyber risks against: Government Security Policy Framework (SPF)DSPT Cyber Assurance FrameworkNCSC guidanceISO 27001 / NIST aligned approachesPromote a proportionate, risk-based approach to cyber security across the organisationGovernance & ReportingContribute to cyber risk reporting for senior management and assurance forumsAnalyse cyber risk data, trends, and Key Risk Indicators (KRIs)Help translate technical cyber security issues into clear risk narratives focused on business and health impactSupport preparation of papers and briefing materials for senior stakeholdersChange & Third Party Risk AssuranceSupport cyber risk assurance activities related to: Digital and data change initiativesCloud services and shared platformsThird party and supplier arrangementsAssist with identifying emerging cyber risks early in the change lifecycleLearning, Assurance & Continuous ImprovementSupport post incident reviews and lessons learned activities from a risk perspectiveContribute to assurance exercises, internal reviews, and audit engagementBuild cyber risk knowledge and capability through on the job learning, mentoring, and formal developmentThe above is only an outline of the tasks, responsibilities and outcomes required of the role. You will carry out any other duties as may reasonably be required by your line manager.The job description and person specification may be reviewed on an ongoing basis in accordance with the changing needs of the organisation.Essential CriteriaExperience or strong interest in Cyber Risk Management, Information Security, Technology Risk, or GRCAwareness of cyber security threats, vulnerabilities, and controlsAbility to analyse information and present risks clearly and conciselyStrong written and verbal communication skillsWillingness to provide constructive challenge while building effective working relationshipsDesirable CriteriaKnowledge of: Government Security Policy FrameworkNCSC principlesRisk registers and assurance reportingDSPT Cyber Assessment FrameworkIndustrial Automated Control SystemsSelection Process DetailsThis vacancy is using Success Profiles Success Profiles - GOV.UKand will assess your Behaviours, Experience and Technical Skills.Stage 1: Application & SiftAt sift stage you will be assessed against the 5 Essential Criteria listed in this job advert. You will be required to complete:An Application Form (Employer/Activity history section on the application)A 1000 word Supporting Statement - do not exceed 1000 words as we will not consider any words over and above this numberThis should outline how you consider your skills, experience and knowledge provide evidence of your suitability for the role, with reference to the 5 Essential Criteria listed in this advert.You will receive a joint score for your application form and statement. The application form is the kind of information you would put into your CV please note you will not be able to upload or email us your CV. Please complete the application form in as much detail as possible.LonglistingIn the event of a large number of applications, we may longlist into 3 piles of:Meets all Essential CriteriaMeets some Essential CriteriaMeets no Essential CriteriaOnly those that 'Meets all Essential Criteria' will progress to Shortlisting.ShortlistingIn the event of a large number of applications, we may conduct an initial sift on the following Essential Criteria:Experience or strong interest in Cyber Risk Management, Information Security, Technology Risk, or GRCDesirable criteria may be used in the event of a large number of applications/successful candidates.If you are successful at this stage, you will progress to interview and assessment.Feedback will not be provided at this stage.Stage 2: InterviewYou will be invited to a single remote interview. Interview date(s) to be confirmed.Behaviours and Technical Skills will be tested at interview.The Behaviours being tested at interview stage will be:Working Together - Lead BehaviourCommunication and InfluencingMaking Effective DecisionsDeveloping Self and OthersYou will be required to give a 10-minute technical presentation on a cyber risk management topic. The exact title will be confirmed when successful candidates are invited to interview.Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.Eligibility CriteriaOpen to all external applicants (anyone) from outside the Civil Service (including internal applicants).Salary InformationCivil Service: Higher Executive Officer (HEO)HEO Inner: 37,749 - 45,353HEO Outer: 35,587 - 43,244HEO National: 33,422 - 40,731Per annum, pro-rataPlease be aware that the salary is based on the office location.If you are successful at interview, and are moving from another government department, NHS, or Local Authority, the relevant starting salary principles for level transfers or promotions will apply. Otherwise, roles are offered at the pay scale minimum for the grade, but in exceptional circumstances there may be flexibility if you are able to demonstrate you are already in receipt of an existing, higher salary. Pay increases are through the relevant annual pay award for the role and terms.LocationThis role is being offered as hybrid working based at any of our core HQs in Birmingham, Leeds, Liverpool, London Canary Wharf.Travel to our Scientific Campus in Porton, Didcot and North London will be required when needed.We offer great flexible working opportunities at UKHSA and operate using a hybrid working model where business needs allow. This provides us with greater flexibility about how and where we work, to get the best from our workforce. As a hybrid worker, you will be expected to spend a minimum of 60% of your contractual working hours (approximately 3 days a week pro rata, (averaged over a month) working at one of UKHSA's core HQs (Birmingham, Leeds, Liverpool, and London).Our core HQ offices are modern and newly refurbished with excellent city centre transport links and benefit from co-location with other government departments such as the Department for Health and Social Care (DHSC).Security Clearance Level RequirementSuccessful candidates must pass a basic disclosure and barring security check.For this role successful candidates must meet the security requirements before they can be appointed. The level of security needed is Security Check (SC).For meaningful National Security Vetting checks to be carried out individuals need to have lived in the UK for a sufficient period of time. You should normally have been resident in the United Kingdom for the last 5 years as the role requires SC clearance. UK residency less than the outlined periods may not necessarily bar you from gaining national security vetting and applicants should contact the Resourcing Support listed in this advert for further advice.Person Specification Application Form & Supporting Statement EssentialApplication Form & Supporting Statement Behaviours EssentialWorking Together - Lead BehaviourCommunication and InfluencingMaking Effective DecisionsDeveloping Self and Others Technical Skills EssentialPresentation: You will be required to give a 10-minute technical presentation on a cyber risk management topic. Person Specification Application Form & Supporting Statement EssentialApplication Form & Supporting Statement Behaviours EssentialWorking Together - Lead BehaviourCommunication and InfluencingMaking Effective DecisionsDeveloping Self and Others Technical Skills EssentialPresentation: You will be required to give a 10-minute technical presentation on a cyber risk management topic.Disclosure and Barring Service CheckThis post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.Certificate of SponsorshipApplications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab). Additional information Disclosure and Barring Service CheckThis post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.Certificate of SponsorshipApplications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).Employer detailsEmployer nameUK Health Security AgencyAddressHybrid working based at any core HQBirmingham, Leeds, Liverpool, London Canary WharfE14 4PUUnited KingdomEmployer's websiteEmployer detailsEmployer nameUK Health Security AgencyAddressHybrid working based at any core HQBirmingham, Leeds, Liverpool, London Canary WharfE14 4PUUnited KingdomEmployer's website

Cyber & Corporate Risk Officer in Birmingham employer: National Health Service

Betsi Cadwaladr University Health Board is an exceptional employer, offering a supportive and collaborative work environment for healthcare professionals in North Wales. With a commitment to employee development and a focus on compassionate care, staff have access to continuous professional development opportunities and the chance to make a meaningful impact in both acute and community paediatrics. The Health Board's integrated approach ensures that employees are part of a dynamic team dedicated to improving health outcomes for the local population.

N

Contact Details:

National Health Service Recruitment Team