Head of Cyber Security Risk Management, Digital Identity

Government Digital and Data

Location Bristol, London, Manchester
Job grade Grade 6
Contract type Permanent
Working pattern Flexible working, Full-time, Job share, Part-time, Compressed hours
Salary £70,175 - £87,305
Closing date Mon 31 Aug 2026
Reference 475458
Profession Digital, Data & Technology
Apply now

As Head of Cyber Security Risk Management for One Login and Digital Identity you will play a central role in protecting the UK’s current and future digital identity ecosystem. At scale, One Login will be the front door for millions of users to access digital public services. Security, reliability and resilience are absolutely critical to delivering our mission. This is a high profile role, suited to an experienced security leader with a track record of setting direction and running security risk, governance and assurance for a complex area. 

As Head of Cyber Security Risk Management you will have oversight for the Digital Identity Cyber Information Assurance team, taking responsibility for the governance, risk management, compliance and 3rd party assurance. In addition, you will be responsible for: 

  • Governance, risk and assurance leadership: building civil servant capability to run a mature, responsive cyber assurance team, working in collaboration with One Logins dedicated Security Operations, Security Design & Architecture, Pods (developer teams) and wider GDS and DSIT cyber teams. Work in partnership with GDS (Privacy, Information Assurance, Security Architecture, Cyber), GSG, CDIO Cyber, NCSC and other government departments
  • Governance, risk and assurance: lead design, implementation and operating of information security governance frameworks aligned to DSIT and regulatory context. Ensure the team provides independent information assurance across the One Login Programme but work closely with the GDS Infosec team for second line assurance. Build and lead the third party and supply chain assurance strategy. Maintain and innovate the current risk management board ensuring present risk positions are clearly communicated to the senior leadership team (SLT).
  • Multi-tier assurance: work closely with the GDS Infosec Team to support 2nd line assurance. Build and manage an integrated governance process which has a unified risk perspective enabling both first and second line assurance to work on a common understanding of the risk posture. Drive proactive engagement across both teams to stop any siloed forming and make sure the risk development lifecycle is balanced. 
  • Policy & standards: develop and maintain security policies, standards frameworks, and governance processes aligned to government and industry best practice for complex cloud-native environments
  • Assurance & remediation: drive security assurance activities across One Login programmes, suppliers, and operational services, including audits, assessments, and ensuring timely remediation within required SLOs
  • Stakeholder collaboration: build strong relationships with key stakeholders—including GDS (Privacy, Information Assurance, Security Architecture), GSG, CDIO Cyber, and NCSC—to embed security into delivery, architecture, procurement, and operational decision making
  • Compliance & frameworks: ensure all operations meet stringent UK Government security requirements by supporting regulatory and contractual compliance activities, including alignment to standards such as NIST, CAF, and GovAssure
  • Governance & reporting: establish and maintain operational metrics to produce clear, meaningful reporting and dashboards that measure the programme's threat posture and support executive decision making
  • Security culture leadership: working in close collaboration with the Head of Product Security and Head of Security Operations for One Login and the GDS CISO, take responsibility for embedding a robust security culture across the programme.

Person specification

We’re interested in people who have experience and knowledge of most of the following: 

  • a strong track record of experience leading security governance, assurance, risk, or compliance functions, ideally for a Critical National Infrastructure (CNI) or comparable risk/profile/impact level product
  • in-depth knowledge of government security standards, frameworks, and assurance approaches, with demonstrable success applying frameworks such as CAF, NIST 800-53, GovAssure, and Secure by Design Principles
  • experience developing and implementing security policies and control frameworks in complex cloud-native environments and serverless architectures
  • ability to communicate complex security concepts clearly and establish effective working relationships with key security stakeholders, including technical and non-technical specialists across organisational boundaries
  • strong analytical, reporting, and risk management capabilities, including building governance dashboards and executive-level assurance reporting
  • understanding of supplier assurance, vulnerability management, and experience integrating governance with security operational integration.
  • hold recognised cyber security certifications such as CISSP, CISM, or CRISC 

Benefits

There are many benefits of working at GDS, including:

  • flexible hybrid working with flexi-time and the option to work part-time or condensed hours
  • a Civil Service Pension with an average employer contribution of 28.97%
  • 25 days of annual leave, increasing by a day each year up to a maximum of 30 days
  • an extra day off for the King’s birthday
  • an in-year bonus scheme to recognise high performance
  • career progression and coaching, including a training budget for personal development
  • a focus on wellbeing with access to an employee assistance programme
  • job satisfaction from making government services easier to use and more inclusive for people across the UK
  • advances on pay, including for travel season tickets
  • death in service benefits
  • cycle to work scheme and facilities
  • access to an employee discounts scheme
  • 10 learning days per year
  • volunteering opportunities (5 special leave days per year)
  • access to a suite of learning activities through Civil Service learning


Any move to Government Digital Service from another employer will mean you can no longer access childcare vouchers. This includes moves between government departments. You may however be eligible for other government schemes, including Tax Free Childcare. Determine your eligibility at https://www.childcarechoices.gov.uk  

Office attendance
The Department operates a discretionary hybrid working policy, which provides for a combination of working hours from your place of work and from your home in the UK. The current expectation for staff is to attend the office or non-home based location for 40-60% of the time over the accounting period.
DSIT does not normally offer full home working (i.e. working at home); but we do offer a variety of flexible working options (including occasionally working from home). 

Things you need to know

Artificial intelligence

Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.

Selection process details

This role will require the post holder to have SC clearance to start and may be required to undergo Developed Vetting (DV) once in post, therefore successful candidates will be expected to either hold this or be willing to undertake the DV clearance process once in post.

More information on DV clearance is linked here

The standard selection process for roles at GDS consists of:

  • a simple application screening process - We only ask for a CV and cover letter of up to 750 words. Important tip - please ensure that your cover letter includes how you meet the skills and experience listed in the “person specification” section above
  • A 90 minute video interview split into 3 main sections which are;
  • leadership and competence questions
  • presentation
  • technical questions 

Depending on how many applications we get, there might also be an extra stage before the video interview, for example a phone interview or a technical exercise.

In the event we receive a high volume of applications, we will conduct the initial sift against the lead criteria which is:

  • a strong track record of experience leading security governance, assurance, risk, or compliance functions, ideally for a Critical National Infrastructure (CNI) or comparable risk/profile/impact level product

In the Civil Service, we use Success Profiles to evaluate your skills and ability. This gives us the best possible chance of finding the right person for the job, increases performance and improves diversity and inclusivity. We’ll be assessing your technical abilities, skills, experience and behaviours that are relevant to this role.

For this role we’ll be assessing you against the following Civil Service Behaviours:

  • leadership
  • seeing the bigger picture
  • making effective decisions
  • working together
  • technical competency 

We’ll also be assessing your experience and specialist technical skills against the following skills defined in the Government Cyber Framework role: Cyber Security Governance and Risk Management 

Want to know more about who Government Digital and Data are? Click Here 

Recruitment Timeline

Sift completion: Thursday 3rd September 2026

Panel interviews: Thursday 10th September 2026 and Friday 11th September 2026

Candidates that do not pass the interview but have demonstrated an acceptable standard may be considered for similar roles at a lower grade.

A reserve list will be held for a period of 12 months, from which further appointments can be made.

The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan and the Civil Service D&I Strategy.

Please note that this role requires SC clearance, which would normally need 5 years’ UK residency in the past 5 years. This is not an absolute requirement, but supplementary checks may be needed where individuals have not lived in the UK for that period. This may mean your security clearance (and therefore your appointment) will take longer or, in some cases, not be possible.

For meaningful checks to be carried out, you will need to have lived in the UK for a sufficient period of time, to enable appropriate checks to be carried out and produce a result which provides the required level of assurance. Whilst a lack of UK residency in itself is not necessarily a bar to a security clearance, and expectation of UK residency may range from 3 to 5 years. Failure to meet the residency requirements needed for the role may result in the withdrawal of provisional jobs offers.

Sponsorship

DSIT cannot offer Visa sponsorship to candidates through this campaign. DSIT holds a Visa sponsorship licence but this can only be used for certain roles and this campaign does not qualify.


Feedback will only be provided if you attend an interview or assessment.

Security

Successful candidates must undergo a basic (or equivalent) criminal record check.

Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check (opens in a new window).

See our vetting charter (opens in a new window).

People working with government assets must complete baseline personnel security standard (opens in new window) checks.

Nationality requirements

This job is broadly open to the following groups:

UK nationals

  • nationals of the Republic of Ireland
  • nationals of Commonwealth countries who have the right to work in the UK
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
  • individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
  • Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service

Further information on nationality requirements (opens in a new window)

Working for the Civil Service

The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.

We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).

The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.

The Civil Service also offers a Redeployment Interview Scheme to civil servants who are at risk of redundancy, and who meet the minimum requirements for the advertised vacancy.

Diversity and Inclusion

The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).

Apply and further information

This vacancy is part of the Great Place to Work for Veterans (opens in a new window) initiative.

The Civil Service welcomes applications from people who have recently left prison or have an unspent conviction. Read more about prison leaver recruitment (opens in new window).

Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.

Contact point for applicants

Job contact :

Name: gdsrecruitment@dsit.gov.uk 

Email: gdsrecruitment@dsit.gov.uk 

Recruitment team

Email: gdsrecruitment@dsit.gov.uk 

Further information

If you feel your application has not been treated in accordance with the Recruitment Principles and you wish to make a complaint, you should contact gds-complaints@dsit.gov.uk in the first instance.

If you are not satisfied with the response you receive you can contact the Civil Service Commission by email: info@csc.gov.uk Or in writing: Civil Service Commission, Room G/8 1 Horse Guards Road, London, SW1A 2HQ.

Apply now

Government Digital and Data


About Government Digital and Data

Government Digital and Data is a community of experts leading digital transformation in government, creating more efficient services that have a meaningful impact on people’s lives.

The profession has technical specialists of all levels and backgrounds. They share a commitment to put users first and deliver world-leading government products and services.

Job roles within the profession range from trainee to Senior Civil Servants who lead on the very future of government itself.

Working in Government Digital and Data

Building the government of tomorrow

The UK government is recognised as a global leader in digital transformation. Government Digital and Data experts design, build and manage essential services that impact millions of peoples lives daily.

With an unprecedented number of digital transformation projects underway, the potential to help solve complex problems and shape our society’s future is enormous.

Examples of Government Digital and Data roles:

  • User Researcher
  • Test Engineer
  • Content Designer
  • Software Developer
  • Delivery Manager
  • Business Analyst
  • DevOps Engineer
  • Product Manager
  • Infrastructure Engineer
  • Technical Architect

As a Government Digital and Data specialist you will be working at the cutting edge of how people interact, and are empowered by government.

You’ll work in collaborative multidisciplinary teams on a range of projects and services that focus on user needs and deliver real value to society. You’ll be part of a cross-government profession with clearly defined career paths, support and learning and development.