An application made for this job — a tailored resume and cover letter that speak straight to the posting.
The Office for National Statistics is seeking a Cyber Security Risk Manager - Lead to join the Security Risk Advisory team. You will deliver security risk assessments, threat modelling and guidance to protect digital programmes, including Census 2031, across internal and supplier environments.
Working patterns offer flexibility and full-time options; you will report to the Cyber Security Risk Manager - Principal and contribute to secure design and governance across the organisation.
Salary: £60,007 - £66,701. Plus a skills allowance of up to £7,500 (non-pensionable and non-contractual) may be payable. Starting salary and level of skills allowance will depend on a technical
skills assessment at interview.
Working Patterns: Flexible working, Full-time, Job share, Part-time, Compressed hours
Closing Date: Apply before 11:55 pm on Tuesday 8th September 2026
The Cyber Security Risk Manager - Lead role forms part of the Security Risk Advisory team within the Security and Information Management Division at the Office for National Statistics (ONS). The roles reports to the Cyber Security Risk Manager - Principal. The primary focus of these roles are to provide the Organisation with security advice and best practice to develop ‘Secure by Design’ protections for organisational assets and embed the ONS Security Framework - principles; policies; processes; threat model; security risk management into the ONS.
This role will be dedicated to supporting all security assessment and assurance activities associated with the preparation and delivery of UKSA digital programmes, such as Census 2031. Key activities will involve security assessment, assurance, threat modeling and mitigation advice/guidance for all aspects of digital delivery, including in-house and procured/third-party elements. Key outcomes from the roles are the identification of security risk within the business context, the identification of appropriate mitigation approaches for business selection and the management of these options through to implementation within the live service. The security advice provided will be informed by threat, vulnerability and risk analysis for business and third parties. The focus, outcomes and responsibilities are aligned to the Government Security Profession framework of the Cyber Security Risk Manager – Lead.