Cyber Security Manager

Office for National Statistics

Newport

On-site

GBP 60,000 - 67,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Pension scheme
Flexible working
9 public holidays
6 weeks maternity/adoption
Employee assistance
Diversity networks
Mental health allies
Sports & social club
Generous holiday allowance

Job summary

The Office for National Statistics is recruiting a Cyber Security Risk Manager – Lead to join the Security Risk Advisory team within the Security and Information Management Division. You will provide security advice to embed the ONS Security Framework and support digital programmes including Census 2031.

Responsibilities include risk assessments, threat modeling, security governance, advising on secure/open-source options, and ensuring policies remain proportionate to risks; you will work with

Qualifications

  • Experience in cyber security risk management and assurance within large organisations.
  • Ability to conduct risk assessments and threat modeling across complex digital services.
  • Proven track record of advising stakeholders and aligning security with business goals.

Responsibilities

  • Lead risk assessments and threat modeling for UKSA digital programmes.
  • Provide security guidance to embed the ONS Security Framework across projects.
  • Coordinate with stakeholders to ensure secure-by-design solutions.
  • Advise on secure/open-source options and governance to mitigate risk.
  • Ensure policies and controls remain proportional to assessed threats.

Skills

Security risk assessment
Threat modeling
Stakeholder engagement
Governance & compliance

Job description

Salary: £60,007 - £66,701. Plus a skills allowance of up to £7,500 (non-pensionable and non-contractual) may be payable. Starting salary and level of skills allowance will depend on a technical skills assessment at interview.


Working Patterns: Flexible working, Full-time, Job share, Part-time, Compressed hours


Closing Date: Apply before 11:55 pm on Tuesday 8th September 2026


The Cyber Security Risk Manager - Lead role forms part of the Security Risk Advisory team within the Security and Information Management Division at the Office for National Statistics (ONS). The roles reports to the Cyber Security Risk Manager - Principal. The primary focus of these roles are to provide the Organisation with security advice and best practice to develop ‘Secure by Design’ protections for organisational assets and embed the ONS Security Framework - principles; policies; processes; threat model; security risk management into the ONS.


This role will be dedicated to supporting all security assessment and assurance activities associated with the preparation and delivery of UKSA digital programmes, such as Census 2031. Key activities will involve security assessment, assurance, threat modeling and mitigation advice/guidance for all aspects of digital delivery, including in-house and procured/third-party elements. Key outcomes from the roles are the identification of security risk within the business context, the identification of appropriate mitigation approaches for business selection and the management of these options through to implementation within the live service. The security advice provided will be informed by threat, vulnerability and risk analysis for business and third parties. The focus, outcomes and responsibilities are aligned to the Government Security Profession framework of the Cyber Security Risk Manager – Lead.


Responsibilities


  • Supporting the development of business-focused security solutions for digital products and business operations that cover data collection, storage and processing of Official - Sensitive information (deployed both internally and via external suppliers); Identifying security threat and risk to the Organisation's digital products, data assets and business operations as part of the delivery lifecycle;

  • Lead the analysis and derivation of business-supporting security needs, undertake Cyber Security related risk assessments, conduct tailored threat assessment and other risk management activities, and ensure activities are consistent with applicable regulations and legislation;

  • Independently undertake risk management activities within a given area of practice or expertise, usually within established security and risk management governance structures;

  • Lead the analysis and derivation of business-supporting security needs, undertake Cyber Security related risk assessments, conduct tailored threat assessment and other risk management activities, and ensure activities are consistent with applicable regulations and legislation;

  • Consulting with the Organisation’s security stakeholders to ensure that the solutions deployed are secure and fit for purpose;

  • Liaising with the Organisation’s business, technology and security colleagues to ensure various business needs are understood and applied, including providing general security architecture, guidance and advice to the stakeholders;

  • Advising on opportunities for using secure and open-source products and any implications of such an approach.

  • Ensure that security policies and security controls remain appropriate and proportionate to the assessed risks, and are responsive and adaptable to the changing threat environment, business requirements and ONS policies;

  • Provide tailored advice to a range of stakeholders on how to remedy identified risks by proportionately applying security capabilities, using published guidance, standards, and drawing on a range of experts as well as personal expertise;

  • Provide expert security advice that highlights Cyber Security related risks, so risk or service owners can make well-informed and auditable decisions.


In return we offer:


  • A market leading pension scheme - our employer contribution rate is around 28%

  • A choice of working patterns: full-time, part-time, job-share.

  • Maternity, adoption or shared parental leave of 26 weeks full pay (subject to qualifying criteria)

  • Employee Assistance Programmes

  • Diversity Network Groups

  • Mental Health Allies

  • Civil Service Sports and Social club

  • Generous holiday allowance – 25 days annual leave, rising to 30 days after 5 years service in addition to 9 public holidays


For more information about this role please log into Civil Service Jobs

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Cyber Security Risk Manager
Lead Cyber Security Risk Manager

UK Home Office • Glasgow

Hybrid
GBP 63,000 - 80,000
Civil Service Pension (employer 28.97%
Annual leave 25 days
Public holidays 8 + 1 day
+2
Lead Cyber Security Risk Manager
Lead Cyber Security Risk Manager

UK Home Office • Sheffield

Hybrid
GBP 63,000 - 80,000
Civil Service Pension
In-year reward scheme
25 days annual leave
+2
Lead Cyber Security Risk Manager
Lead Cyber Security Risk Manager

UK Home Office • Croydon

Hybrid
GBP 67,000 - 81,000
Civil Service Pension
Performance reward scheme
25 days annual leave
+2
Cyber Security Risk Lead — Secure by Design
Cyber Security Risk Lead — Secure by Design

Office for National Statistics • Newport

On-site
GBP 60,000 - 67,000
Pension scheme
Flexible working
9 public holidays
+6
Lead Cyber Security Risk Manager
Lead Cyber Security Risk Manager

UK Home Office • Salford

Hybrid
GBP 63,000 - 80,000
Civil Service Pension
25 days annual leave
Public holidays
Cyber Security Consultant (Senior Security Advisor - CISO) | NHS England
Cyber Security Consultant (Senior Security Advisor - CISO) | NHS England

Allscreens Nationwide Ltd • Leeds, Exeter

On-site
GBP 69,000 - 78,000
RRP payment 20%
Senior Capability Manager
Senior Capability Manager

Office for National Statistics • Titchfield

Hybrid
GBP 40,000 - 60,000
Market-leading pension scheme
Generous holiday allowance
Flexible working patterns
+2
Chief Security Officer
Chief Security Officer

Global Resourcing • England

Hybrid
GBP 100,000 - 163,000
Cyber Risk Manager - Active Security Clearance Required
Cyber Risk Manager - Active Security Clearance Required

Solirius Ltd. • Greater London

On-site
GBP 70,000 - 110,000
Competitive salary
Bonus scheme
Private healthcare insurance
+3
Junior Cyber Risk and Assurance Analyst (12m FTC)
Junior Cyber Risk and Assurance Analyst (12m FTC)

Bank of England • City Of London

On-site
GBP 40,000 - 56,000