Enable job alerts via email!

Cyber Security Risk Manager

HM Revenue & Customs

England

On-site

GBP 70,000 - 85,000

Full time

4 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join HM Revenue & Customs as a Cyber Security Risk Manager. In this role, you will drive security excellence, guide on secure delivery, and ensure robust protection of cloud infrastructure. You will be central in managing security risks, supporting audits, and fostering compliance across the organization.

Benefits

Civil Service Pension with employer contribution

Qualifications

  • Experience with AWS and Azure required.
  • Strong technical background in security necessary.
  • Ability to mentor others in security.

Responsibilities

  • Lead the assessment and reporting of vulnerabilities.
  • Develop and maintain security policies and procedures.
  • Monitor compliance with governance controls.

Skills

Cloud Technologies
Security Governance
Stakeholder Management
Vulnerability Assessment
Incident Response

Education

Security Check (SC) clearance
CISMP Certification

Tools

Tenable.sc
AWS Security Hub

Job description

Join to apply for the Cyber Security Risk Manager role at HM Revenue & Customs

Join to apply for the Cyber Security Risk Manager role at HM Revenue & Customs

Get AI-powered advice on this job and more exclusive features.

Direct message the job poster from HM Revenue & Customs

Apply before 11:55 pm on Friday 20th June 2025

A Civil Service Pension with an employer contribution of 28.97%

Location

Bristol, Newcastle-upon-Tyne, Telford

As the Cyber Security Risk Manager within HMRC’s Enterprise Cloud Services (ECS), you’ll be a central figure in driving security excellence. Acting as the first point of contact for all internal ECS security queries, advice, and guidance, you’ll also lead vulnerability assessments across ECS products, ensuring risks are identified, communicated, and addressed effectively.

You’ll play a hands-on role in shaping ECS security policies, supporting penetration testing, and guiding teams on secure service delivery. With a deep understanding of security and risk management, you’ll use evidence, data, and experience to make well-informed decisions that protect HMRC’s cloud infrastructure.

Key Responsibilities:

• Serve as the primary contact for ECS security advice, guidance, and support.

• Lead the review, assessment, and reporting of vulnerabilities in ECS products.

• Support penetration testing activities and advise on ECS service request risks.

• Develop and maintain ECS-specific security policies and procedures.

• Monitor compliance with governance controls and produce Risk Treatment Plans.

• Report and manage security incidents in line with HMRC and ECS procedures.

• Support internal and external audits

Person specification

We’re looking for a motivated self-starter who thrives both independently and as part of a small team. You’ll have a strong technical background in security and be able to mentor others, translating complex security concepts into clear guidance for a range of stakeholders.

You must meet the following requirements to be considered:

• Experience working with cloud technologies, particularly AWS and Azure.

• Proven background in security governance, compliance, and audit practices.

• Familiarity with ISO 27001, Risk Management, and GDPR frameworks.

• Proficient in vulnerability scanning tools such as, but not limited to:

  • Tenable.sc.
  • AWS Security Hub.

• Strong stakeholder management skills, with experience working across diverse teams.

• Must already hold Security Check (SC) clearance.

• Knowledge of technical, procedural, physical, and personnel-based security controls.

• Experience in security monitoring, testing, and incident response.

• Familiarity with risk assessment methodologies and security management systems.

Desirable Qualifications (or willingness to work towards):

• AWS: Cloud Practitioner, Security Specialty.

• Azure: Fundamentals, Security Engineer.

• Security Frameworks: EU/UK GDPR, ISO 27001, ISO 27005 Risk Manager.

• Certifications: CISMP (Certificate in Information Security Management Principles).

Desirable criteria will only be assessed in the event of a tied score.

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Information Technology
  • Industries
    IT Services and IT Consulting

Referrals increase your chances of interviewing at HM Revenue & Customs by 2x

Sign in to set job alerts for “Risk Manager” roles.

City Of London, England, United Kingdom 1 week ago

London, England, United Kingdom 1 week ago

London, England, United Kingdom 1 month ago

London, England, United Kingdom 3 weeks ago

London, England, United Kingdom 1 month ago

Brighton, England, United Kingdom 1 month ago

Greater London, England, United Kingdom 3 weeks ago

Governance, Risk and Compliance (GRC) Manager

London, England, United Kingdom 3 weeks ago

City Of London, England, United Kingdom £70,000.00-£85,000.00 1 week ago

London, England, United Kingdom 2 weeks ago

London, England, United Kingdom 1 week ago

London, England, United Kingdom 3 days ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Security Consultant

Sharp UK

London

Remote

GBP 70.000 - 100.000

3 days ago
Be an early applicant

HSE Manager (Part-time - 3 hours/week)

viso.ai

City Of London

Remote

GBP 60.000 - 80.000

6 days ago
Be an early applicant

Senior Product Marketing Manager - Risk (9-Month FTC)

RLDatix

Manchester

Remote

GBP 60.000 - 80.000

30+ days ago

Senior Product Marketing Manager - Risk (9-Month FTC)

RLDatix

Birmingham

Remote

GBP 60.000 - 80.000

30+ days ago

Information Security Risk Manager

TieTalent

Sheffield

Hybrid

GBP 58.000 - 88.000

3 days ago
Be an early applicant

Senior Strategy Risk Manager , Worldwide Operations Security

Amazon

Manchester

On-site

GBP 55.000 - 80.000

6 days ago
Be an early applicant

Information Technology Risk Manager

JSS Search

Manchester

Hybrid

GBP 65.000 - 75.000

3 days ago
Be an early applicant

Information Technology Risk Manager

Investigo

Manchester

On-site

GBP 75.000 - 87.000

3 days ago
Be an early applicant

Senior Operational Risk Manager

Close Brothers

London

Hybrid

GBP 70.000 - 100.000

3 days ago
Be an early applicant