21441 - Security Risk & Assurance Practitioner

Allscreens Nationwide Ltd

National (WA)

On-site

USD 85,000 - 125,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Ministry of Justice is seeking a Cyber Security Risk and Assurance Practitioner to help deliver security assurance across digital services, assess control effectiveness and communicate findings to senior stakeholders. You will review services, gather evidence, identify risks and opportunities for improvement, and contribute to building secure, compliant processes within a supportive, diverse team.

The role emphasizes collaboration, guidance on risk management, and translating complex

Job description

21441 - Security Risk & Assurance Practitioner

Cyber Security Risk and Assurance Practitioner (HEO)

The MoJ Information Security Team sits at the heart of the Ministry of Justice, enabling good security practices through the provision of security policies, guidance and education, by understanding cyber security risks from all parts of the Ministry of Justice and providing assurance to the departmental SIRO, the Permanent Secretary and other senior stakeholders that these risks are being effectively managed in the delivery of MoJ objectives.

The role of the Cyber Security Risk and Assurance Practitioner is to support the central MoJ Information Security Team in carrying out cyber security assurance, highlighting non-compliance with required standards and raise and communicate cyber security risks arising from control gaps.

The team works across a diverse range of digital services, technologies and business functions to identify and understand cyber security risks and provide assurance that these risks are being managed appropriately in support of departmental objectives.

The role involves reviewing services and systems, analysing evidence, identifying risks and opportunities for improvement, and communicating findings to a wide range of stakeholders.

The Cyber Security Risk and Assurance Practitioner may also provide advice to others on good risk management practices to enable them to manage residual risk well, identify trends resulting from risk and assurance activities and use these to propose and deliver improvements to processes, policies and guidance, and enable senior team members to resolve tactical requests to the team.

All members of the team are expected to help develop the MoJ Security Function as a centre of excellence for the department and to contribute to building a brilliant and diverse team that is a welcoming place for all.

All members of the team are expected to contribute to developing the MoJ Security Function as a centre of excellence, helping to build a brilliant, diverse and inclusive team environment. The post holder will contribute across a variety of assurance, risk and governance activities, working collaboratively with colleagues to continuously improve security practices, processes and decision-making across the department.

Typical role expectations and responsibilities
Security Risk and Assurance
  • Deliver security assurance, governance and risk management activities across a range of digital services, technical platforms, projects, suppliers and business functions.
  • Assess the effectiveness of security controls and identify control gaps, risks and areas requiring improvement.
  • Provide evidence-based opinions and recommendations on cyber security risks and the adequacy of controls, supporting informed decision-making and proportionate risk management while enabling business outcomes.
  • Support the delivery of assurance activities across the department including assurance reviews, incident management, GovAssure and third party assurance and communicate findings in a clear and proportionate manner to stakeholders.
Review, Analysis and Investigation
  • Conduct detailed reviews of digital services, business processes and technical solutions to understand how security and risk management requirements are being implemented in practice.
  • Gather, validate and analyse evidence from multiple sources to identify risks, trends, themes, control weaknesses and examples of good practice.
  • Apply analytical and investigative skills to understand complex issues, challenge assumptions and determine underlying causes of identified risks or concerns.
  • Use data and evidence to support recommendations and prioritisation of security improvement activities.
Technical Understanding
  • Develop and maintain an understanding of modern digital technologies and how they are used within large organisations.
  • Develop an understanding of cloud platforms, enterprise technologies, applications and digital services, and use this knowledge to support assurance, risk and governance activities.
  • Translate technical concepts into language that can be understood by non-technical stakeholders.
Reporting and Stakeholder Engagement
  • Produce clear, concise and evidence-based reports, assessments, briefings and recommendations for technical and non-technical audiences.
  • Present findings confidently to stakeholders and support discussions relating to risk management, governance and assurance outcomes.
  • Build productive working relationships across the organisation and act as a trusted partner in supporting good security practices.
  • Contribute to submissions, reports and briefing materials for senior leaders and governance forums.
Process Improvement
  • Review assurance, governance and risk management processes to identify opportunities to improve efficiency, consistency and effectiveness.
  • Support the development and implementation of improvements to processes, guidance, reporting and ways of working.
  • Identify themes emerging from assurance and risk activities and use insight to drive continuous improvement.
Team Contribution
  • Support a broad range of work across the team and adapt to changing priorities and organisational needs.
  • Share knowledge, skills and experience with colleagues to improve team capability and resilience.
  • Collaborate effectively with team members and stakeholders to deliver collective outcomes.
  • Contribute to maintaining a positive, inclusive and supportive team culture.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Risk & Assurance Specialist
Cyber Security Risk & Assurance Specialist

Allscreens Nationwide Ltd • National (WA)

On-site
USD 85,000 - 125,000
20998 - Director of Technology Services
20998 - Director of Technology Services

Allscreens Nationwide Ltd • National (WA)

On-site
USD 162,000 - 203,000
20957 - Digital Workforce Manager (National)
20957 - Digital Workforce Manager (National)

Allscreens Nationwide Ltd • National (WA)

Hybrid
USD 81,000 - 122,000
Pension 28.97%
Annual leave 25 days
Hybrid working
+3
Information Governance Data Security and Protection Specialist
Information Governance Data Security and Protection Specialist

Allscreens Nationwide Ltd • New Jersey

On-site
USD 90,000 - 130,000
Director of Technology Services — Transformation & Security
Director of Technology Services — Transformation & Security

Allscreens Nationwide Ltd • National (WA)

Hybrid
USD 162,000 - 244,000
21232 - Security Engineer (National)
21232 - Security Engineer (National)

Allscreens Nationwide Ltd • National (WA)

Hybrid
USD 58,000 - 70,000
Pension contribution 28.97%
25 days annual leave + 8 bank holidays
Hybrid working
+2
Lead Cyber Security Monitoring
Lead Cyber Security Monitoring

Allscreens Nationwide Ltd • Uxbridge (MA)

On-site
USD 54,000 - 66,000
Civil Service pension
Flexible working options
21101 - Portfolio Benefits Analyst (National)
21101 - Portfolio Benefits Analyst (National)

Allscreens Nationwide Ltd • National (WA)

Hybrid
USD 95,000 - 136,000
Pension scheme
25 days annual leave
Hybrid working
+2
Cyber Security Analyst - (Closing date - 31/08/2026)
Cyber Security Analyst - (Closing date - 31/08/2026)

Esh Group • North Carolina

On-site
USD 41,000 - 62,000
Junior Offensive Cyber Security Specialist
Junior Offensive Cyber Security Specialist

NexTech Solutions LLC • Tampa (FL)

On-site
USD 65,000 - 90,000