Deputy Director of Enterprise Security & Risk Management
- Civil Service
- Full Time
- London
- 86,000 - 104,000
Job Description
Job summary
Shape how one of the UK's largest organisations understands and responds to security risk.
This is a unique opportunity for an experienced governance, risk and assurance leader to shape how DWP understands, manages and acts on security risk. We are looking for someone who can bring clarity, pace and innovation to enterprise security risk management; who is confident working with complex evidence, assurance and threat information; and who can translate that insight into decisions that influence senior leaders across the whole organisation. The function is already mature and well-respected; you will have the opportunity to build and shape the credibility of the function across the Department, Government and the wider industry.
You will be a natural relationship builder, comfortable operating in a large, complex delivery organisation in either the public or private sector. You will need to inspire confidence with Ministers, the Permanent Secretary, the Departmental Audit, Risk and Assurance Committee, senior colleagues and your own teams through the quality of your judgement, the strength of your evidence, and your ability to help the organisation act on the risks that matter most. This is a role for someone who cares deeply about impact: not simply reporting risk and assurance, but changing behaviour, improving resilience and enabling better outcomes for millions of citizens.
We are looking for an inclusive, credible and ambitious senior leader to support me in leading the teams that provide proportionate, well-informed security and risk advice to the Department and its senior leaders. Values and making Security & Data Protection Directorate within DWP a brilliant place to work will be important to you. Youll thrive on delivering outcomes and making wider contributions to Government Security and the Civil Service.
To learn more about this opportunity, hear directly from Mike Fell, Chief Security Officer and vacancy holder.
For more information about DWP and this role, please see the Candidate Pack attached.
Hear more about DWP
Job description
As Deputy Director of Enterprise Security & Risk Management, the accountabilities of the postholder include:
- Enterprise Risk Management - Lead the organisations security risk function, ensuring enterprise-level security risks are identified, assessed, prioritised and effectively managed in alignment with the organisation's risk appetite or agreed risk tolerance.
- Security Oversight Develop and deliver the departments enterprise security governance model and associated boards, ensuring alignment with corporate strategy, governance, regulatory requirements and risk appetite.
- Governance, Risk & Compliance - Lead Governance Risk & Compliance (GRC) activities, ensuring it is aligned, proportionate, transparent, compliant and business-centric. Provide programme and service-specific risk advice aligned to policy and risk appetite. Work closely with Security Policy & Awareness teams to deliver joined up security.
- Third‑Party Security Assurance - Responsible for the organisations multi-tiered supplier assurance programme, ensuring all third‑party security risks are assessed, monitored and actively managed throughout the contract lifecycle in a proportionate, risk-based manner.
- IT Security Assurance - Deliver a holistic, balanced programme of independent assurance over IT security architecture and associated controls providing confidence in technology‑driven risk including mandatory external and internal assurance and compliance activity.
- Physical Security Assurance - Responsible for evaluating, testing and verifying the organisations physical security measures across circa 850 locations ensuring site- and enterprise-level resilience measures are robust, risk-aligned and compliant with external requirements.
- Regulatory & Audit Engagement - Acts as the primary interface with internal audit, external auditors, and wider government bodies, ensuring clear evidence of security risk management and control effectiveness.
- Leadership of a Dispersed Workforce - Lead a team of 90 security, risk and assurance professionals across multiple UK locations, building a unified culture, clear accountability and high performing team.
- Strategic Advisor - Advises the Chief Security Officer, Executive Team and other boards on systemic risks and strategic investment priorities to manage those risks.
- Management Accountable for the efficient running of the team, including a multi-million-pound budget, accurate forecasting, and HR, finance and commercial compliance.
Person specification
The successful candidate must be able to demonstrate their knowledge, experience and skills against the following essential criteria:
- Proven senior security leadership experience, with a track record of leading and inspiring large, geographically dispersed teams through an engaging, authentic and adaptable leadership style. The successful candidate will demonstrate exceptional interpersonal and influencing skills, with the credibility to build trusted relationships at all levels of the organisation. They will possess high levels of emotional intelligence, sound judgement, executive presence, diplomacy and adaptability.
- Security Governance, Risk & Compliance (GRC) expertise recognised expertise in security GRC, with experience establishing and leading enterprise-wide, cross-domain security governance, risk management and compliance frameworks within complex organisations. This will include deep knowledge of relevant regulations, frameworks and standards, together with experience of managing risk across both legacy and modern technology environments. This expertise should be evidenced through relevant professional qualifications and memberships (e.g. CISM, CISA, CISSP, CRISC, GRC(A), Chartered Security/Cyber Profession status).
- Excellent communication and stakeholder management skills, with the ability to influence senior leaders and communicate complex security and risk issues clearly to both technical and non-technical audiences.
- Experience leading security assurance across complex supply chains and outsourced service models, ensuring effective governance, risk management and resilience across third-party environments.