Back to search

Lead Security Risk Assurance Manager

Civil Service

Job Description

Job summary

Each year DWP is responsible for delivering approximately 280 billion in benefits and pensions, with over eight hundred physical locations and around 1000 commercial suppliers. DWP holds substantial personal data and manages several critical digital systems and key elements of the Governments critical national infrastructure.

Enterprise Security & Risk Management (ESRM) supports the secure delivery of DWP business, empowering the Department to operate within its security risk appetite, prioritise security improvement activities and maximise return on security investment.

As a senior leadership position in ESRM a Lead Security Risk Assurance Manager holds responsibility for producing high‑quality enterprise‑level security risk assessments or security risk assurance reports that can inform decision-making at the highest levels including Director General Finance, the Executive Team, and Departmental Audit & Risk Assurance Committee (DARAC).

This includes the identification and monitoring of enterprise-level security risks, contextualising principal security threats to identify strategic risks to DWP and help inform departmental security policy. Alternatively, a Lead Security Risk Assurance Manager will, ensure delivery of security assurance activities, undertake and oversee multiple activities to gather evidence on the security posture of DWP assets and services for example: interviews, sampling, design review, IT health checks and controls testing. ESRM analyse findings from these activities to provide confidence that DWP is sufficiently secure or identify areas for improvement.

A Lead Security Risk Assurance Manager is vital in understanding the big picture, synthesising information, and articulating how security risks could impact the departments ability to operate, deliver services, maintain resilience, and protect staff, data, and assets.

The position requires an individual who can understand complex and interconnected risks across a large organisation, influence senior stakeholders, challenge assumptions, and provide clear, evidence-based advice on whether controls are effective, thus, enabling informed business decisions. Working across multiple functions and disciplines, the successful candidate will help DWP deliver its objectives securely, resiliently and effectively.

ESRM provide confidence through evidence, placing a strong focus on continuous improvement, looking wider and deeper than just compliance. We highlight good practice and provide a professional, impartial view of the potential improvements to the departments security position.

Job description

Lead an area of Enterprise Security Risk or Security Assurance

  • Develop, maintain and lead the production of timely Enterprise Security Risk or Assurance Products for senior leaders
  • Oversee multi‑layered risk and assurance analysis covering threat scenarios, impacts, effectiveness of controls, and residual risk.

Deliver Complex Security Risk Analysis

  • Identify interdependencies and cumulative impacts across systems, services and business areas, translating localised risks into an enterprise-wide understanding of potential consequences
  • Break down large, ambiguous or abstract security problems into structured analytical components
  • Gather, evaluate and synthesise information from diverse sources, including digital risk data, system-level risk assessments, threat intelligence, estate vulnerabilities, resilience data and people safety insights
  • Apply structured analytical methods to generate robust findings, uncertainty judgements, and evidence‑based conclusions.

Influence Decision Makers

  • Understand complex and interconnected risks, provide balanced and pragmatic advice that supports senior leaders in making informed decisions, recognising both risk exposure and business objectives
  • Produce clear, actionable insights to inform Director General level decision‑making, risk appetite setting, and departmental prioritisation
  • Articulate business impacts: how risks could affect operations, resilience, service delivery, customer experience, staff safety or data protection
  • Support senior leaders (for example DWP's Finance Director General (DG) as risk owner) by outlining options, consequences and recommended mitigations.

Stakeholder Leadership and Engagement

  • Build credibility with senior leaders, influencing across organisational boundaries and constructively challenging assumptions where required
  • Build strong relationships with senior stakeholders across Digital, Estates, People Safety, Risk & Resilience, Commercial and wider security teams
  • Coordinate and convene stakeholders to gather evidence, test assumptions and validate analysis.

Team Leadership and Delivery Management

  • Lead, mentor and quality‑assure the work of a small team of colleagues
  • Task and oversee scenario‑level analysis (for example physical estate failure scenarios, cyber resilience scenarios)
  • Shape team capability, drive continuous improvement and support professionalisation of ESRMs analytical approach.

Strategic and Tactical Risk Support

  • Enable the business to achieve its objectives securely by identifying practical options, mitigations and routes to delivery within agreed risk appetite.
  • Lead thematic/strategic risk assessments for priority business areas (for example arms length bodies)
  • Deliver tactical assessments when the business requests security input on emerging issues (for example reviewing new operating models, or outreach activities)
  • Provide options and recommendations while enabling the business to understand and own its risk decisions.

Given the geographic spread of our team, DWP customers, cross-government stakeholders and industry suppliers, you'll need to be willing to travel to other DWPlocations,withperiodicovernightstaysrequired.

Person specification

Wewouldlovetohearfromyouifyoucandemonstrateyourskillsandexperience across all the following essential criteria:

Experience providing risk assessment or assurance or decision support within large, complex environments involving multiple stakeholders, competing priorities and distributed accountabilities, alongside a strong understanding of security or risk principles.

Transferable experience (such as threat analysis, operational risk, resilience, or intelligence) is equally valuable. No mandatory qualifications are required

Strong stakeholder engagement and influencing capability -build credibility with senior leaders, gain buy-in across organisational boundaries, and communicate complex security risk issues in a clear and compelling way.

Demonstrate curiosity and professional scepticism using questioning to test assumptions, understand the evidence to assure effectiveness of controls and develop a strong understanding of risk and business impact.

Ability to understand and communicate business impact -translating security, technical or operational issues into clear consequences for service delivery, resilience, staff safety or organisational performance

Leadership experience -able to guide and quality‑assure the work of others, support change, and contribute to improving or professionalising a team or function

Exceptional analytical skills -able to assess complex, and interconnected security or operational problems, identify dependencies and develop evidence based assurance opinions in ambiguous environments clearly and concisely.

Yodel are hiring now

Working at Yodel, they promise to support you, develop you and give you all the tools you need to do a great job. They have a range of opportunities across the UK now - why not see if Yodel have the perfect role for you?

See Yodel jobs

Good luck with your application