Back to search

Local Government - Cyber Risk Analyst

Civil Service

Job Description

Job summary

Here at the Ministry of Housing, Communities & Local Government (MHCLG), we work on things that make a real difference to people's lives.
Whether it's through the homes we live in, the work of our local councils, or the communities we're all part of, our work is at the top of the political agenda. We have ambitious and far-reaching outcomes to achieve this year and, if you're thinking of joining us, there's never been a more exciting time.
The Local Digital team sits within the Ministry of Housing, Communities and Local Government and supports councils across England to deliver more secure, user-centred, cost-effective local public services through open, collaborative and reusable work. We support the local government sector to be more cyber resilient and deliver on the ambition of the Government Cyber Action Plan which sets out how we will secure public services, so they are trustworthy and resilient, as part of the broader Roadmap for a Modern Digital Government.

To achieve this, we work closely with councils to:

· Understand the risk: improving visibility of digital assets, assessing vulnerabilities, and sharing intelligence so councils and MHCLG can make informed decisions about how best to reduce cyber risk.

· Manage the risk: strengthening cyber security posture through continuous improvement, addressing systemic weaknesses, and coordinating effective incident response.

· Strengthen partnerships: promoting collaboration across local government and with national partners to reduce duplication, share resources, and build collective resilience.

We are seeking a Senior Executive Officer (SEO) Local Government Cyber Risk Analyst to work alongside the Cyber Risk Manager to run and continuously improve our local government sector cyber risk reporting and insight capability. This role focuses on analysis, reporting and maintaining a clear evidence base to support prioritisation and decision making in support of local government cyber resilience.

The post-holder will work with councils and partners to improve the quality and usefulness of sector-level insight, while being clear about data limitations and that councils own their risks and remediation.

Find out more about our Digital teams and what they are working on through our MHCLG Digital blog.  Please note that MHCLG do not offer visa sponsorship and applicants will need a valid visa for the duration of your employment.

Job description

As a Cyber Risk Analyst You'll:

  • Own the local government sector cyber risk reporting cycle end-to-end, producing a consistent local government risk pack with clear caveats, confidence levels, and documented limitations
  • Ensure reporting and insight remain focused on sector-level risks and trends across local government, clearly distinguishing between council-owned risks and MHCLGs enabling role
  • Analyse and synthesise Cyber Assessment Framework (CAF) returns from the local government sector and other agreed inputs into senior-ready insight, without overstating completeness, representativeness, or certainty
  • Maintain the cyber risk data repository and evidence base that underpins reporting, including clear data quality markers and documented assumptions
  • Support continuous improvement of risk reporting outputs, maintaining an agreed backlog of enhancements based on leadership feedback and data maturity
  • Engage with councils and internal partners when required to clarify evidence and close priority data gaps, using lightweight and proportionate approaches
  • Provide a cyber risk lens into CAF process development, sharing evidence-led insight on sector gaps, trends and emerging concerns
  • Produce senior-ready slide decks and briefings (PowerPoint), by pulling validated data from reporting spreadsheets (Excel) and translating into clear narrative, neat charts and visuals, and decision-focused recommendations for Senior Leadership Team decision making.

Person specification

As a Cyber Risk Analyst You'll have;

  • Experience working in a cyber security risk, assurance, governance, or related analytical role in a complex organisation or multi-stakeholder environment.
  • Experience analysing evidence aligned to recognised frameworks such as the Cyber Assessment Framework (CAF) or ISO 27001, and translating it into clear, proportionate insight
  • Experience producing structured reporting or briefing products for senior stakeholders, including clear narrative, caveats, and recommendations
  • Strong analytical skills, including working with imperfect data, documenting assumptions, and applying quality assurance to reduce errors
  • The ability to communicate complex or technical issues in a clear and practical way to non-technical audiences
  • Strong planning and organisation skills, able to manage priorities and deliver to deadlines in a fast-paced environment
  • Strong Excel and PowerPoint skills, able to maintain and quality assure reporting spreadsheets (Excel) and translate outputs into clear, concise, senior-ready packs (PowerPoint) with well-structured narrative, neat charts and visuals, and appropriate version control.
This role requires SC security clearance and a willingness to apply for DV clearance once in post.

Desirable:

· Experience producing dashboards or management information products (for example Power BI or equivalent) and working within data governance constraints.

· Relevant cyber security certifications (for example CISSP, CISM, CISMP, or ISO 27001 Lead Auditor/Implementer) or working towards them.

Yodel are hiring now

Working at Yodel, they promise to support you, develop you and give you all the tools you need to do a great job. They have a range of opportunities across the UK now - why not see if Yodel have the perfect role for you?

See Yodel jobs

Good luck with your application