Location
About the job
Job summary
A trainee Cyber Security Risk Manager supports an established team of risk managers across Home Office Cyber Security (HOCS) to identify, understand and mitigate cyber-related risks. They identify and evaluate security risks to information, systems and processes owned by the organisation, and proactively provide appropriate advice, drawing on a wide variety of sources, to stakeholders across the organisation and at a variety of levels. They provide risk or service owners with advice to help them make well informed risk-based decisions.
You will receive coaching, mentoring and direction from more senior team members.
The role is a trainee position where you can broaden you technical understanding and skills and start developing a specialisation.
The role is a pilot trainee position and will sit within the profession management team. You will be supported by numerous teams across Cyber Security to learn whilst on the job, where you can broaden your technical understanding and skills and start developing a specialisation. You will work under close supervision and can expect to benefit from training (formal and informal), coaching and mentoring to help you develop towards a permanent career in Cyber Security Risk Management.
We are offering 1 role in Manchester/Croydon. All roles will be appointed on merit order and location preference will be considered but not guaranteed.
Job description
Your main day to day responsibilities will be:
• Assisting in the planning and implementation of organisation-wide processes and procedures for the management of risk to the success or integrity of the business, especially those arising from the use of information technology, reduction or non-availability of energy supply or inappropriate disposal of materials, hardware or data. Working with the team to monitor the efficiency and effectiveness of the risk management processes across the organisation and help make recommendations for continuous improvement.
• Collaborate to conduct reviews and risk assessments when necessary and help feedback findings to the relevant parties. Contribute to communicating risk assessment outcomes to stakeholders in ways that support effective security, risk management and decision-making, and advise stakeholders on their approach to risk assessment in the context of their business outcomes
• Work within established security and risk management governance structures, under supervision to support, review and undertake straightforward risk management activities such as: helping with the analysis and derivation of business-supporting security needs; undertaking cyber security related risk assessments; basic threat assessments and other risk management activities
• Interpret and contribute to the development of risk management-related policy and assure the ongoing appropriateness of policy in accordance with regulation and wider departmental and government policies. Have some understanding of the applicability of appropriate regulations.
• Help to provide advice to address identified cyber security related risks by applying of a variety of security capabilities. Provide straightforward advice to validate the effectiveness of risk mitigation measures, including some understanding of how to use different assurance activities (such as a pen test) and make recommendations for improvement
• Help to advise risk or service owners to make decisions that are well informed by good and clear security advice, including making some contribution to reports or working within established reporting chains in a security team
Note: An employee may be required to carry out other duties within the scope of the grade and within the limits of their skill, competence and training.
Due to the nature of this role/business needs, this post is available on full-time and flexible working only but not on part time basis.
Hybrid Working
Hybrid working enables employees to work partly in their workplace(s) and partly at home. A hybrid working pattern may be available, where business needs allow. Applicants can discuss what this means with the vacancy holder if they have specific questions. Some occasional travel will be required.
Person specification
You will also be expected to carry out the following day to day activities:
• Help to identify process optimisation opportunities and work on the implementation of proposed solutions
• Driving the collection of statistical information relating to systems security incidents and identified vulnerabilities to produce reports for senior stakeholders
• Working with members of the team to ensure that everyone is up to speed with Home Office and security principles and developing in line with Home Office values
• Working closely with other Home Office Cyber Security (HOCS) personnel to ensure that specialist knowledge is kept current
• Assist with providing ad hoc support to IT teams by answering general enquiries about information security requirements
• Participating, contributing to, and supporting collaboration initiatives and career development within the community, building in-house capability via the professional community of practice
• Supporting reviews of security policy documentation, including procedures, processes and security notices, to ensure that requirements from governance, such as the System Security Document are reflected
• Helping to plan and deliver internal security audits, assisting with analysing audit data in order to help make recommendations on how we can ensure information conforms to processes, procedures and regulations
• Communicating effectively with relevant teams and stakeholders regarding the importance of security considerations and respond accordingly to changes in policy and procedure
• Supporting the review of internal controls following any security breach, helping to provide advice on how to remediate any vulnerabilities discovered.
• Working with the team on remedial solutions and helping to ensure resolution activities are carried out through liaising with the appropriate stakeholders
• Working with technical teams to audit the continuous monitoring of designated systems and networks and the recording of security events and incidents to highlight system and network errors and support investigations
• Ensure all identified risks are managed in accordance with Home Office risk management policies.
Note: The post-holder may be required to carry out other duties within the scope of the grade and within the limits of their skill, competence and training.
Skills and experience
Essential criteria
You’ll have a passion for Cyber Security. Please see below some of the relevant skills required for this role which you may want to address in your application:
• Communication
• Problem-solving
• Time management
• Critical thinking
• Decision-making
• Adaptability
• Conflict management
• Leadership
• Resourcefulness
• Motivation
• Collaboration
• Flexibility
• Willingness to learn
• Resilience
Desirable criteria
Ideally you will also have some experience and/or awareness of:
• Risk management
• Audit and audit tools
• Understanding of Lean, Agile and DevOps principles within a Product-centric delivery model
• Currently enrolled onto a Level 6 apprenticeship scheme
• Currently enrolled onto a Cyber Level 6 apprenticeship scheme
Behaviours
We’ll assess you against these behaviours during the selection process:
- Communicating and Influencing
- Changing and Improving
- Delivering at Pace
Technical skills
We’ll assess you against these technical skills during the selection process:
- Cyber Policy
Benefits
- Learning and development tailored to your role
- An environment with flexible working options
- A culture encouraging inclusion and diversity
- A Civil Service pension with an average employer contribution of 27%