skip navigation
skip mega-menu

Cyber Security Risk Manager - HMRC - SEO

Government Digital & Data -

Full-time (Permanent)
£44,110 - £47,664
Published on
13 June 2025
Deadline
20 June 2025

Location

Bristol, Newcastle-upon-Tyne, Telford

About the job

Job summary

Discover a career in your hands at HMRC. Whether you're seeking purpose, growth, or a workplace that gives you a true sense of belonging, hear from some of our employees as they share their story about what it’s really like to work at HMRC.

   

Visit our YouTube channel to watch the full series and come and discover your potential.

Within HMRC’s Chief Digital & Information Group (CDIO), specifically in the Enterprise Cloud Services (ECS) team we are redefining and growing a team of outstanding people to improve its HMRC Cloud Centre of Excellence offering.

We are already a diverse team of 80+ individuals, creating a dynamic and inclusive working environment whose skills cover Architecture, Development, Service Design, Operation and Governance.

We are looking for someone who will be responsible for the security aspects for supporting the development and operations of HMRC’s Cloud Environment.

This is a key role that will undertake and feed into governance and compliance activities of HMRC Cloud Services and delivery activities within the ECS Security and other processes.

You will work directly with the Security Lead and the Security Architect, Cyber Security Technical Services (CSTS) team, and across the ECS capability functions to ensure that security is built into and maintained within HMRC cloud services, including the identification, and management of our risks.

Travel to Telford is expected as part of this role, and 60% of your working time will need to be office based.

Job description

As the Cyber Security Risk Manager within HMRC’s Enterprise Cloud Services (ECS), you’ll be a central figure in driving security excellence. Acting as the first point of contact for all internal ECS security queries, advice, and guidance, you’ll also lead vulnerability assessments across ECS products, ensuring risks are identified, communicated, and addressed effectively.

You’ll play a hands-on role in shaping ECS security policies, supporting penetration testing, and guiding teams on secure service delivery. With a deep understanding of security and risk management, you’ll use evidence, data, and experience to make well-informed decisions that protect HMRC’s cloud infrastructure.

Key Responsibilities:

•    Serve as the primary contact for ECS security advice, guidance, and support.

•    Lead the review, assessment, and reporting of vulnerabilities in ECS products.

•    Support penetration testing activities and advise on ECS service request risks.

•    Develop and maintain ECS-specific security policies and procedures.

•    Monitor compliance with governance controls and produce Risk Treatment Plans.

•    Report and manage security incidents in line with HMRC and ECS procedures.

•    Support internal and external audits

Person specification

We’re looking for a motivated self-starter who thrives both independently and as part of a small team. You’ll have a strong technical background in security and be able to mentor others, translating complex security concepts into clear guidance for a range of stakeholders.

Essential Criteria:

You must meet the following requirements to be considered:

•    Experience working with cloud technologies, particularly AWS and Azure.
• Proven background in security governance, compliance, and audit practices.
• Familiarity with ISO 27001, Risk Management, and GDPR frameworks.
•    Proficient in vulnerability scanning tools such as, but not limited to:

  • Microsoft Defender for Cloud.
  • Tenable.sc.
  • AWS Security Hub.

•    Strong stakeholder management skills, with experience working across diverse teams.

Desirable Criteria:

•    Knowledge of technical, procedural, physical, and personnel-based security controls.

•    Experience in security monitoring, testing, and incident response.

•    Familiarity with risk assessment methodologies and security management systems.

Desirable Qualifications (or willingness to work towards):

•    AWS: Cloud Practitioner, Security Specialty.

•    Azure: Fundamentals, Security Engineer.

•    Security Frameworks: EU/UK GDPR, ISO 27001, ISO 27005 Risk Manager.

•    Certifications: CISMP (Certificate in Information Security Management Principles).

Desirable criteria will only be assessed in the event of a tied score.

Additional Security Information

Must already hold or be eligible to obtain Security Check (SC) clearance.

Behaviours

We'll assess you against these behaviours during the selection process:

  • Changing and Improving
  • Communicating and Influencing
  • Making Effective Decisions


More jobs at Government Digital & Data

Lead Business Analyst-Department for Transport
£51,997
Full-time (Permanent)
Technical Architect Vehicle Certification Agency-SEO
£57,400
Full-time (Permanent)
Software Engineer - ONS - HEO
£32,452
Full-time (Permanent)
IT Support Engineer - Met Office - EO
£26,954 - £29,531
Full-time (Permanent)
DDaT Senior BI Design & Integration Manager - MoD - SEO
£43,080
Full-time (Permanent)
Lead Applied AI Engineer (i.AI) - CO - G6
£67,126 - £103,924
Full-time (Permanent)
DDAT Lead Technical Architect - MoD - G7
£57,670 - This post is eligible for a Digital Skills Allowance of up to £15,300 per annum
Full-time (Permanent)
Interaction Design Industrial Placement 2025 - Met Office - AO
£25,606
Full-time (Permanent)
Lead DevOps Engineer - DWP - G6
£72,664 - £89,995
Full-time (Permanent)
Software Development Engineer In Test (Automation Test Engineer
Full-time (Permanent)
Software Developer - HM Courts and Tribunals Service - SEO
The national salary range is £41,463 - £45,276, London salary range is £47,657 - £52,040.
Full-time (Permanent)
Interaction Designer - Planning Inspectorate - SEO
£45,219 - £49,462
Full-time (Permanent)
Digital, Information & Technology (DIT) Senior Software Developer - MoD - SEO
The base salary for this grade is £44,590, Offers above this will be made up of DSA , Digital Skill allowance of up to £11,400
Full-time (Permanent)
Interaction Designer - Ofgem - HEO
London £36,824-£48,561 National £34,123-£45,831.
Full-time (Permanent)
Code First Girls Opportunities sponsored by the IPO (GFiE Scheme) - IPO - EO
£28,883
Full-time (Permanent)
Security Monitoring Associate - Planning Inspectorate - HEO
£36,396 - £39,424
Full-time (Permanent)
Senior Software Developer - DBT - G7
(including allowances) London £63,248 to £79,133, National £59,634 to £75,618.
Full-time (Permanent)
Security Architect Data Services and Analytics (DSA) - HO - SEO
£44,720 National, £48,720 London plus up to £12,680 allowance
Full-time (Permanent)
Lead Enterprise Architect - Competition & Markets Authority - G6
£73,730 - £79,813 a DDAT allowance of up to £8750 may be applicable
Full-time (Permanent)
Lead Test Engineer - Companies House - SEO
Base salary is £41,571 - £45,784 with an additional DDaT allowance of £4,350 - £11,000 available
Full-time (Permanent)
Lead Interaction Designer - GDS - G7
The base salary of this grade is £67,126 for other locations. Offers made above this will be made up with a specialist pay allowance.
Full-time (Permanent)
Lead Software Developer - Companies House - SEO
The basic salary is £41,571 - £45,784 with an additional, non-pensionable digital allowance of up to £11,000
Full-time (Permanent)
Senior Software Developer - MoJ - G7
£56,532 - £69,338 plus allowance
Full-time (Permanent)
Developer - HMRC - HEO
£36,320 - £39,234
Full-time (Permanent)
Technical Architect - Welsh Government - SEO
£45,974 - £54,431
Full-time (Permanent)
Lead Technical Architect Chief Technology Office (CTO) - HO - G7
£60,300 - £64,300 location dependant plus allowance up to £20,100
Full-time (Permanent)
Principal Salesforce Architect - Ofgem - G6
London £65,835-£86,547 National - £61,446-£80,425.
Full-time (Permanent)
Development Operations (DevOps) Engineer - MoD - SEO
£44,590, Offers above this will be made up of DSA , Digital Skill allowance of up to £11,400
Full-time (Permanent)
Infrastructure Engineering Specialist - GCHQ - EO
£44,044 plus additional allowances
Full-time (Permanent)
Lead Product Manager FTC 8 months - Ofqual - G7
£50,882 - £62,011
Full-time (Permanent)
Product Manager - Ofqual - SEO
£41,113 - £48,088
Full-time (Permanent)
Senior Data Engineers - FCDO - SEO
£44,500 - £49,500
Full-time (Permanent)
Enterprise Business Architect (Army) - MoD - SEO
£44,590 This post may be eligible for a Digital Skills Allowance of up to £11, 400 per annum
Full-time (Permanent)
Principal Technical Architect - MoD - G6
£70,540 This post is eligible for a Digital Skills Allowance of up to £18,000 per annum
Full-time (Permanent)
Test Manager - Welsh Revenue Authority - SEO
£45,974 - £54,431 plus additional allowance £3,150 - 6,143
Full-time (Permanent)
Lead Interaction Designer - DWP - G6
£72,664 - £77,740
Full-time (Permanent)
Software Developer - HSE - HEO
£36,235 - £39,611
Full-time (Permanent)
Lead DevOps Engineer - DWP - G6
£72,664 - £89,995
Full-time (Permanent)
Senior Infrastructure Engineer - DfE - SEO
£41,458 £45,492 (London minimum) This post is eligible for a Digital, Data and Technology (DDT) capability based pay (CBP) allowance.
Full-time (Permanent)
Senior Infrastructure Engineer - DfE - SEO
£41,458 London minimum - £45,492 plus additional allowance
Full-time (Permanent)
Technical Architect - HO - SEO
£44,720 - £52,130 You may be eligible for an additional allowance up to £12,680
Full-time (Permanent)
Army Network Architect - MoD - HEO
£36,530
Full-time (Permanent)
Senior DevOps Engineer - DWP - G7
£55,557 - £78,517
Full-time (Permanent)

Subscribe to our newsletter

Sign up here