Cyber Security Risk Analyst - Government Legal Department - SEO
Government Digital & Data -
Location
Bristol, Croydon, Leeds, London, Manchester
About the job
Job summary
From healthcare to artificial intelligence, energy to national security, we provide legal advice to government departments on nation-changing subjects.
At Government Legal Department we have a vital, single-minded purpose: to help the Government govern well within the rule of law. This is complemented by our exciting vision to be an outstanding legal organisation, committed to the highest standards of service and professionalism and a brilliant place to work where we can all thrive and fulfil our potential.
Our work touches almost every aspect of public life. We are the largest provider of legal services across government, working on high profile matters.
Our respected professionals are involved in everything from regulation and litigation to advice on drafting legislation. They provide expertise to the full range of government departments. We are at the heart of delivering the government’s priorities and our success depends on our people.
GLD is a non-ministerial government department headed by the Treasury Solicitor, our Permanent Secretary, and employs nearly 4000 people, including nearly 3000 legal professionals. We have offices nationwide, in Bristol, Leeds, inner and outer London and Manchester. Our lawyers can also be located within other departments and overseas.
GLD also depends on a range of cross-functional professionals to provide our corporate services. There are nearly 1000 colleagues playing an essential part in helping GLD to achieve its purpose and truly deliver much more than law.
This is an exciting time to join GLD, with cutting edge legal work on global issues and a transformation agenda which is ensuring the Department exemplifies the Modern Civil Service.
To find out more about what we do you can view our introductory film. On our website you can hear from team members, find out how to apply and learn about the benefits of working for GLD. You can also read more about the future vision for GLD in our GLD Strategy 2024 – 2027.
Job description
The Digital, Data and Cyber Division is transforming the way GLD works through modern and secure digital services.
We are building an ever expanding and modern digital workplace that empowers our people, strengthens collaboration and enables the organisation to operate efficiently, securely and sustainably.
Through agile delivery and user-centred approaches, we design and deliver products and services in partnership with the people who use them, ensuring solutions meet real needs and deliver lasting value.
As part of the wider Government Digital and Data profession, we play a key role in transforming how government operates, enabling better outcomes for colleagues, stakeholders and the public we serve.
The Role
Join GLD at an exciting stage in the evolution of its Cyber Security capability. At the heart of our day-to-day Cyber operations, you’ll turn complex risks into clear, practical decisions—helping new services, applications, suppliers and technology changes move forward securely and with confidence.
You’ll collaborate with technical teams, service owners, suppliers and governance leaders to uncover cyber risks, shape practical solutions and ensure confident, well-evidenced decisions.
This is an ideal opportunity for someone organised, curious and pragmatic—an engaging communicator who can make cyber security clear and relevant to both technical and non-technical audiences.
Key Responsibilities
- Drive day-to-day cyber security operations, coordinating requests, tracking risks, progressing vulnerabilities and building robust evidence.
- Shape secure technology change through the Change Advisory Board, challenging risk, testing and rollback plans to support confident decisions.
- Deliver proportionate Security Risk Assessments for new applications, services, suppliers, contracts and significant technology changes.
- Strengthen supply-chain assurance by assessing how third parties access, process, host and connect to GLD data and systems.
- Review cloud, SaaS, Microsoft 365, Azure, on-premises and hybrid environments to improve access, configuration, monitoring and resilience.
- Advance GLD’s security maturity through penetration testing, vulnerability remediation, ISO 27001, Cyber Essentials Plus and audit activity.
- Turn complex cyber requirements into clear, practical actions by collaborating with service owners, Commercial, Information Governance, suppliers and technical teams.
Person specification
Behaviours
Below are details of the Success Profiles that make up this role. Demonstrating all the behaviours listed below is essential at either application or interview. You can read more about Success Profiles and how they are used as an assessment method before completing your application.
We'll assess you against these behaviours during the selection process:
- Communicating and influencing
- Making effective decisions
Key Skills and Experience
Essential – must be demonstrated at application and interview
- Experience in cyber security, cyber risk, security assurance or compliance, with strong knowledge of identifying, assessing, managing and communicating cyber security risks within a complex digital environment.
- Experience of conducting or contributing to security risk assessments, reviewing technical, security and supplier information, identifying vulnerabilities and control gaps, and making clear, proportionate recommendations.
- Good understanding of third-party and supply-chain security risks and cyber resilience, including business continuity and disaster recovery.
- Good understanding of security controls across cloud, SaaS and hybrid environments, including identity and access management technologies such as Microsoft 365, Active Directory, Microsoft Entra ID, multi-factor authentication and privileged access management.
- Experience of working collaboratively with technical specialists, service owners, suppliers and other stakeholders, providing effective challenge and supporting informed, risk-based decisions.
- Understanding of security assurance frameworks, vulnerability management and audit activity, and how these contribute to improving organisational cyber security.
Desirable – must be demonstrated at application and interview
- Knowledge of ITIL change and configuration management, including the security considerations associated with technology change.
- Familiarity with SIEM and vulnerability management tools.
- Understanding of penetration testing principles, including how findings are assessed, prioritised and remediated.
- Knowledge of security standards and assurance schemes such as ISO 27001 and Cyber Essentials Plus.
Desirable criteria will be used when there is a need to distinguish between candidates who are closely tied or the same after the initial consideration of essential criteria, at sift and interview.
Qualifications
Desirable
- Cloud Security certification Risk Management certification
- Cyber Vulnerability Management Certificate
Desirable criteria will be used when there is a need to distinguish between candidates who are closely tied or the same after the initial consideration of essential criteria, at sift and interview.