skip navigation
skip mega-menu

Cyber Security Supply Chain Risk Manager - Government Digital Service - G7

Government Digital & Data -

Full-time (Permanent)
£56,070 - £64,040 (National) / £61,740 - £72,466 (London) Based on capability
Published on
9 February 2026
Deadline
22 February 2026

Location

Bristol, London, Manchester

About the job

Job summary

The Government Digital Service (GDS) is the digital centre of the government. We are responsible for setting, leading and delivering the vision of a digital modern government.

Our priorities are to drive a modern digital government, by: 

  1. joining up public sector services
  2. harnessing the power of AI for the public good
  3. strengthening and extending our digital and data public infrastructure
  4. elevating leadership and investing in talent
  5. funding for outcomes and procuring for growth and innovation
  6. committing to transparency and driving accountability

We are home to the Incubator for Artificial Intelligence (I.AI), the world-leading GOV.UK and at the forefront of coordinating the UK’s geospatial strategy and activity. We lead the Government Digital and Data function and champion the work of digital teams across government.

We’re part of the Department for Science, Innovation and Technology (DSIT) and employ more than 1,000 people all over the UK, with hubs in Manchester, London and Bristol.

The Government Digital Service is where talent translates into impact. From your first day, you’ll be working with some of the world’s most highly-skilled digital professionals, all contributing their knowledge to make change on a national scale.

Join us for rewarding work that makes a difference across the UK. You'll solve some of the nation’s highest-priority digital challenges, helping millions of people access services they need

The Cyber Security Supply Chain Risk Manager is responsible for ensuring the security, integrity, and resilience of the organisation's supply chain in relation to cybersecurity risks. This role involves identifying and assessing cybersecurity risks within the supply chain, identifying suitable tender/contract security requirements/obligations to mitigate these risks, managing third-party vendor compliance with GDS’ specified security terms, and ensuring compliance/alignment with regulatory requirements and industry standards respectively. The Cyber Security Supply Chain Risk Manager will work cross-functionally with procurement, commercial, IT, risk management, engineering operations and legal departments to ensure that cybersecurity risks in the supply chain are understood and effectively managed throughout the supply chain lifecycle.

Job description

What you’ll do:

  • Cybersecurity Risk Assessment: conduct and manage comprehensive risk assessments of suppliers, vendors, and partners to identify and mitigate cybersecurity threats in the supply chain
  • Service Team Collaboration: support and assist Service Teams with the security aspects of their procurement needs, ensuring that appropriate information and cyber security requirements are included in tender documents, specifications and contracts Liaise with Commercial and Legal functions to ensure the requirements are included in tender and contract documentation
  • Vendor Due Diligence: collaborate with procurement and legal teams to assess vendor security practices during onboarding and throughout the vendor lifecycle ensure third-party vendors comply with the organisation’s cybersecurity policies and standards
  • Supply Chain Risk Management (SCRM): develop and maintain a robust cybersecurity supply chain risk management (SCRM) program, including standardised supply chain risk logging, continuous monitoring, auditing, and evaluating third-party risk exposure individually, by category and in aggregate
  • Compliance and Standards: ensure supply chain activities comply with relevant cybersecurity frameworks and regulations (e.g., NCSC Cyber Assessment Framework, GovS007, ISO 27001, GDPR/DPA18) Implement best practices from industry standards to secure supply chain operations
  • Third-Party Contract Management: work with the legal and commercial teams to ensure cybersecurity clauses are included in supplier contracts Define key performance indicators (KPIs) and service level agreements (SLAs) around vendor cybersecurity responsibilities Periodically audit contracts for security terms, in order to understand any gaps in live contracts
  • Incident Response: support the development of processes and protocols for managing third-party cybersecurity incidents, including coordinating with vendors during a breach, ensuring timely communication, and mitigating the impact on the organisation
  • Vendor Cybersecurity Audits: lead or co-ordinate periodic cybersecurity audits of vendors and third parties to ensure they maintain high security standards Identify gaps and work with vendors to implement remediation plans
  • Training and Awareness: provide training and support to internal stakeholders on supply chain cybersecurity risks and vendor management best practices Increase awareness of supply chain threats and trends within the organisation
  • Collaboration and Communication: work closely with IT, risk, and procurement teams to communicate findings and recommended mitigations Ensure transparency and alignment between teams on cybersecurity risks and strategies
  • ‘Intelligent customer’ supply chain management: contribute to the working relationship and management of inter-government supply chain, for example, internal services provided by another government department
  • Supply Chain Resilience: develop strategies to ensure supply chain resilience in the face of cybersecurity threats, including supply chain mapping and diversification to mitigate risk
  • Monitoring and Reporting: continuously monitor the security posture of the supply chain and provide regular reports to leadership on third-party risk exposure, incidents, and mitigation efforts

Person specification

We’re interested in people who have:

  • significant demonstrable experience in cybersecurity, supply chain management, and vendor/third-party risk management, including supply chain risk assessments and audits
  • experience working with cybersecurity frameworks, risk management methodologies, and compliance requirements (e.g., NCSC CAF, ISO 27001, SOC 2), with strong information and cyber security risk knowledge and experience
  • experience in managing cybersecurity for complex supply chains in sectors such as technology, healthcare, finance, or critical infrastructure, with the ability to identify and assess potential cybersecurity risks across the supply chain
  • in-depth knowledge of cybersecurity principles and how they apply to supply chain and third-party risk management, including familiarity with emerging threats such as cyber-physical risks, counterfeit hardware/software, and compromised components
  • strong understanding of supply chain operations, global supply chain regulations, and their intersection with cybersecurity policies, including integration of cybersecurity practices into procurement processes and supplier lifecycle/third-party vendor risk management
  • knowledge of cloud service providers, managed service providers (MSPs), and other third-party IT service ecosystems, and experience working with vendor management systems, supply chain management tools, and cybersecurity risk platforms
  • excellent communication and negotiation skills, with the ability to manage complex relationships with suppliers and vendors, and strong analytical skills to translate complex cybersecurity issues into actionable business term
  • indicative professional qualifications / accreditations:
    a degree in Information Security, Information Technology, Business, or a related discipline (or equivalent professional experience), complemented by preferred professional certifications such as CISSP, CISM, CTPRP, or CSCP, with ISO 27001 Lead Auditor or Implementer qualifications considered advantageous

More jobs at Government Digital & Data

Interaction Designer - GDS
Full-time (Permanent)
Test Engineer - GDS - SEO
£46,725 - £50,220 (London) / £42,893 - £45,653 (National) plus additional allowance
Full-time (Permanent)
Cloud Infrastructure Engineer - The National Archives - HEO
£42,000 plus £2,998 Market Supplement
Full-time (Permanent)
Interaction Designer - MI5 The Security Service - HEO
£60,358
Full-time (Permanent)
Senior Software Developer - HM Courts and Tribunals Service - G7
The national salary is £58,511 - £65,329. London salary is £63,343 - £70,725.
Full-time (Permanent)
Software Developer (Low Code) - HM Courts and Tribunals Service - SEO
The national salary range is £42,914 - £46,182, London salary range is £49,325 - £53,081.
Full-time (Permanent)
Data Governance & Privacy Lead - Government Digital Service - G7
£56,070 - £61,793 (National) / £61,740 - £70,219 (London) Based on capability
Full-time (Permanent)
Data Governance and Privacy Manager - Government Digital Service - SEO
£42,893 - £45,653 (National) / £46,725 - £50,220 (London) Based on capability
Full-time (Permanent)
Senior Officer (DDaT Financial Performance) - National Crime Agency - HEO
£45,326 plus allowances and additional £4,218 London weighting
Full-time (Permanent)
Senior IT Service Manager - HMRC - SEO
National £45,544 - £69,523 London £50,686 - £55,157
Full-time (Permanent)
Senior Technical Architect - Department for Work and Pensions - G7
£57,946 - £83,917
Full-time (Permanent)
Lead Technical Architect, End User Compute & Collaboration - Home Office - G7
£62,109 National £66,229 London Roles plus up to £18,291 additional allowance
Full-time (Permanent)
Director Platform Engineering, Resilience & Cyber - Department for Science, Innovation & Technology - SCS2
£100,000 - £163,000
Full-time (Permanent)
Head of Enterprise Architecture (Principal Enterprise Architect) - National Savings and Investments - G6
£92,000 - £82,000 London; £87,000 - £79,000 Durham, Lytham, Glasgow
Full-time (Permanent)
Senior Software Developer - Ministry of Housing, Communities and Local Government - G7
National £61,374 London: £66,929 plus additional digital allowance
Full-time (Permanent)
Senior Delivery Manager - Welsh Revenue Authority - G7
£61,098 - £73,057
Full-time (Permanent)
Senior Agile Delivery Manager - Department for Work and Pensions - G7
£57,946 - £77,895
Full-time (Permanent)
Senior Project Manager - Driver and Vehicle Licensing Agency - G7
£57,515
Full-time (Permanent)
Infrastructure Engineer - Driver and Vehicle Standards Agency - HEO
£35,663 plus £4,000 London weighting for Yeading location
Full-time (Permanent)
Junior Infrastructure Engineer - Driver and Vehicle Standards Agency - EO
£30,485 additional £4,000 London weighting for Yeating location
Full-time (Permanent)
Cyber Engineering 12 month Internship - National Crime Agency - EO
National £36,057 London offers additional £4,218 weighting
Internship/ Placement
Business Analyst - MI5 The Security Service - HEO
£60,358
Full-time (Permanent)
Senior Business Analyst (Microsoft 365) - Government Property Agency - G7
£56,500 - £62,554
Full-time (Permanent)
Business/Performance Analyst 12 month Internship - National Crime Agency - EO
£36,057 plus London weighting £4,218
Internship/ Placement
Senior Product Manager - Department for Energy Security & Net Zero - SEO
National: £42,385 - £46,850 London: £46,280 - £51,540 plus up to £1,500 enhancement
Full-time (Permanent)
Front End Developer - Intellectual Property Office - HEO
£36,736 up to £46,743 with additional allowance
Full-time (Permanent)
DevOps Engineer - HM Land Registry - HEO
£42,500 - £45,700 Pay supplement scheme - depending on your level of assessed capability
Full-time (Permanent)
Senior Platform Engineer - Department for Business and Trade - G7
London: £67,547 to £83,778/ National: £63,824 - £80,158 (including allowance)
Full-time (Permanent)
Senior Technical Architect - HMRC - G7
National Salary £58,541 - £64,624. London Salary £65,869 - £72,711.
Full-time (Permanent)
Principal Technical Architect - Home Office - G6
£76,117 for National Roles or £80,237 for London Roles
Full-time (Permanent)
Director of Technology and Operations - FCDO Services - SCS1
£81,000 - £98,000 Plus £1,750 location allowance
Full-time (Permanent)
Chief Digital and Information Officer - National Crime Agency - SCS2
£100,000 - £149,999
Full-time (Permanent)
Chief Digital and Information Officer - Driver and Vehicle Standards Agency - SCS1
£95,000
Full-time (Permanent)
Deputy Director, Prime Minister Media Strategy - Cabinet Office - SCS1
£81,000 - £117,800
Full-time (Permanent)
Project Manager - Intellectual Property Office - SEO
£47,766 - £50,155
Full-time (Permanent)
Head of Digital Design - Intellectual Property Office - G7
£66,162 plus up to £77,888 with additional allowances
Full-time (Permanent)
Head of Programme (GOV.UK) - Government Digital Service - G6
£67,972 - £75,275 (national) Based on capability
Full-time (Permanent)
Senior Cyber Business Relationship Manager - Government Digital Service - SEO
£44,288 - £47,413 (Bristol & Manchester) and £48,244 - £51,853 (London) Based on capability.
Full-time (Permanent)
Senior Test Engineer - Government Digital Service - G7
£61,740 - £70,219 (London) / £56,070 - £61,939 (National) Based on capability
Full-time (Permanent)
Senior Delivery Manager - National Crime Agency - G7
£67,609 plus additional £4,218 for London
Full-time (Permanent)
Delivery Manager - Office for National Statistics - SEO
£41,985 - £47,121
Full-time (Permanent)
Senior Delivery Manager - National Crime Agency - G7
£67,609 plus additional £4,218 London weighting
Full-time (Permanent)
Delivery Manager - National Crime Agency - SEO
£55,575 plus additional £4,218 for London
Full-time (Permanent)
Senior Service Designer - Government Digital Service - G7
£70,219 - £73,702 (London) / £61,793 - £65,163 (National) Based on capability
Full-time (Permanent)
Junior Software Developer (IT Placement) - HM Land Registry - EO
£34,800 - £38,000
Full-time (Permanent)
Senior Delivery Manager - Department for Energy Security & Net Zero - G7
National: £55,105 - £62,475; London: £60,620 - £67,565
Full-time (Permanent)
Apprentice Infrastructure Engineer - HM Land Registry - AO
£26,811
Full-time (Permanent)
Technical Lead (Senior Infrastructure Engineer) - Met Office - SEO
£43,081 - £46,728. Total reward package £65,658 which includes additional allowance
Full-time (Permanent)
Business Analyst - Active Travel England - SEO
£44,241
Full-time (Permanent)
ServiceNow Business Analyst - Department for Environment, Food and Rural Affairs - SEO
National: £42,665 - £46,765, London: £46,060 - £50,495
Full-time (Permanent)
Senior Business Analyst - Department for Work and Pensions - G7
£57,946 - £68,205
Full-time (Permanent)
Test Engineer - Driver and Vehicle Licensing Agency - HEO
£35,663
Full-time (Permanent)
Lead Test Engineer (Automation) - Home Office - G7
£62,109
Full-time (Permanent)
Deputy Director, Central Data Science and AI - Office for National Statistics - SCS1
£81,000
Full-time (Permanent)
Data & CRM Planner - National Savings and Investments - HEO
£38,000-40,400 London; £37,200 -£39,200 Durham, Lytham, Glasgow
Full-time (Permanent)
IT Apprentice - FCDO Services - AO
£27,500 plus location allowance up to £1,750
Internship/ Placement

Subscribe to our newsletter

Sign up here