Technology Risk Advisor - Government Digital Service - SEO
Government Digital & Data -
Location
Bristol, London, Manchester
About the job
Job summary
The Government Cyber Unit's mission is to protect public services from cyber threats and digital resilience failures. We are working to achieve a step change in our cyber and digital resilience across government, through delivery of the Government Cyber Action Plan, and working closely with departments and national technical authorities including the National Cyber Security Centre to deliver. This is a challenging time to be working in cyber security and digital resilience, but we have an incredible opportunity to make a difference to people’s lives and promote national security by protecting the public services and national infrastructure they rely on. We work at the forefront of shaping the UK’s national response to emerging cyber and technology issues - from the increasingly complex range of state-sponsored cyber-attacks and supply chain compromises, through to the transformational benefits and security challenges of frontier AI and quantum computing.
We are committed to creating an inclusive and supportive working environment where people can learn, develop and do their best work. Continuous professional development and a focus on wellbeing is core to our unit culture. We welcome applications from candidates who share this ethos and are excited by our mission.
We’re part of the Department for Science, Innovation and Technology (DSIT) and employ more than 1,000 people all over the UK, with hubs in Manchester, London and Bristol.
You will be joining the Technology Risk team, part of the Cyber Accountability Deputy Director area, helping to drive consistent, effective technology risk management across government. The Technology Risk team works across central teams and departments to improve how technology risks are identified, understood and acted on – using frameworks, data and targeted engagement to drive accountability and investment.
Join us for rewarding work that makes a difference across the UK. You'll solve some of the nation’s highest-priority digital challenges, helping millions of people access services they need
Job description
We are hiring two roles to support the development and operation of the cross government Technology Risk Framework and Technology Risk Appetite. The postholder helps maintain government's understanding of significant technology risks through research, analysis, governance support and stakeholder engagement, ensuring risk information is accurate, accessible and available to support decision making.
If you're motivated by national-scale impact, this is a chance to be at the heart of how government manages technology risk. Working closely with the Technology Risk Manager, you'll help maintain the Technology Risk Framework and Technology Risk Appetite, coordinate inputs from departments and central teams, and turn complex information into clear, well-organised products.
You'll work across organisational boundaries, acting as a reliable coordination point and helping the team deliver at pace and to a high standard.
As Technology Risk Advisor - Framework & Risk Appetite you’ll:
- Framework & Risk Appetite Support: Support the development and maintenance of the Technology Risk Framework and Technology Risk Appetite, including documentation, evidence gathering, stakeholder engagement and version control.
- Technology Risk Group support: Support the operation of the Technology Risk Group, including preparing agendas, coordinating papers, tracking actions and helping ensure risks are presented clearly and consistently for discussion and with appropriate supporting evidence for discussion and decision-making.
- Risk Research & Analysis: Conduct research and analysis on technology risk topics, supporting the identification of emerging risks, threat trends, control weaknesses and cross-government risk themes.
- Stakeholder Coordination: Act as a coordination point for departments, central teams and national technical authorities, helping gather evidence, manage inputs and maintain effective working relationships.
- Risk Information Management: Maintain risk trackers, action logs, dependencies and supporting datasets, ensuring information is accurate, accessible and available to support governance and decision-making.
- Continuous Improvement: Support improvements to technology risk processes, documentation, reporting and governance arrangements as the Technology Risk Framework matures.
As Technology Risk Advisor - Monitoring & Advisory you’ll:
- Department Engagement: Support engagement with departments, helping identify barriers to effective technology risk management and supporting adoption of the Technology Risk Framework and Technology Risk Appetite.
- Capability Building & Learning: Support delivery of workshops, training and peer-learning activity that improves understanding of technology risk assessment, risk treatment and technology risk governance.
- Guidance & Advisory Products: Develop guidance, briefings, templates and case studies that help departments apply technology risk management approaches consistently.
- Capability & Maturity Monitoring: Monitor departmental adoption of the Technology Risk Framework and Technology Risk Appetite, identifying gaps, implementation challenges, risks and opportunities for improvement.
- Feedback & Insight: Collate and analyse feedback from departments, identifying common risks, implementation challenges, emerging themes and examples of good practice to support continual improvement and risk-based decision making.
- Risk Research & Improvement: Conduct research on technology risk topics, threat trends and emerging issues, supporting development of guidance, capability-building products and improvement activity.
- Controls & Remediation Support: Support departments to identify and implement proportionate controls, risk treatments and remediation activity, helping improve resilience and reduce the likelihood and impact of technology risks.
Please Note - The post holder may be required to support out of hours on call rotas for responding to cyber and digital resilience incidents, for which remuneration and /or flexible working arrangements will be available.
Person specification
We’re interested in people who have:
- experience supporting risk management, governance, programme delivery or related functions in a complex environment
- the ability to manage and track multiple workstreams, actions and deadlines, keeping accurate records and trackers
- confidence drafting clear written material including, minutes, briefings, templates and guidance for a range of audiences
- the ability to collate, quality-check and analyse information from a range of sources and present it clearly
- strong interpersonal skills and the ability to coordinate inputs from stakeholders across organisational boundaries
- good attention to detail, with sound document and version-control discipline
- proficiency with everyday tools such as SharePoint, Excel and collaboration software to maintain trackers and documentation
- understanding of risk management concepts, including risk assessment, risk appetite, controls and mitigation
- ability to gather, analyse and present information from multiple sources to support risk-based decision making
- interest in technology, cyber or operational risk, including an awareness of security threats, resilience risks and technology governance, and a willingness to build knowledge of risk frameworks, appetite and governance