Senior Cyber Security Risk Manager
Home Office Digital - Salford
Salford
The Senior Cyber Security Risk Manager plans and implements organisation-wide processes and procedures for the management of risk. They monitor the efficiency and effectiveness of the risk management processes across the organisation and make recommendations for continuous improvement.
As a Senior Cyber Security Risk Manager, your main day to day responsibilities will be:
• Developing risk management-related policy and assuring the ongoing appropriateness of policy in accordance with regulation and wider organisational and government policies.
• Supporting the embedding of risk management systems, processes, and frameworks, communicating these across the business to a range of stakeholders.
• Working within established security and risk management governance structures, usually under supervision to support, review and undertake risk management activities such as: undertaking cyber security related risk assessments; threat assessments and other risk management activities.
• Communicating the risk assessment outcomes to stakeholders in ways that support effective security, risk management and decision-making.
• Providing advice to address straight-forward cyber security risks by applying a variety of security capabilities, which may include using published guidance or standards, and validating the effectiveness of risk mitigation measures.
• Helping risk or service owners to make decisions that are well informed by providing clear security advice, including contributing to reports or working within established reporting chains in a security team.
• Providing risk-oriented training to a range of stakeholders, including preparation of training materials, to ensure that relevant stakeholders are equipped to use standard risk management frameworks.
Essential Skills
You’ll have a demonstrable experience in, and passion for, Cyber Security including the
following skills or experience in:
- Reviewing and performing risk assessments, developing risk treatment plans and communicating those risks to others.
- Identifying typical risk indicators and explaining prevention measures.
- Adopting a structured approach to executing and documenting audits, following agreed standards.
- Maintaining integrity of records to support and satisfy audit trails.
- Ability to champion cyber security risk and ensure ongoing appropriateness or practices.
- Communicating technical requirements effectively to both technical and non technical stakeholders.