Rodeo
Get started

Government Digital Service

Head of Cyber Security Risk Management, Digital Identity

Bristol
Posted about 21 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Location: Bristol, London, Manchester (HYBRID)

About the job

Job summary

This role will require the post holder to have SC clearance to start and may be required to undergo Developed Vetting (DV) once in post, therefore successful candidates will be expected to either hold this or be willing to undertake the DV clearance process once in post.

More information on DV clearance is linked here

The Government Digital Service (GDS) is the digital centre of government. We are responsible for setting, leading and delivering the vision for a modern digital government. Our priorities are to drive a modern digital government, by:

  • joining up public sector services
  • harnessing the power of AI for the public good
  • strengthening and extending our digital and data public infrastructure
  • elevating leadership and investing in talent
  • funding for outcomes and procuring for growth and innovation
  • committing to transparency and driving accountability

We are home to the Incubator for Artificial Intelligence (I.AI), the world-leading GOV.UK and at the forefront of coordinating the UK’s geospatial strategy and activity. We lead the Government Digital and Data function and champion the work of digital teams across government.

We’re part of the Department for Science, Innovation and Technology (DSIT) and employ more than 1,000 people all over the UK, with hubs in Manchester, London and Bristol.

The Government Digital Service is where talent translates into impact. From your first day, you’ll be working with some of the world’s most highly-skilled digital professionals, all contributing their knowledge to make change on a national scale.

Join us for rewarding work that makes a difference across the UK. You'll solve some of the nation’s highest-priority digital challenges, helping millions of people access services they need.

Job description

As Head of Cyber Security Risk Management for One Login and Digital Identity you will play a central role in protecting the UK’s current and future digital identity ecosystem. At scale, One Login will be the front door for millions of users to access digital public services. Security, reliability and resilience are absolutely critical to delivering our mission. This is a high profile role, suited to an experienced security leader with a track record of setting direction and running security risk, governance and assurance for a complex area.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

As Head of Cyber Security Risk Management you will have oversight for the Digital Identity Cyber Information Assurance team, taking responsibility for the governance, risk management, compliance and 3rd party assurance. In addition, you will be responsible for:

  • governance, risk and assurance leadership: building civil servant capability to run a mature, responsive cyber assurance team, working in collaboration with One Logins dedicated Security Operations, Security Design & Architecture, Pods (developer teams) and wider GDS and DSIT cyber teams. Work in partnership with GDS (Privacy, Information Assurance, Security Architecture, Cyber), GSG, CDIO Cyber, NCSC and other government departments
  • governance, risk and assurance: lead design, implementation and operating of information security governance frameworks aligned to DSIT and regulatory context. Ensure the team provides independent information assurance across the One Login Programme but work closely with the GDS Infosec team for second line assurance. Build and lead the third party and supply chain assurance strategy. Maintain and innovate the current risk management board ensuring present risk positions are clearly communicated to the senior leadership team (SLT).
  • multi tier assurance: work closely with the GDS Infosec Team to support 2nd line assurance. Build and manage an integrated governance process which has a unified risk perspective enabling both first and second line assurance to work on a common understanding of the risk posture. Drive proactive engagement across both teams to stop any siloed forming and make sure the risk development lifecycle is balanced.
  • policy & standards: develop and maintain security policies, standards frameworks, and governance processes aligned to government and industry best practice for complex cloud-native environments
  • assurance & remediation: drive security assurance activities across One Login programmes, suppliers, and operational services, including audits, assessments, and ensuring timely remediation within required SLOs
  • stakeholder collaboration: build strong relationships with key stakeholders—including GDS (Privacy, Information Assurance, Security Architecture), GSG, CDIO Cyber, and NCSC—to embed security into delivery, architecture, procurement, and operational decision making
  • compliance & frameworks: ensure all operations meet stringent UK Government security requirements by supporting regulatory and contractual compliance activities, including alignment to standards such as NIST, CAF, and GovAssure
  • governance & reporting: establish and maintain operational metrics to produce clear, meaningful reporting and dashboards that measure the programme's threat posture and support executive decision making
  • security culture leadership: working in close collaboration with the Head of Product Security and Head of Security Operations for One Login and the GDS CISO, take responsibility for embedding a robust security culture across the programme.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Person specification

We’re interested in people who have experience and knowledge of most of the following:

  • a strong track record of experience leading security governance, assurance, risk, or compliance functions, ideally for a Critical National Infrastructure (CNI) or comparable risk/profile/impact level product
  • in-depth knowledge of government security standards, frameworks, and assurance approaches, with demonstrable success applying frameworks such as CAF, NIST 800-53, GovAssure, and Secure by Design Principles
  • experience developing and implementing security policies and control frameworks in complex cloud-native environments and serverless architectures
  • ability to communicate complex security concepts clearly and establish effective working relationships with key security stakeholders, including technical and non-technical specialists across organisational boundaries
  • strong analytical, reporting, and risk management capabilities, including building governance dashboards and executive-level assurance reporting
  • understanding of supplier assurance, vulnerability management, and experience integrating governance with security operational integration.
  • hold recognised cyber security certifications such as CISSP, CISM, or CRISC

Note: DSIT cannot offer Visa sponsorship to candidates through this campaign. DSIT holds a Visa sponsorship licence but this can only be used for certain roles and this campaign does not qualify.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Cyber Security Risk Management
Information Assurance
Governance Risk and Compliance
Third Party Assurance
Cloud-Native Security
Security Policy Development
Stakeholder Management
Vulnerability Management
Risk Reporting
Security Culture Leadership
NIST Framework
CAF Framework
GovAssure
Secure by Design Principles
Audit and Remediation
Supply Chain Assurance

Location

Bristol, England, United Kingdom

Sign up to applySee more jobs like this