Ministry of Justice UK
Security Risk & Assurance Practitioner (Ref: 21441)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
East Midlands (England), East of England, London (region), North East England, North West England, Scotland, South East England, South West England, Wales, West Midlands (England), Yorkshire and the Humber
Job Summary
This is a Nationally based role
Job Description
Cyber Security Risk and Assurance Practitioner (HEO)
The MoJ Information Security Team sits at the heart of the Ministry of Justice, enabling good security practices through the provision of security policies, guidance and education, by understanding cyber security risks from all parts of the Ministry of Justice and providing assurance to the departmental SIRO, the Permanent Secretary and other senior stakeholders that these risks are being effectively managed in the delivery of MoJ objectives.
The role of the Cyber Security Risk and Assurance Practitioner is to support the central MoJ Information Security Team in carrying out cyber security assurance, highlighting non-compliance with required standards and raise and communicate cyber security risks arising from control gaps.
The team works across a diverse range of digital services, technologies and business functions to identify and understand cyber security risks and provide assurance that these risks are being managed appropriately in support of departmental objectives.
The role involves reviewing services and systems, analysing evidence, identifying risks and opportunities for improvement, and communicating findings to a wide range of stakeholders.
The Cyber Security Risk and Assurance Practitioner may also provide advice to others on good risk management practices to enable them to manage residual risk well, identify trends resulting from risk and assurance activities and use these to propose and deliver improvements to processes, policies and guidance, and enable senior team members to resolve tactical requests to the team.
All members of the team are expected to help develop the MoJ Security Function as a centre of excellence for the department and to contribute to building a brilliant and diverse team that is a welcoming place for all.
All members of the team are expected to contribute to developing the MoJ Security Function as a centre of excellence, helping to build a brilliant, diverse and inclusive team environment. The post holder will contribute across a variety of assurance, risk and governance activities, working collaboratively with colleagues to continuously improve security practices, processes and decision-making across the department.
Typical Role Expectations And Responsibilities
Security Risk and Assurance
- Deliver security assurance, governance and risk management activities across a range of digital services, technical platforms, projects, suppliers and business functions.
- Assess the effectiveness of security controls and identify control gaps, risks and areas requiring improvement.
- Provide evidence-based opinions and recommendations on cyber security risks and the adequacy of controls, supporting informed decision-making and proportionate risk management while enabling business outcomes.
- Support the delivery of assurance activities across the department including assurance reviews, incident management, GovAssure and third party assurance and communicate findings in a clear and proportionate manner to stakeholders.
Review, Analysis and Investigation
- Conduct detailed reviews of digital services, business processes and technical solutions to understand how security and risk management requirements are being implemented in practice.
- Gather, validate and analyse evidence from multiple sources to identify risks, trends, themes, control weaknesses and examples of good practice.
- Apply analytical and investigative skills to understand complex issues, challenge assumptions and determine underlying causes of identified risks or concerns.
- Use data and evidence to support recommendations and prioritisation of security improvement activities.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Technical Understanding
- Develop and maintain an understanding of modern digital technologies and how they are used within large organisations.
- Develop an understanding of cloud platforms, enterprise technologies, applications and digital services, and use this knowledge to support assurance, risk and governance activities.
- Translate technical concepts into language that can be understood by non-technical stakeholders.
Reporting and Stakeholder Engagement
- Produce clear, concise and evidence-based reports, assessments, briefings and recommendations for technical and non-technical audiences.
- Present findings confidently to stakeholders and support discussions relating to risk management, governance and assurance outcomes.
- Build productive working relationships across the organisation and act as a trusted partner in supporting good security practices.
- Contribute to submissions, reports and briefing materials for senior leaders and governance forums.
Process Improvement
- Review assurance, governance and risk management processes to identify opportunities to improve efficiency, consistency and effectiveness.
- Support the development and implementation of improvements to processes, guidance, reporting and ways of working.
- Identify themes emerging from assurance and risk activities and use insight to drive continuous improvement.
Team Contribution
- Support a broad range of work across the team and adapt to changing priorities and organisational needs.
- Share knowledge, skills and experience with colleagues to improve team capability and resilience.
- Collaborate effectively with team members and stakeholders to deliver collective outcomes.
- Contribute to maintaining a positive, inclusive and supportive team culture.
About You:
You may come from a security, technology, risk, governance, assurance, audit, operational or analytical background. Most importantly, you will be curious, collaborative and comfortable working across a variety of topics and activities.
You Will:
- Have experience of working within a security, technology, risk, governance or assurance environment.
- Be comfortable analysing information from multiple sources and forming evidence-based conclusions.
- Have strong analytical, problem-solving and investigative skills.
- Be able to review complex information and identify key risks, themes and opportunities for improvement.
- Have good written communication skills and be able to produce high-quality reports, assessments and briefing materials.
- Be confident engaging with stakeholders and explaining technical concepts to non-technical audiences.
- Have an interest in technology and cyber security, including modern cloud and digital services.
- Be adaptable and willing to contribute across a broad range of activities rather than specialising in a single area.
- Be methodical, inquisitive and willing to challenge constructively where necessary.
- Demonstrate attention to detail and appropriate discretion when handling sensitive or confidential information.
Behaviours
We'll assess you against these behaviours during the selection process:
- Managing a Quality Service
- Delivering at Pace
- Communicating and Influencing
- Making Effective Decisions
- Changing and Improving
Technical Skills
We may assess your current level of knowledge of cyber security and risk management during the selection process.
Cyber Security Risk and Assurance Practitioner (HEO)
The MoJ Information Security Team sits at the heart of the Ministry of Justice, enabling good security practices through the provision of security policies, guidance and education, by understanding cyber security risks from all parts of the Ministry of Justice and providing assurance to the departmental SIRO, the Permanent Secretary and other senior stakeholders that these risks are being effectively managed in the delivery of MoJ objectives.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
The role of the Cyber Security Risk and Assurance Practitioner is to support the central MoJ Information Security Team in carrying out cyber security assurance, highlighting non-compliance with required standards and raise and communicate cyber security risks arising from control gaps.
The team works across a diverse range of digital services, technologies and business functions to identify and understand cyber security risks and provide assurance that these risks are being managed appropriately in support of departmental objectives.
The role involves reviewing services and systems, analysing evidence, identifying risks and opportunities for improvement, and communicating findings to a wide range of stakeholders.
The Cyber Security Risk and Assurance Practitioner may also provide advice to others on good risk management practices to enable them to manage residual risk well, identify trends resulting from risk and assurance activities and use these to propose and deliver improvements to processes, policies and guidance, and enable senior team members to resolve tactical requests to the team.
All members of the team are expected to help develop the MoJ Security Function as a centre of excellence for the department and to contribute to building a brilliant and diverse team that is a welcoming place for all.
All members of the team are expected to contribute to developing the MoJ Security Function as a centre of excellence, helping to build a brilliant, diverse and inclusive team environment. The post holder will contribute across a variety of assurance, risk and governance activities, working collaboratively with colleagues to continuously improve security practices, processes and decision-making across the department.
Technical Skills
We may assess your current level of knowledge of cyber security and risk management during the selection process.
Person specification
Please Refer To The Job Description
Behaviours
We'll assess you against these behaviours during the selection process:
- Managing a Quality Service
- Delivering at Pace
- Communicating and Influencing
- Making Effective Decisions
- Changing and Improving
Benefits
Alongside your salary of £35,335, Ministry of Justice contributes £10,236 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).
- Access to learning and development
- A working environment that supports a range of flexible working options to enhance your work life balance
- A working culture which encourages inclusion and diversity
- A Civil Service pension with an employer contribution of 28.97%
- Annual Leave
- Public Holidays
- Season Ticket Advance
For more information about the recruitment process, benefits and allowances and answers to general queries, please click the below link which will direct you to our Candidate Information Page.
Link: https://justicejobs.tal.net/vx/candidate/cms/About%20the%20MOJ
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.
Selection process details
This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours and Experience.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location