Rodeo
Get started

UK Health Security Agency

Senior STRAPSO, Governance & Rosa Manager

London
£46.3k – £52.2k/yr
Posted about 20 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Hybrid working based at our core HQ in London Canary Wharf

Job Summary

We are currently seeking a Senior STRAPSO, Governance & Rosa Manager to manage the risks identified by both the Physical Security and Personal Security. They will manage the Security Risk Assurance Decision (SRAD) process and work with risk managers to implement contingencies to resolve, reduce or manage the identified risk.

This role will also require the post holder to be inducted onto the STRAP regime. STRAP is a regime that regulates access to sensitive intelligence material which requires more protective handling than is afforded by the standard arrangements for government assets. To be eligible to apply for STRAP, applicants must hold full UK Nationality or dual/multi-nationality, subject to one part being British and the other part/s to be reviewed on a case-by-case basis. Please note those whose right to work in the UK is subject to immigration controls are ineligible to apply for this role.

Clearance also typically requires a 10-year, verifiable UK-based footprint, where individuals have not been out of the UK 3 months or more in any 12-month period during that time. More information can be found about the vetting and clearance levels before completing your application.

Please note, this is a reserved post.

Job Description

  • Set and lead people strategy aligned to organisational objectives
  • Actively manage UKHSA SRAD Process, identifying recording and mitigating security risk management proposals with senior risk owners across UKHSA
  • Dynamically addressing new and emergent risks and advising on the escalation of the risk to the SRAD process
  • Manage the SRAD data base ensuring risk owners update their risk interventions and ensuring that appropriate risks are raised at the corporate risk governance meeting according to threat harm risk likelihood RAG matrix status
  • Draft and publish UKHSA policy and direction on Security Risk Management Framework
  • Produce management information (KPQs and KPIs) and risk reporting for ExCo, the UKHSA Departmental Security Health Check (DSHC) and assist in the preparation of the UKHSA Annual Security Report
  • Manage ROSA accounts across the UKHSA, validate security clearance and manages account suspensions and terminations
  • Enrol users and reset PINs Issue and manage two-factor authentication keys appoints and train enrollers
  • Review usage and coordinate budget with service lead, maintain partner key information sheet
  • Deliver STRAPSO Security Policy Framework, liaise across government and with the central STRAP Authority
  • Ensure STRAP information and assets are handled, stored, transmitted and destroyed according to SPF deliver briefings and inductions, liaison and compliance
  • Manage and administer applications for clearances and role changes liaising with line management regarding sensitive enquiries
  • Provide secure administrative management and control of material and environments in order to protect highly sensitive material and maintain accreditation requirements
  • Support good information management compliance in accordance with policies, procedures and government standards in relation to access to and use of classified material and classified IT
  • Support the wider security function of protecting and securing personnel, physical and information assets
  • Manage routine security and access control, secure environments in accordance with associated security standards engaging with the authorities
  • Provide day-to-day advice and assistance to colleagues regarding sensitive material and IT systems
  • Manage and administer applications for clearances and role changes liaising with line management regarding sensitive enquiries
  • Manage/administer account applications and access to IT
  • Maintain accurate records of inductions/de-inductions and IT accounts
  • Conduct briefings and familiarisation sessions for IT systems to colleagues of all grades
  • Manage access to secure meeting rooms and video conferencing facilities liaising with partners across government regarding clearances and related matters

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

The Senior STRAPSO, Governance & Rosa Manager will be required to identify interdependencies between physical and personnel security issues as well as those which cross over into information and cyber security functions working closely with both the UKHSA Cyber and inform risk managers.

They will report to the UKHSA Security Advisor in order to drive forward a coordinated process driven security risk management culture within the UKHSA. This will require engagement across the UKHSA and then out into DHSC. They will often talk to new people from across the UKHSA advising, guiding, and informing them of the UKHSA policies.

They will also be deputy Rosa manager. Rosa is the cross-government information management system for data assets protectively marked ‘secret’.

They will be required to liaise across government and with the central STRAP Authority.

They will advise on the UKHSA Security Risk Management Security policies and guidance across all the roles and responsibilities and interpret the CEO and Executive Committee risk tolerance and advise Risk Owners how to navigate and manage individual risk profiles according to this established risk tolerance on a case by case basis.

This role is part of the wider Government Security Profession.

The above is only an outline of the tasks, responsibilities and outcomes required of the role. You will carry out any other duties as may reasonably be required by your line manager.

The job description and person specification may be reviewed on an ongoing basis in accordance with the changing needs of the organisation.

Person Specification

Essential Criteria

  • Policy development and delivery experience
  • Experience of identifying, recording and mitigating security risks, and working with risk owners to implement risk management proposals
  • Experience of managing security risk management processes, databases, records and reporting to support organisational governance and decision-making
  • Experience of handling, storing, transmitting and protecting highly sensitive or classified information in accordance with security policies, procedures and government standards
  • Experience of managing and administering security clearances, access controls, account applications or secure information systems
  • Experience of providing advice, guidance, briefings or training to stakeholders on security policies, procedures and compliance requirements

Desirable Criteria

  • Membership or associate of the Security Institute would be advantageous
  • Knowledge of NPSA
  • Security experience

Benefits

Alongside your salary of £46,310, UK Health Security Agency contributes £13,416 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).

  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • A Civil Service pension with an employer contribution of 28.97%

We pride ourselves as being an employer of choice, where Everyone Matters promoting equality of opportunity to actively encourage applications from everyone, including groups currently underrepresented in our workforce.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

UKHSA ethos is to be an inclusive organisation for all our staff and stakeholders. To create, nurture and sustain an inclusive culture, where differences drive innovative solutions to meet the needs of our workforce and wider communities. We do this through celebrating and protecting differences by removing barriers and promoting equity and equality of opportunity for all.

Please visit our careers site for more information: Civil Service job search - Civil Service Jobs - GOV.UK

Artificial Intelligence

Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.

Selection Process Details

This vacancy is using Success Profiles Success Profiles - GOV.UK and will assess your Behaviours and Experience.

Stage 1: Application & Sift

Required

At sift stage you will be assessed against the 6 Essential Criteria listed in this job advert. You will be required to complete:

  • An Application Form (‘Employer/Activity history’ section on the application)
  • A 1500 word Supporting Statement - do not exceed 1500 words as we will not consider any words over this amount

This should outline how you consider your skills, experience and knowledge provide evidence of your suitability for the role, with reference to the 6 Essential Criteria listed in this advert.

You will receive a joint score for your application form and statement. The application form is the kind of information you would put into your CV – please note you will not be able to upload or email us your CV. Please complete the application form in as much detail as possible.

Longlisting

In the event of a large number of applications, we may longlist into 3 piles of:

  • Meets all Essential Criteria
  • Meets some Essential Criteria
  • Meets no Essential Criteria

Only those that 'Meets all Essential Criteria' will progress to Shortlisting.

Shortlisting

In the event of a large number of applications, we may conduct an initial sift on the following Essential Criteria:

  • Experience of identifying, recording and mitigating security risks, and working with risk owners to implement risk management proposals
  • Experience of managing security risk management processes, databases, records and reporting to support organisational governance and decision-making

Desirable criteria may be used in the event of a large number of applications/successful candidates.

If you are successful at this stage, you will progress to interview and assessment. Feedback will not be provided at this stage.

Stage 2: Interview

You will be invited to a single remote interview. Interview location and date(s) to be confirmed.

The Behaviours Being Tested At Interview Stage Be

  • Making Effective Decisions - Lead Behaviour
  • Communicating and Influencing
  • Managing a Quality Service
  • Delivering at Pace

Once this job has closed, the job advert will no longer be available

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

London, England, United Kingdom

Sign up to applySee more jobs like this