NHSCloses in 13 days

Cyber & Corporate Risk Officer

UK Health Security Agency

Birmingham, Leeds, Liverpool, London Canary Wharf, E14 4PU

Salary

£33,422 to £45,353

Contract

Permanent

Hours

Not specified

Closing date

14 September 2026

13 days left

Job description

We are seeking a Cyber & Corporate Risk Officer to join the UKHSA Cyber Security team. This is an exciting opportunity to become a central part of thi...

The Cyber & Corporate Risk Officer will coordinate and deliver security risk management activity within enabling a clear and realistic view of security risk across Cyber.

They will support the delivery of Second Line Cyber Risk Assurance (CRA) across the UKHSA, reporting to the SEO Senior Cyber Risk Officer. The role will require a level of independent oversight, and work stream responsibility for focussing on a particular business area to include IACS and Harlow, supporting the programmes in the creation of a single overview of the cyber risk helping to ensure that they are clearly understood and managed in line with UKHSA's risk appetite, government standards, and public sector assurance expectations, managing escalation in line with UKHSA processes.

As second line assurance, the role does not implement or operate cyber security controls, but helps to support UKHSA leadership by:

  • Providing confidence that cyber risks are identified, understood, and escalated appropriately
  • Strengthening transparency, governance, and assurance
  • Protecting the Agency's ability to deliver vital health security outcomes

This role offers experience of cyber risk in a complex field presenting a number of learning and developmental opportunities, all of which support UKHSA's critical health security mission.

This is not an exhaustive list.

The Cyber & Corporate Risk Officer must be comfortable to work flexibly and operate in a highly ambiguous environment while the Agency continues its transformation journey and defines its organisational culture. The ability to identify and understand challenges to find creative solutions will be critical as will strength in managing and building relationships across the organisation, undertaking effective collaboration at fast pace, both internally and externally to UKHSA. They will be expected to work on their own initiative without micro-management but know when to revert to seek a steer or decision.

This is a dynamic and challenging environment, and they will need to be confident in managing complexity, applying judgement, and making decisions whilst collaborating effectively with other members of the team and across the organisation.

This role will requires working with cyber team members of staff who are predominantly home-based workers.

Second Line Cyber Risk Support - Support the delivery of Second Line oversight and challenge of cyber and technology risks

  • Assist in reviewing First Line cyber risk assessments, control documentation, and mitigation plans
  • Ensure cyber risks are recorded clearly and consistently within UKHSA risk registers and tooling
  • Help differentiate between risk ownership (First Line) and risk assurance (Second Line) activities

Cyber Risk Framework & Standards - Support the maintenance of UKHSAs Cyber Risk Management Framework

  • Assist in assessing cyber risks against: - Government Security Policy Framework (SPF)
  • DSPT Cyber Assurance Framework
  • NCSC guidance
  • ISO 27001 / NIST aligned approaches
  • Promote a proportionate, risk-based approach to cyber security across the organisation

Governance & Reporting - Contribute to cyber risk reporting for senior management and assurance forums

  • Analyse cyber risk data, trends, and Key Risk Indicators (KRIs)
  • Help translate technical cyber security issues into clear risk narratives focused on business and health impact
  • Support preparation of papers and briefing materials for senior stakeholders

Change & Third Party Risk Assurance - Support cyber risk assurance activities related to: - Digital and data change initiatives

  • Cloud services and shared platforms
  • Third party and supplier arrangements
  • Assist with identifying emerging cyber risks early in the change lifecycle

Learning, Assurance & Continuous Improvement - Support post incident reviews and lessons learned activities from a risk perspective

  • Contribute to assurance exercises, internal reviews, and audit engagement
  • Build cyber risk knowledge and capability through on the job learning, mentoring, and formal development

The above is only an outline of the tasks, responsibilities and outcomes required of the role. You will carry out any other duties as may reasonably be required by your line manager.

The job description and person specification may be reviewed on an ongoing basis in accordance with the changing needs of the organisation.

Essential Criteria

  • Experience or strong interest in Cyber Risk Management, Information Security, Technology Risk, or GRC
  • Awareness of cyber security threats, vulnerabilities, and controls
  • Ability to analyse information and present risks clearly and concisely
  • Strong written and verbal communication skills
  • Willingness to provide constructive challenge while building effective working relationships

Desirable Criteria

  • Knowledge of: - Government Security Policy Framework
  • NCSC principles
  • Risk registers and assurance reporting
  • DSPT Cyber Assessment Framework
  • Industrial Automated Control Systems

Selection Process Details

This vacancy is using Success Profiles Success Profiles - GOV.UKand will assess your Behaviours, Experience and Technical Skills.

Stage 1: Application & Sift

At sift stage you will be assessed against the 5 Essential Criteria listed in this job advert. You will be required to complete:

  • An Application Form (Employer/Activity history section on the application)
  • A 1000 word Supporting Statement - do not exceed 1000 words as we will not consider any words over and above this number

This should outline how you consider your skills, experience and knowledge provide evidence of your suitability for the role, with reference to the 5 Essential Criteria listed in this advert.

You will receive a joint score for your application form and statement. The application form is the kind of information you would put into your CV please note you will not be able to upload or email us your CV. Please complete the application form in as much detail as possible.

Longlisting

In the event of a large number of applications, we may longlist into 3 piles of:

  • Meets all Essential Criteria
  • Meets some Essential Criteria
  • Meets no Essential Criteria

Only those that 'Meets all Essential Criteria' will progress to Shortlisting.

We pride ourselves as being an employer of choice, where Everyone Matters promoting equality of opportunity to actively encourage applications from everyone, including groups currently underrepresented in our workforce.

UKHSA ethos is to be an inclusive organisation for all our staff and stakeholders. To create, nurture and sustain an inclusive culture, where differences drive innovative solutions to meet the needs of our workforce and wider communities. We do this through celebrating and protecting differences by removing barriers and promoting equity and equality of opportunity for all.

Please visit our careers site for more information https://gov.uk/ukhsa/careers

Application Form & Supporting Statement

Essential

  • Application Form & Supporting Statement

Behaviours

Essential

  • Working Together - Lead Behaviour
  • Communication and Influencing
  • Making Effective Decisions
  • Developing Self and Others

Technical Skills

Essential

  • Presentation: You will be required to give a 10-minute technical presentation on a cyber risk management topic.

How to apply

Applications are handled entirely by the employer on the original advert. We do not collect CVs, supporting statements or application data.

Provenance

Source

NHS Jobs

First seen

1 September 2026

Last checked

1 September 2026

Salary, closing date and description are taken from the employer's advert. The original advert always takes precedence.

About the employer

UHS
UK Health Security Agency

NHS organisation

This listing was structured from NHS Jobs. Vacancy details and the application process remain the responsibility of the original source.

We would like to set one optional cookie that recognises your browser when you come back, so we can tell returning visitors from new ones. It stays off unless you say yes, and you can change your mind at any time. Cookies that keep you signed in are always on. Read our cookie policy