×
Register Here to Apply for Jobs or Post Jobs. X

Head of Security Risk

Job in Cardiff, Cardiff City Area, CF10, Wales, UK
Listing for: Department for Work and Pensions (DWP)
Full Time position
Listed on 2026-04-17
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Salary/Wage Range or Industry Benchmark: 82026 GBP Yearly GBP 82026.00 YEAR
Job Description & How to Apply Below

Pay up to £82,026, plus 28.97% employer pension contributions, hybrid working, flexible hours, and great work life balance.

This is a rare opportunity to shape security risk at national scale, influencing decisions that directly protect millions of citizens and the UK’s most critical public services.

The Head of Security Risk leads DWP’s strategic security risk function, operating at enterprise scale across all security domains: cyber, personnel, physical and supply chain security.

In this role you will provide authoritative, organisation wide security risk insight to senior leaders, enabling them to make confident, well informed decisions that protect departmental objectives, services and UK citizens.

This is a role with national significance, given DWP’s scale: 96,000 staff, £250bn in annual payments, personal data on every living UK citizen, and a threat landscape spanning everything from frontline operational incidents, insiders, organised crime groups and state sponsored cyber actors. The Head of Security Risk shapes how DWP identifies, understands and responds to these risks, ensuring the department delivers services safely, securely and resiliently.

The Head of Security Risk leads a team of approximately 15 staff and is responsible for strengthening DWP’s security risk capability, embedding high‑quality analytical standards, modern methodologies and clear strategic reporting. It also provides expert security risk support to core business functions that do not have their own dedicated security risk capability.

Key responsibilities Strategic Leadership & Direction
  • Own and lead DWP’s enterprise level security risk function, setting direction, standards and methodology for how the department conducts security risk analysis.
  • Define, maintain and continually improve the security risk framework, including structured analytical techniques and consistent reporting approaches.
Production of Strategic Security Risk Assessments
  • Lead the creation and maintenance of DWP’s strategic security risk assessments, covering all security domains.
  • Produce risk insights for Director Generals, the Executive Team and the Departmental Audit & Risk Assurance Committee (DARAC).
  • Provide regular (monthly/quarterly) senior‑level briefings on cyber, personnel and supply chain security risks.
Influencing and Senior Stakeholder Engagement
  • Act as a trusted advisor to DG‑level decision‑makers, articulating complex technical risks in plain English, with clear implications for departmental objectives.
  • Provide actionable, board ready narratives, recommendations and insights.
Supporting Security Policy & Standards
  • Deliver bespoke risk assessments to inform security policy, standards and strategic direction for the department.
On‑Demand Risk Support Across DWP
  • Provide expert risk support to parts of the organisation without their own embedded capability.
Transforming and Professionalising the Function
  • Build a modern, credible risk profession aligned with cross‑government analytical standards and industry‑recognised frameworks
Cross‑organisation Leadership and Collaboration
  • Strengthen cross‑government collaboration on security risk, supporting initiatives such as the Government Cyber Action Plan and shared security risk models.
  • Collaborate with a range of DWP stakeholders, such as Digital Security, Commercial and Estates to collectively deliver against DWP’s Security Strategy for 2030
  • Shape assurance priorities based on risk findings, ensuring risk and assurance functions work closely together, sharing insight and driving continuous improvement.
What skills, knowledge and experience will you need?
  • Leadership of an enterprise‑level risk function — demonstrable experience directing strategic risk activity in a complex or regulated organisation, using risk insight to inform senior‑level decision‑making.
  • Strong analytical leadership — proven ability to lead analytical work, apply structured analytical techniques, and develop analytical capability within a team.
  • Broad security domain knowledge — credible understanding across physical, personnel, cyber and supply chain security, with the ability to represent cross‑domain risk professionally at senior level…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary