CS Interview Coach

Cyber Security Risk Manager Lead

Office for National Statistics

Department
Office for National Statistics
Location
Newport, Fareham
Openings
1 post
Grade
Grade 7
Salary
£60,007 to £66,701
Closing
8 days left
Profession
DDaT, Operational Delivery
Contract
Permanent
Security clearance
SC
Working pattern
Flexible working, Full-time, Job share, Part-time, Compressed hours
Apply on Civil Service Jobs

Job summary

The Office for National Statistics (ONS) is the UK’s largest producer of official statistics, covering a range of key economic, social and demographic topics. These include measuring changes in the value of the UK economy, estimating the size, geographic distribution and characteristics of the population, and providing indicators of price inflation, employment, earnings, crime and migration.

The last few years has seen an extensive overhaul of security and information management to meet the challenges of corporate and statistics transformation in technology, methods and practice, the Digital Economy Act and organisational risk appetite. The capability is evolving and expanding to address changes in threat and business direction. Security and Information Management Directorate (SaIM) operates five key services across ONS: security risk advice and management; knowledge and information management (KIM); physical security and business continuity; security compliance and audit; security operations including our Security Operations Centre.

What they’re looking for

  • Essential Criteria:
  • Extensive expertise in cloud, application, infrastructure and networking security controls, with strong proficiency across cyber, physical, procedural and technical (ICT) security domains, particularly in relation to secure data management.
  • Proven experience delivering high quality security advice and technical security solutions within a UK Government Department, supporting complex operational and digital environments.
  • Strong working knowledge of UK Government security frameworks and standards, including the Government Security Policy Framework (SPF), ISO 27001, and the Data Protection Act (DPA).
  • Commitment to professional development, ideally working towards relevant certifications such as CESG Certified Professional (CCP) at Senior Practitioner level and/or membership of professional bodies such as the British Computer Society (BCS).
  • A successful track record of leading and influencing the implementation of security frameworks (e.g., Secure-by-Design) in multi-disciplinary environments.

Behaviours you’ll be assessed on

This advert says the panel will score you against these behaviours at Grade 7 level. Each one links to worked examples.

Job description

The Cyber Security Risk Manager - Lead roles forms part of the Security Risk Advisory team within the Security and Information Management Division at the Office for National Statistics (ONS). The roles reports to the Cyber Security Risk Manager - Principal. The primary focus of these roles are to provide the Organisation with security advice and best practice to develop ‘Secure by Design’ protections for organisational assets and embed the ONS Security Framework - principles; policies; processes; threat model; security risk management into the ONS.

These roles will be dedicated to supporting all security assessment and assurance activities associated with the preparation and delivery of UKSA digital programmes, such as Census 2031. Key activities will involve security assessment, assurance, threat modeling and mitigation advice/guidance for all aspects of digital delivery, including in-house and procured/third-party elements. Key outcomes from the roles are the identification of security risk within the business context, the identification of appropriate mitigation approaches for business selection and the management of these options through to implementation within the live service. The security advice provided will be informed by threat, vulnerability and risk analysis for business and third parties. The focus, outcomes and responsibilities are aligned to the Government Security Profession framework of the Cyber Security Risk Manager – Lead.

Government Security Profession - Career framework

Responsibilities

  • Supporting the development of business-focused security solutions for digital products and business operations that cover data collection, storage and processing of Official - Sensitive information (deployed both internally and via external suppliers);
  • Identifying security threat and risk to the Organisation's digital products, data assets and business operations as part of the delivery lifecycle;
  • Lead the analysis and derivation of business-supporting security needs, undertake Cyber Security related risk assessments, conduct tailored threat assessment and other risk management activities, and ensure activities are consistent with applicable regulations and legislation;
  • Independently undertake risk management activities within a given area of practice or expertise, usually within established security and risk management governance structures;
  • Lead the analysis and derivation of business-supporting security needs, undertake Cyber Security related risk assessments, conduct tailored threat assessment and other risk management activities, and ensure activities are consistent with applicable regulations and legislation;
  • Consulting with the Organisation’s security stakeholders to ensure that the solutions deployed are secure and fit for purpose;
  • Liaising with the Organisation’s business, technology and security colleagues to ensure various business needs are understood and applied, including providing general security architecture, guidance and advice to the stakeholders;
  • Advising on opportunities for using secure and open-source products and any implications of such an approach.
  • Ensure that security policies and security controls remain appropriate and proportionate to the assessed risks, and are responsive and adaptable to the changing threat environment, business requirements and ONS policies;
  • Provide tailored advice to a range of stakeholders on how to remedy identified risks by proportionately applying security capabilities, using published guidance, standards, and drawing on a range of experts as well as personal expertise;
  • Provide expert security advice that highlights Cyber Security related risks, so risk or service owners can make well-informed and auditable decisions.

Nationality requirements

This job is broadly open to the following groups:

  • UK nationals
  • nationals of the Republic of Ireland
  • nationals of Commonwealth countries who have the right to work in the UK
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
  • individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
  • Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service

Further information on nationality requirements (opens in a new window)

Selection process

This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours, Experience and Technical skills.

Security Clearance

For ONS the requirement for SC clearance is to have been present in the UK for 3 consecutive years immediately prior to applying and the department will consider eligibility by exception on a case-by-case basis. You will be asked to provide information regarding your UK residency during your application, and failure to provide this will result in your application being rejected.

If you are unsure that you meet the eligibility above, please read the information available on Gov.uk on this link or contact the recruitment email on the advert before applying to discuss, as failure to meet the residency requirements will result in your security clearance application being rejected and any offer of employment being withdrawn.

At the point of SC application, you will need to provide or give access to the following evidence:

  • Departmental or company records (personnel files, staff reports, sick leave reports and security records)
  • UK criminal records covering both spent and unspent criminal records
  • Your credit and financial history with a credit reference agency
  • Security Services records

Please note we will reach out to you once the advert has closed to confirm eligibility for this role, this will be via an e-mail. Please check your junk e-mails for any correspondence.

Visa Sponsorship

ONS may be able to provide visa sponsorship where the role meets ONS sponsorship criteria and all relevant Home Office requirements. Applicants must hold, or be eligible to obtain, the right to work in the UK before employment commences.

Application Process

Number of Stages: 2 stage process

Stage 1: Application

Stage 2: Interview

Stage 1 – Application

The assessment process at the application stage will be based on your work history, CV, skills, experience, and personal statement. It is important that your application is tailored to highlight the skills, knowledge, and experience relevant to the role.

A personal statement is required at application stage, the maximum word count allowed is 1000 words, which should not be exceeded. You should provide evidence for each essential skill criterion listed in the person specification. As these criteria are scored, it is advisable to give clear examples for each one, including the impact of your actions, ideally utilising the STAR technique (Situation, Task, Action, Result).

Please note that Success Profiles Behaviour examples are not required at this stage of the application process.

In instances where a high number of applications are received, the sift pass mark may be adjusted, and candidates will be invited to interview based on merit order, i.e., those with the highest scores.

When a high volume of applications are received, the sift pass mark may be adjusted. Candidates will be invited to interview based on their merit order, with those achieving the highest scores being prioritised. Applicants who score below the adjusted pass mark but still pass will be placed on hold and may be invited to interview at a later date.

Stage 2 – Interview

If invited to interview, you will be assessed using techniques aligned with the Civil Service Success Profiles framework, covering all behaviours listed in the job advert and any required technical skills.

Interviews will be via Microsoft Teams.

A reserve list may be held for a period up to 12 months from which further appointments may be made.

Important Dates

  • Eligibility Security Clearance checks from 09/09 to 16/09. We will be sending you an e-mail with a form to fill out. Please check your junk e-mails for any correspondence.
  • Sift will be conducted from 17/09/2026
  • Interviews will be conducted from 05/10/2026

For the full terms and conditions of the post, please see attachment.

Please note that all campaigns may be subject to withdrawal at any stage if the internal resource position changes.

This role is eligible for the Government Digital and Data (GDD) Capability and Pay Framework. If you are successful at interview, your salary will be directly linked to your capability outcome, as determined by your performance in the Technical section of the interview.

  • Capability Outcome: Assessed based on scores achieved during the technical interview.
  • Salary Determination: Your starting salary will reflect the capability level assigned.
  • Feedback: Full feedback on your capability outcome will be provided at the point of offer.

All successful candidates are required to undertake an annual capability assessment as part of their ongoing employment terms. The outcome of this assessment directly influences individual pay levels:

  • Higher Capability Outcome: Results in an increase in pay.
  • Lower Capability Outcome: Results in a decrease in pay.

Completion of the assessment is mandatory. Failure to complete the annual capability assessment will result in the individual being transitioned to ONS pay terms and conditions, with a corresponding adjustment to their pay.

If you're already in a GDD Group 1 role and receiving GDD pay, and you make a lateral move (i.e. same grade, different role):

Initial Capability Assessment:

  • You’ll be assessed in your new role through the interview process.
  • If your proficiency level is lower than your current one, you retain your current level and pay for 6 months.

If your proficiency level is higher than your current one, you will move to that level of pay.

Development Plan:

  • During those 6 months, you’ll work with your line manager to create and follow a development plan to build the required skills.

Reassessment at 6 Months:

  • If you reach your previous proficiency level, you keep your current pay.
  • If your proficiency is still lower, your pay will decrease to match the new level.
  • If your proficiency level is higher, your pay will increase to match the new level.

Starting salary for roles within the Government Digital and Data (GDD) Capability and Pay Framework is determined solely by the capability outcome achieved during the recruitment process.

Please note:

  • Existing allowances (scarce skills) will not be taken into account when calculating starting salary.
  • This policy applies to all candidates, including existing Civil Servants and ONS colleagues transitioning to the GDD Capability and Pay Framework.

Feedback will only be provided if you attend an interview or assessment.

Practise before you apply

Civil Service panels score every answer against the Success Profiles behaviours at Grade 7 level. Practise STAR answers and get them marked against the same framework.

Start practising free

3 free questions · No card needed

Similar vacancies

Interview articles for Grade 7 roles

All articles

Browse more like this