Deputy Director of Enterprise Security & Risk Management
Department for Work and Pensions
- Department
- Department for Work and Pensions
- Location
- London
- Openings
- 1 post
- Grade
- SCS
- Salary
- £86,000 to £104,000
- Closing
- Closes today
- Profession
- Finance, Operational Delivery
- Contract
- Permanent
- Security clearance
- DV
- Working pattern
- Flexible working, Full-time, Job share
Job summary
Shape how one of the UK's largest organisations understands and responds to security risk.
This is a unique opportunity for an experienced governance, risk and assurance leader to shape how DWP understands, manages and acts on security risk. We are looking for someone who can bring clarity, pace and innovation to enterprise security risk management; who is confident working with complex evidence, assurance and threat information; and who can translate that insight into decisions that influence senior leaders across the whole organisation. The function is already mature and well-respected; you will have the opportunity to build and shape the credibility of the function across the Department, Government and the wider industry.
You will be a natural relationship builder, comfortable operating in a large, complex delivery organisation in either the public or private sector. You will need to inspire confidence with Ministers, the Permanent Secretary, the Departmental Audit, Risk and Assurance Committee, senior colleagues and your own teams through the quality of your judgement, the strength of your evidence, and your ability to help the organisation act on the risks that matter most. This is a role for someone who cares deeply about impact: not simply reporting risk and assurance, but changing behaviour, improving resilience and enabling better outcomes for millions of citizens.
We are looking for an inclusive, credible and ambitious senior leader to support me in leading the teams that provide proportionate, well-informed security and risk advice to the Department and its senior leaders. Values and making Security & Data Protection Directorate within DWP a brilliant place to work will be important to you. You’ll thrive on delivering outcomes and making wider contributions to Government Security and the Civil Service.
To learn more about this opportunity, hear directly from Mike Fell, Chief Security Officer and vacancy holder.
For more information about DWP and this role, please see the Candidate Pack attached.
Hear more about DWP
What they’re looking for
- The successful candidate must be able to demonstrate their knowledge, experience and skills against the following essential criteria:
- Proven senior security leadership experience, with a track record of leading and inspiring large, geographically dispersed teams through an engaging, authentic and adaptable leadership style. The successful candidate will demonstrate exceptional interpersonal and influencing skills, with the credibility to build trusted relationships at all levels of the organisation. They will possess high levels of emotional intelligence, sound judgement, executive presence, diplomacy and adaptability.
- Security Governance, Risk & Compliance (GRC) expertise – recognised expertise in security GRC, with experience establishing and leading enterprise-wide, cross-domain security governance, risk management and compliance frameworks within complex organisations. This will include deep knowledge of relevant regulations, frameworks and standards, together with experience of managing risk across both legacy and modern technology environments. This expertise should be evidenced through relevant professional qualifications and memberships (e.g. CISM, CISA, CISSP, CRISC, GRC(A), Chartered Security/Cyber Profession status).
- Excellent communication and stakeholder management skills, with the ability to influence senior leaders and communicate complex security and risk issues clearly to both technical and non-technical audiences.
- Experience leading security assurance across complex supply chains and outsourced service models, ensuring effective governance, risk management and resilience across third-party environments.
-
-
-
Behaviours you’ll be assessed on
This advert says the panel will score you against these behaviours at SCS level. Each one links to worked examples.
Job description
As Deputy Director of Enterprise Security & Risk Management, the accountabilities of the postholder include:
- Enterprise Risk Management - Lead the organisation’s security risk function, ensuring enterprise-level security risks are identified, assessed, prioritised and effectively managed in alignment with the organisation's risk appetite or agreed risk tolerance.
- Security Oversight – Develop and deliver the department’s enterprise security governance model and associated boards, ensuring alignment with corporate strategy, governance, regulatory requirements and risk appetite.
- Governance, Risk & Compliance - Lead Governance Risk & Compliance (GRC) activities, ensuring it is aligned, proportionate, transparent, compliant and business-centric. Provide programme and service-specific risk advice aligned to policy and risk appetite. Work closely with Security Policy & Awareness teams to deliver joined up security.
- Third‑Party Security Assurance - Responsible for the organisation’s multi-tiered supplier assurance programme, ensuring all third‑party security risks are assessed, monitored and actively managed throughout the contract lifecycle in a proportionate, risk-based manner.
- IT Security Assurance - Deliver a holistic, balanced programme of independent assurance over IT security architecture and associated controls providing confidence in technology‑driven risk including mandatory external and internal assurance and compliance activity.
- Physical Security Assurance - Responsible for evaluating, testing and verifying the organisation’s physical security measures across circa 850 locations ensuring site- and enterprise-level resilience measures are robust, risk-aligned and compliant with external requirements.
- Regulatory & Audit Engagement - Acts as the primary interface with internal audit, external auditors, and wider government bodies, ensuring clear evidence of security risk management and control effectiveness.
- Leadership of a Dispersed Workforce - Lead a team of 90 security, risk and assurance professionals across multiple UK locations, building a unified culture, clear accountability and high performing team.
- Strategic Advisor - Advises the Chief Security Officer, Executive Team and other boards on systemic risks and strategic investment priorities to manage those risks.
- Management – Accountable for the efficient running of the team, including a multi-million-pound budget, accurate forecasting, and HR, finance and commercial compliance.
Nationality requirements
This job is broadly open to the following groups:
- UK nationals
- nationals of the Republic of Ireland
- nationals of Commonwealth countries who have the right to work in the UK
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
- Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Further information on nationality requirements (opens in a new window)
Selection process
This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours.
Application Process
To apply for this post, you will need to complete the online application via Saxton Bampfylde process outlined below no later than Monday the 31st of August at 23:55:
- A CV setting out your career history, with key responsibilities and achievements. Please ensure you have provided reasons for any gaps within the last two years;
- A personal statement (maximum 1250 words), explaining how you consider your personal skills, qualities, and experience provide evidence of your suitability for the role, with particular reference to the essential criteria in the person specification.
Failure to submit both documents will mean the panel has only limited information on which to assess your application against the criteria in the person specification.
Longlist
Depending on the volume of applications received, a longlisting process may be undertaken. As part of this process, candidates will be interviewed by Corrie Cowlard or Jonathan Morgan, Consultants at Saxton Bampfylde, the executive search firm appointed to manage this recruitment on behalf of DWP. These discussions are intended to explore candidates' experience and motivation in greater depth and do not form a pass/fail assessment. Instead, they provide additional evidence to support the panel's overall evaluation when determining which candidates best meet the requirements of the role and should be invited to the next stage of the process.
Shortlist
A panel, including the hiring manager, will assess applications against the person specification and shortlist those demonstrating the strongest evidence of suitability for the role. Failure to address any or all of these may affect your application.
The timeline stated in the Candidate Pack attached indicates the date by which a decision is expected to be made, and all shortlisted candidates will be advised of the outcome as soon as possible thereafter.
Assessment
If you are shortlisted, you will be asked to take part in a Staff Engagement Exercise on the 30/09/2026, via MS Teams, in advance of the interview. This assessment will not result in a pass or fail decision. Rather, it is designed to support the panel’s decision making and highlight areas for the panel to explore further at interview.
Shortlisted candidates may have the opportunity to speak to Mike Fell, prior to the final interview. This is an informal discussion to allow candidates to learn more
about the role and is not part of the assessment process.
Interview
Shortlisted candidates will be invited to attend a panel interview to discuss your previous experience and professional competence in relation to the criteria set out in the person specification. You will be asked to prepare a 5-minute presentation. Full details will be provided prior to the interview.
Your interview will take place face to face on Tuesday 13 October 2026 at Caxton House, London. Further details will be confirmed nearer the time. The interview panel will be chaired by Mike Fell, who will be supported by additional panel members. The final panel interview will be a blended interview, covering Behaviours, Technical skills and Experience. A blended interview aims to be more of a conversation exploring the candidate’s capability for the role.
Offer and Feedback
Regardless of the outcome, we will notify all candidates as soon as possible. We will offer the opportunity to discuss feedback for all candidates who reached interview.
A reserve list will be held for up to 12 months, which we may use to fill future similar vacancies for candidates who are considered appointable following interview.
Feedback will only be provided if you attend an interview or assessment.
Practise before you apply
Civil Service panels score every answer against the Success Profiles behaviours at SCS level. Practise STAR answers and get them marked against the same framework.
3 free questions · No card needed
Similar vacancies
- Chief Security Officer · HM Revenue and Customs · £150,000+
- Deputy Director - Client Services Delivery · Social Security Scotland · £93,667+
- Deputy Director International Strategy & Capabilities · National Crime Agency · £86,000+
- Head of Finance · Ministry of Defence · £90,000
- Deputy Director, Head of AI Assurance · HM Revenue and Customs · £86,000+