Lead Cyber Security Risk Manager
Crown Prosecution Service
- Department
- Crown Prosecution Service
- Location
- This post can be based in any location within England and Wales where a Crown Prosecution Service office is located. You are expected to travel to Crown Prosecution Service locations as part of this role
- Openings
- 1 post
- Grade
- Grade 7
- Salary
- £58,330 to £73,520
- Closing
- 2 days left
- Profession
- DDaT
- Contract
- Permanent
- Security clearance
- DV
- Working pattern
- Flexible working, Full-time, Job share, Part-time
Job summary
This is a senior cyber security leadership role at the heart of protecting the Crown Prosecution Service’s people, information, systems and public trust. As Lead Cyber Security Risk Manager, you will play a critical role in strengthening the CPS’s cyber resilience, ensuring that security risks are understood, managed and embedded into the way the organisation delivers its services.
You will lead the development and implementation of effective cyber security risk management strategies, provide expert advice and assurance across major change and transformation programmes, and help ensure that security requirements are built in from the outset. This includes supporting strategic initiatives such as the replacement of the Case Management System, where cyber risk, compliance and resilience will be central to successful delivery.
Working closely with senior leaders, Information Asset Owners, digital teams, government partners and external bodies, you will provide constructive challenge, clear guidance and practical solutions that enable the CPS to make balanced, risk-based decisions. You will also play a key role in shaping cyber security policies, improving organisational awareness, and promoting a positive security culture across the CPS.
The role requires strong judgement, technical credibility and the ability to translate complex cyber risks into clear recommendations for senior stakeholders. You will need to be confident operating in a complex environment, responding decisively to incidents, and ensuring that controls, standards and assurance activities remain effective against an evolving threat landscape.
This is an excellent opportunity for an experienced cyber security risk professional who wants to lead, influence and make a tangible contribution to the security, resilience and integrity of a nationally important public service.
The Crown Prosecution Service is based in England and Wales. If you’re applying for this role and live in Scotland or Northern Ireland, you must let us know when accepting this offer as you need permission to work from your home address if hybrid working is part of your role. There’s no guarantee that we will grant this approval.
You must be aged 16 or over at the point of starting in this role. The expected start date is approximately 8–12 weeks after the application closing date. Candidates are expected to commence employment as soon as possible following the expiry of their notice period. Requests for significantly later start dates may not be accommodated.
As part of this role, you are expected to undertake direct line management responsibilities.
What they’re looking for
- To be eligible to apply, you need to:
- Have substantial experience leading cyber security risk, assurance or governance functions within a large, complex organisation, with responsibility for identifying, assessing and managing cyber security risk at an enterprise level.
- Demonstrate experience of providing independent cyber security assurance, constructive challenge and expert advice to senior leaders, governance boards and major business change or digital transformation programmes.
- Possess a strong understanding of cyber security frameworks, standards and regulatory requirements, including government security standards, NIST, ISO 27001, the Cyber Assessment Framework (CAF), and data protection legislation.
- Have experience of developing and implementing cyber security policies, control frameworks, assurance activities and risk management processes that support organisational compliance and resilience.
- Ideally hold, or be working towards, a recognised cyber security, risk management or information assurance qualification (such as CISSP, CISM, CRISC or equivalent) and have experience leading and influencing multidisciplinary teams and stakeholders.
Behaviours you’ll be assessed on
This advert says the panel will score you against these behaviours at Grade 7 level. Each one links to worked examples.
Job description
Your roles and responsibilities
- Provide independent cyber security assurance across CPS services, programmes and major transformation initiatives, ensuring risks are identified, controls are effective, and security requirements are embedded throughout the delivery lifecycle.
- Lead the assessment, reporting and oversight of cyber security risks across the organisation, providing expert advice and constructive challenge to enable informed risk-based decision making.
- Develop and maintain cyber security policies, standards and assurance frameworks, ensuring compliance with government security requirements, legislation and recognised industry standards.
- Provide assurance to senior leaders, governance boards and Information Asset Owners on the effectiveness of cyber security controls, resilience measures and risk mitigation activities.
- Lead the review of cyber security incidents, emerging threats and areas of non-compliance, ensuring lessons identified are translated into improvements that strengthen the CPS security posture.
A copy of the full job description is attached.
Nationality requirements
This job is broadly open to the following groups:
- UK nationals
- nationals of the Republic of Ireland
- nationals of Commonwealth countries who have the right to work in the UK
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
- Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Further information on nationality requirements (opens in a new window)
Selection process
This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours, Strengths and Experience.
Recruitment process
The recruitment process consists of an online application, interview and assessment. These are expected to take place on w/c 20 September 2026 at 9 Colmore Row, Birmingham B3 2BJ or 102 Petty France, London SW1H 9EA.
A member of our recruitment team will be in touch with guidance. If you have any queries about this, contact dimitra.siakavara@cps.gov.uk
You should keep this week free or notify us if you're not available. We'll make every effort to accommodate your date preferences but we can't guarantee it.
Assessment
We ask you to complete an assessment as part of the recruitment process for this role. We will provide details immediately before your interview.
Personal statement
We ask you to complete a personal statement of no more than 1,250 words. You need to address the core behaviours for this role, which are:
- Managing a Quality Service (Lead Behaviour)
You also need to demonstrate the following experience/technical skills required for this role:
- Have substantial experience leading cyber security risk, assurance or governance functions within a large, complex organisation, with responsibility for identifying, assessing and managing cyber security risk at an enterprise level.
- Demonstrate experience of providing independent cyber security assurance, constructive challenge and expert advice to senior leaders, governance boards and major business change or digital transformation programmes.
- Possess a strong understanding of cyber security frameworks, standards and regulatory requirements, including government security standards, NIST, ISO 27001, the Cyber Assessment Framework (CAF), and data protection legislation.
- Have experience of developing and implementing cyber security policies, control frameworks, assurance activities and risk management processes that support organisational compliance and resilience.
- Ideally hold, or be working towards, a recognised cyber security, risk management or information assurance qualification (such as CISSP, CISM, CRISC or equivalent) and have experience leading and influencing multidisciplinary teams and stakeholders.
- In addition, you need to demonstrate the Crown Prosecution Service or Civil Service values.
The panel has the right to assess the lead behaviour ‘Managing a Quality Service’ first. If the standard on this behaviour isn’t met, the other behaviours won’t be considered and your application won’t progress. The panel also has the right to raise the minimum standard pass mark. The panel may also refer to the lead behaviour at the interview stage to determine merit order.
Interview/Assessment
We use behaviours to help us understand your experience, to see if you're a good fit for the role. You are assessed against G7 in the Civil Service success profiles behaviours framework. We are assessing 4 behaviours at interview stage:
- Managing a Quality Service
- Making Effective Decisions
- Developing Self and Others
- Leadership
Essential Experience will be assessed through a Technical Assessment as part of the interview.
CV
You’re not required to upload your CV. However, when submitting your application there is a ‘CV section’. You are required to provide information about your employment and/or academic history for the past three years, skills, and qualification details. The CV section will be assessed.
It’s your responsibility to provide the specified information in the requested format to ensure that you're considered for the post.
If you're unable to cover three years through employment or academic history, you must provide a character reference for clearance purposes.
Strengths
Strengths are tested at interview stage - the strengths tested are not shared before the interview.
Other
This is a full-time post. We do consider requests for flexible, part-time working and job share, always considering the operational needs of the department.
Please note that the CPS is unable to offer visa sponsorship. Therefore, if you require visa sponsorship to work in the UK, you will not meet the eligibility criteria for this role.
Clearance
If successful, you are required to secure a Developed Vetting clearance, for which you must have a current valid UK address.
If successfully appointed, we ask you to complete a character enquiry form, nationality and immigration questionnaire, and national security vetting form.
The job you’re applying for is covered by Article 3(a) of the Rehabilitation of Offenders Act 1974 (Exceptions) Order 1975, consequently Section 4(2) of that Act doesn’t apply. You’re required to disclose all previous convictions and cautions including spent convictions. Failing to make a full declaration will result in withdrawing your offer of employment if our checks reveal convictions that haven’t been disclosed.
To be cleared to Developed Vetting clearance level, you have to be able to meet the residency requirement in the Cabinet Office guidance. For the Crown Prosecution Service, this is six years within the last ten years.
Reserve list
If you're recommended by the selection panel but not appointed to the current vacancy, you’re put on a reserve list for 12 months. You may be offered another Lead Cyber Security Risk Manager post in the CPS if a vacancy comes up during this period. We may also approach candidates on the waiting list to fill other roles that require similar knowledge and experience.
Fraud check
The Crown Prosecution Service provides a Fair Processing Notice to all new applicants after they’ve been successful at interview. These candidates are informed that, as one aspect of pre-employment screening, their personal details – name, National Insurance number and date of birth – are checked against the Internal Fraud Database. We won't employ anyone included on the database unless they can demonstrate exceptional circumstances.
The Strategic Resourcing team in the Crown Prosecution Service will, on behalf of the vacancy holder, inform applicants when they are refused employment because of their inclusion in the Internal Fraud Database.
Civil Service Commission
If you’re dissatisfied with the recruitment process and wish to make a complaint, please contact Strategic.Resourcing@cps.gov.uk with your concerns.
If you remain dissatisfied and wish to make a further complaint, please click on the following link to the Civil Service Commission complaints page Recruitment Complaints - Civil Service Commission
Civil Service Commission Recruitment Principles can be found at https://civilservicecommission.independent.gov.uk/recruitment/
Details of the Civil Service Nationality Rules are located at https://www.gov.uk/government/publications/nationality-rules
Candidates are subject to UK immigration requirements. For the most up-to-date information on the requirements of working in the UK, please go to the UK Visas and Immigration website at https://www.gov.uk/browse/visas-immigration/work-visas
Feedback will only be provided if you attend an interview or assessment.
Practise before you apply
Civil Service panels score every answer against the Success Profiles behaviours at Grade 7 level. Practise STAR answers and get them marked against the same framework.
3 free questions · No card needed
Similar vacancies
- Senior Full Stack Software Engineer · Cabinet Office · £59,207+
- G7 Senior Data Architect · UK Health Security Agency · £56,185+
- Senior Project Manager – Active Directory Service Consolidation · Department for Environment, Food and Rural Affairs · £56,375+
- Senior Project Manager – Privileged Access Management Remediation · Department for Environment, Food and Rural Affairs · £56,375+
- Head of IT Service Management (Service Owner) · HM Revenue and Customs · £58,541+