Lead Security Risk Assurance Manager
Department for Work and Pensions
Job at a glance
Job summary Each year DWP is responsible for delivering approximately £280 billion in benefits and pensions, with over eight hundred physical locations and around 1000 commercial suppliers. DWP holds substantial personal data and manages several critical digital systems and key elements of the Government’s critical national infrastructure. Enterprise Security & Risk Management (ESRM) supports the secure delivery of DWP business, empowering the Department to operate within its security risk appetite, prioritise security improvement activities and maximise return on security investment.
As a senior leadership position in ESRM a Lead Security Risk Assurance Manager holds responsibility for producing high‑quality enterprise‑level security risk assessments or security risk assurance reports that can inform decision-making at the highest levels including Director General Finance, the Executive Team, and Departmental Audit & Risk Assurance Committee (DARAC). This includes the identification and monitoring of enterprise-level security risks, contextualising principal security threats to identify strategic risks to DWP and help inform departmental security policy.
Alternatively, a Lead Security Risk Assurance Manager will, ensure delivery of security assurance activities, undertake and oversee multiple activities to gather evidence on the security posture of DWP assets and services for example: interviews, sampling, design review, IT health checks and controls testing. ESRM analyse findings from these activities to provide confidence that DWP is sufficiently secure or identify areas for improvement.
A Lead Security Risk Assurance Manager is vital in understanding the big picture, synthesising information, and articulating how security risks could impact the department’s ability to operate, deliver services, maintain resilience, and protect staff, data, and assets. The position requires an individual who can understand complex and interconnected risks across a large organisation, influence senior stakeholders, challenge assumptions, and provide clear, evidence-based advice on whether controls are effective, thus, enabling informed business decisions.
Working across multiple functions and disciplines, the successful candidate will help DWP deliver its objectives securely, resiliently and effectively. ESRM provide confidence through evidence, placing a strong focus on continuous improvement, looking wider and deeper than just compliance. We highlight good practice and provide a professional, impartial view of the potential improvements to the department’s security position.
Job description Lead an area of Enterprise Security Risk or Security Assurance Develop, maintain and lead the production of timely Enterprise Security Risk or Assurance Products for senior leaders Oversee multi‑layered risk and assurance analysis covering threat scenarios, impacts, effectiveness of controls, and residual risk. Deliver Complex Security Risk Analysis Identify interdependencies and cumulative impacts across systems, services and business areas, translating localised risks into an enterprise-wide understanding of potential consequences Break down large, ambiguous or abstract security problems into structured analytical components Gather, evaluate and synthesise information from diverse sources, including digital risk data, system-level risk assessments, threat intelligence, estate vulnerabilities, resilience data and people safety insights Apply structured analytical methods to generate robust findings, uncertainty judgements, and evidence‑based conclusions.
Influence Decision Makers Understand complex and interconnected risks, provide balanced and pragmatic advice that supports senior leaders in making informed decisions, recognising both risk exposure and business objectives Produce clear, actionable insights to inform Director General level decision‑making, risk appetite setting, and departmental prioritisation Articulate business impacts: how