Menu

Head of Security Risk

Job details
Posting date: 06 March 2026
Salary: £75,026 to £80,267 per year
Additional salary information: This post currently attracts an additional Recruitment & Retention Allowance of £7,000 per annum. This is reviewed on an annual basis.
Hours: Full time
Closing date: 25 March 2026
Location: Sheffield
Company: Government Recruitment Service
Job type: Permanent
Job reference: 450345/8

Apply for this job

Summary

This is a rare opportunity to shape security risk at national scale, influencing decisions that directly protect millions of citizens and the UK’s most critical public services.

The Head of Security Risk leads DWP’s strategic security risk function, operating at Enterprise scale across all security domains: Information, Cyber, Personnel, Physical and Supply Chain Security. In this role you will provide authoritative, organisation‑wide security risk insight to senior leaders, enabling them to make confident, well‑informed decisions that protect delivery of departmental objectives, services and UK citizens.

This is a role with national significance, given DWP’s scale: circa 90,000 staff, £292bn in annual payments, personal data on every living UK citizen, and a threat landscape spanning everything from frontline operational incidents, insiders, organised crime groups and state‑sponsored cyber actors. The Head of Security Risk shapes how DWP identifies, understands and responds to these risks, protecting safe execution of the business strategy.

The Head of Security Risk leads a team of approximately 15 staff and is responsible for strengthening DWP’s security risk capability, embedding high‑quality analytical standards, modern methodologies and clear strategic reporting. It also provides expert security risk support to core business functions that do not have their own dedicated security risk capability.

The Head of Enterprise Security & Risk Management, under which this post sits and the current post holder will be delivering engagement sessions on Wednesday 11 March at 09:30 and Monday 16 March at 13:30 where you can find out more about this unique role and pose any questions you may have about it.

To book your place on an event please use either of the following links:

Head of Security Risk Engagement Session Tickets, Wed 11 Mar 2026 at 09:30 | Eventbrite

Head of Security Risk Engagement Session Tickets, Mon 16 Mar 2026 at 13:30 | Eventbrite

These sessions will not be recorded.

Strategic Leadership & Direction

  • Own and lead DWP’s Enterprise‑level Security Risk function, setting strategy direction, standards and methodology for how the department conducts security risk analysis.
  • Define, maintain and continually improve the security risk framework, including structured analytical techniques and consistent reporting approaches.

Production of Strategic Security Risk Assessments

  • Lead the creation and maintenance of DWP’s strategic security risk assessments, covering all security domains.
  • Produce risk insights for Director Generals, the Executive Team and the Departmental Audit & Risk Assurance Committee (DARAC).
  • Provide regular (monthly/quarterly) senior‑level briefings on Enterprise level risks.

Influencing and Senior Stakeholder Engagement

  • Act as a trusted advisor to Director General level decision‑makers, articulating complex technical risks in plain English, with clear implications for departmental objectives.
  • Provide actionable, board‑ready narratives, recommendations and insights.

Supporting Security Policy & Standards

  • Deliver bespoke risk assessments to inform security policy, standards and strategic direction for the department.

On‑Demand Risk Support Across DWP

  • Provide expert risk support to parts of the organisation without their own embedded capability.

Transforming and Professionalising the Function

  • Build a modern, credible risk profession aligned with cross‑government analytical standards and industry‑recognised frameworks.

Cross‑organisation Leadership and Collaboration

  • Strengthen cross‑government collaboration on security risk, supporting initiatives such as the Government Cyber Action Plan and shared security risk models.
  • Collaborate with a range of DWP stakeholders, such as Digital Security, Commercial and Estates to collectively deliver against DWP’s Security Strategy for 2030.
  • Shape assurance priorities based on risk findings, ensuring risk and assurance functions work closely together, sharing insight and driving continuous improvement.

Given the geographic spread of our team, DWP customers, cross-government stakeholders and industry suppliers, you'll need to be willing to travel to other DWP locations, with periodic overnight stays required.

Proud member of the Disability Confident employer scheme

Disability Confident
A Disability Confident employer will generally offer an interview to any applicant that declares they have a disability and meets the minimum criteria for the job as defined by the employer. It is important to note that in certain recruitment situations such as high-volume, seasonal and high-peak times, the employer may wish to limit the overall numbers of interviews offered to both disabled people and non-disabled people. For more details please go to Disability Confident.

Apply for this job