Current jobs related to Senior Cyber Security Risk Manager – Information Security – salary 57,028 p.a. + digital allowance + benefits - Leeds, Leeds - Medicines and Healthcare products Regulatory Agency


  • Leeds, Leeds, United Kingdom Medicines and Healthcare products Regulatory Agency Full time

    DetailsReference number441097Salary£57,028A Civil Service Pension with an employer contribution of 28.97%GBPJob gradeGrade 7Contract typePermanentBusiness areaMHRA - Digital and Technology GroupType of roleDigitalInformation TechnologyWorking patternFlexible working, Full-timeNumber of jobs available1ContentsLocationAbout the jobBenefitsThings you need to...


  • Leeds, Leeds, United Kingdom Asda Full time

    Job TitleCyber Security Risk ManagerLocationAsda HouseEmployment TypeFull timeContract TypePermanentHours Per Week37.5SalaryCompetitive salary plus benefitsCategoryCyber SecurityClosing Date31 October 2025Asda's Cyber Security team are looking for a Risk Manager to join the Governance and Risk function of our dedicated team. If you are a Cyber Security Risk...


  • Leeds, Leeds, United Kingdom Asda Full time

    Job TitleCyber Security Risk ManagerLocationAsda HouseEmployment TypeFull timeContract TypePermanentHours Per Week37.5SalaryCompetitive salary plus benefitsCategoryCyber SecurityClosing Date31 October 2025Asda's Cyber Security team are looking for a Risk Manager to join the Governance and Risk function of our dedicated team. If you are a Cyber Security Risk...


  • Leeds, Leeds, United Kingdom 8d77a0ac-0c8d-4150-bab6-163c5bce645e Full time £71,835 per year

    Wellington Place, LeedsJob SummaryWe are currently looking for aLead Security Architectto join ourStrategy and ArchitectureFunctionwithin theDigital & Technologygroup.This is afull-timeopportunity, on apermanentbasis. The role will be based in 7-8 Wellington Place, Leeds, LS1 4AP. Our Canary Wharf and South Mimms sites are only available as contractual work...


  • Leeds, Leeds, United Kingdom 8d77a0ac-0c8d-4150-bab6-163c5bce645e Full time £73,000 per year

    DetailsReference number439681Salary£71,835A Civil Service Pension with an employer contribution of 28.97%GBPJob gradeGrade 6Contract typePermanentBusiness areaMHRA - Digital and Technology GroupType of roleInformation TechnologyWorking patternFull-timeNumber of jobs available1ContentsLocationAbout the jobBenefitsThings you need to knowApply and further...


  • Leeds, Leeds, United Kingdom PEXA Group Full time £90,000 - £110,000

    Hi, we're PEXAWe know you'll Google us before applying, so let's keep this brief. PEXA revolutionised the way that property is settled in Australia, turning a paper-based process into a digital one. Our solution is a world-first, with over 500 people across Australia and an expanding international team, we're helping 20,000+ families into their homes each...


  • Leeds, Leeds, United Kingdom PEXA UK Full time £60,000 - £100,000 per year

    Hi, we're PEXAWe know you'll Google us before applying, so let's keep this brief. PEXA revolutionised the way that property is settled in Australia, turning a paper-based process into a digital one. Our solution is a world-first, with over 500 people across Australia and an expanding international team, we're helping 20,000+ families into their homes each...


  • Leeds, Leeds, United Kingdom Lloyds Banking Group Full time £70,929 - £78,010 per year

    End DateWednesday 26 November 2025Salary Range£70,929 - £78,810We support flexible working – click here for more information on flexible working optionsFlexible Working OptionsHybrid Working, Job ShareJob Description SummaryCyber Security Consultant who has a broad knowledge of Cyber Security domains and controls working across a wide range of computing...


  • Leeds, Leeds, United Kingdom Medicines and Healthcare products Regulatory Agency Full time £42,000 - £60,000 per year

    Wellington Place, LeedsJob SummaryWe are currently looking for anInteraction Designerto join ourDigital & Service Designfunction within theDigital & Technologygroup.This is afull-timeopportunity, on apermanentbasis. The role will be based in 7-8 Wellington Place, Leeds, LS1 4AP. Our Canary Wharf and South Mimms sites are only available as contractual work...


  • Leeds, Leeds, United Kingdom Medicines and Healthcare products Regulatory Agency Full time £42,010 per year

    DetailsReference number437366Salary£42,410A Civil Service Pension with an employer contribution of 28.97%GBPJob gradeSenior Executive OfficerContract typePermanentBusiness areaMHRA - Digital and Technology GroupType of roleDigitalWorking patternFull-timeNumber of jobs available1ContentsLocationAbout the jobBenefitsThings you need to knowApply and further...

Senior Cyber Security Risk Manager – Information Security – salary 57,028 p.a. + digital allowance + benefits

2 weeks ago


Leeds, Leeds, United Kingdom Medicines and Healthcare products Regulatory Agency Full time £73,000 per year

7-8 Wellington Place, Leeds, LS1 4AP

Job Summary
We are currently looking for an
Senior Cyber Security Risk Manager – Information Security
to join our
Technology & Operations
function within the
Digital & Technology
group.

This is a
full-time
opportunity, on a
permanent
basis. The role will be based in 7-8 Wellington Place, Leeds, LS1 4AP. Our Canary Wharf and South Mimms sites are only available as contractual work locations to existing employees of the MHRA. Please be aware that this role can only be worked in the UK and not overseas.

We are currently implementing a flexible, hybrid way of working, with a minimum of 8 days per month working on site to enable the collaboration and contact with partners and stakeholders needed to deliver MHRA business. Attendance on site is driven by business needs so depending on the nature of the role, this can flex up to 12 days a month, with the remainder of time worked either remotely or in the office. Some roles will need to be on site more regularly.

A Digital Allowance of up to £21,948 per annum may be available for exceptional candidates based on our assessment of your skills and experience. This allowance is non-pensionable and may change on an annual basis.
Who are we?
The Medicines and Healthcare products Regulatory Agency enhance and improve the health of millions of people every day through the effective regulation of medicines and medical devices, underpinned by science and research.

The Digital and Technology Group (DTG) lies at the heart of the Agency and is responsible for delivering an optimised IT infrastructure and maximising the secure use of data to enable our scientists, inspectors, and the rest of the organisation to deliver world class services which can improve outcomes for patients and the public. The Group was essential in the race to approve COVID-19 vaccines in 2020 and in supporting the UK to set up its own medicines and devices approvals systems following our exit from the EU. The work we do matters

Job Description
Its centre of excellence is also responsible for delivering a broad portfolio of change initiatives, both to transform the Agency's legacy technologies and to deliver innovative new solutions, designed around our customers' needs. DTG works in a holistic way to combine digital and technology change, data and information management, project delivery, business process, product management and cultural change to maximise out impact and ensure sustainability.

We plan to be at the heart of one of the most digitally advanced medical regulators in the world and we need people who can help us deliver that ambition. DTG is a great place to build your career and we are committed to enabling our people to do the best work of their lives.

The Technology & Service Operations function is responsible for managing the existing IT infrastructure including both software and hardware, databases, and other technology platforms; leading the support and maintenance of applications; development and testing of new applications and platforms; and cyber and information security for the Agency.

What's the role?
This is an exciting role where you will drive the agency's information security agenda.

As a skilled and experienced Information Security Manager, you will play a central role in delivering the Agency's strategic objectives by embedding robust governance, risk, and compliance practices. You will lead and develop a high-performing team, building capability and maturity to ensure that information security remains integral to our digital, data, and information transformation.

You will work closely with the Head of Information and Cyber Security, the Senior Information Risk Owner (SIRO), Board members, and delivery teams to continuously improve the management of information risk. You will also represent the Agency in engagements with external stakeholders, including other government health bodies and IT and security delivery partners.

In this role, you will collaborate with the Cyber Defence Team and the Data Protection Team to make informed, risk-based decisions on both strategic and operational matters. You will be expected to quickly understand the Agency's culture and processes, enabling you to influence and embed a strong, pragmatic security and privacy culture across the organisation.

*Key Responsibilities:*

  • Governance & Leadership

  • Lead the development and implementation of the Agency's information security governance framework, ensuring alignment with strategic objectives and regulatory expectations.

  • Maintain and enforce security policies, standards, and guidelines that support consistent risk-based decision-making.
  • Promote a culture of accountability and security awareness across the Agency.

  • Risk Management & Assurance

  • Own and operate the information security risk management process, ensuring risks are identified, assessed, and treated proportionately.

  • Ensure security controls are selected and maintained based on business context and threat landscape, using recognised frameworks (e.g. ISO 27001, NCSC CAF).
  • Provide assurance to senior stakeholders through regular reporting and engagement with governance forums.
  • Understanding and implementation of Secure by Design.

  • Identity & Access Oversight

  • Govern identity lifecycle processes (e.g. joiners, movers, leavers) and ensure access rights are appropriate, risk-based, and regularly reviewed.

  • Oversee privileged access governance and support enforcement of least privilege principles.

  • Assurance & Control Effectiveness

  • Lead or support internal and third-party assurance activities, including audits and compliance reviews.

  • Validate the effectiveness of controls and ensure findings are communicated and addressed.

  • Horizon & Threat Awareness

  • Monitor emerging threats, vulnerabilities, and regulatory changes to inform the Agency's risk posture and control strategy.

  • Ensure lessons learned from incidents, audits, and assessments are captured and used to improve controls, processes, and response capabilities.
  • Provide input into security impact assessments and business impact assessments to ensure critical assets and processes are appropriately protected.

  • Stakeholder Engagement & Process Improvement

  • Act as a trusted advisor to business and technical stakeholders, translating risk into actionable insights.

  • Continuously improve GRC processes to support operational effectiveness and informed decision-making.

Its centre of excellence is also responsible for delivering a broad portfolio of change initiatives, both to transform the Agency's legacy technologies and to deliver innovative new solutions, designed around our customers' needs. DTG works in a holistic way to combine digital and technology change, data and information management, project delivery, business process, product management and cultural change to maximise out impact and ensure sustainability.

We plan to be at the heart of one of the most digitally advanced medical regulators in the world and we need people who can help us deliver that ambition. DTG is a great place to build your career and we are committed to enabling our people to do the best work of their lives.

The Technology & Service Operations function is responsible for managing the existing IT infrastructure including both software and hardware, databases, and other technology platforms; leading the support and maintenance of applications; development and testing of new applications and platforms; and cyber and information security for the Agency.

What's the role?
This is an exciting role where you will drive the agency's information security agenda.

As a skilled and experienced Information Security Manager, you will play a central role in delivering the Agency's strategic objectives by embedding robust governance, risk, and compliance practices. You will lead and develop a high-performing team, building capability and maturity to ensure that information security remains integral to our digital, data, and information transformation.

You will work closely with the Head of Information and Cyber Security, the Senior Information Risk Owner (SIRO), Board members, and delivery teams to continuously improve the management of information risk. You will also represent the Agency in engagements with external stakeholders, including other government health bodies and IT and security delivery partners.

In this role, you will collaborate with the Cyber Defence Team and the Data Protection Team to make informed, risk-based decisions on both strategic and operational matters. You will be expected to quickly understand the Agency's culture and processes, enabling you to influence and embed a strong, pragmatic security and privacy culture across the organisation.

*Key Responsibilities:*

  • Governance & Leadership

  • Lead the development and implementation of the Agency's information security governance framework, ensuring alignment with strategic objectives and regulatory expectations.

  • Maintain and enforce security policies, standards, and guidelines that support consistent risk-based decision-making.
  • Promote a culture of accountability and security awareness across the Agency.

  • Risk Management & Assurance

  • Own and operate the information security risk management process, ensuring risks are identified, assessed, and treated proportionately.

  • Ensure security controls are selected and maintained based on business context and threat landscape, using recognised frameworks (e.g. ISO 27001, NCSC CAF).
  • Provide assurance to senior stakeholders through regular reporting and engagement with governance forums.
  • Understanding and implementation of Secure by Design.

  • Identity & Access Oversight

  • Govern identity lifecycle processes (e.g. joiners, movers, leavers) and ensure access rights are appropriate, risk-based, and regularly reviewed.

  • Oversee privileged access governance and support enforcement of least privilege principles.

  • Assurance & Control Effectiveness

  • Lead or support internal and third-party assurance activities, including audits and compliance reviews.

  • Validate the effectiveness of controls and ensure findings are communicated and addressed.

  • Horizon & Threat Awareness

  • Monitor emerging threats, vulnerabilities, and regulatory changes to inform the Agency's risk posture and control strategy.

  • Ensure lessons learned from incidents, audits, and assessments are captured and used to improve controls, processes, and response capabilities.
  • Provide input into security impact assessments and business impact assessments to ensure critical assets and processes are appropriately protected.

  • Stakeholder Engagement & Process Improvement

  • Act as a trusted advisor to business and technical stakeholders, translating risk into actionable insights.

  • Continuously improve GRC processes to support operational effectiveness and informed decision-making.

Person specification

Who are we looking for?
Our Successful Candidates Will Have:

  • Certification and Professional Alignment - Holds a recognised professional security certification (e.g. CISM, CISSP, CRISC) and at least four years' experience in an information security or GRC role.
  • Demonstrates a strong understanding of security frameworks and standards, governance, risk management, and compliance practices, and a commitment to continuous professional development.
  • Technical Infrastructure - Ability to critically assess and challenge technical or infrastructure work from a risk perspective, with a solid understanding of key domains such as Cloud, Network and Applications, focusing on those most relevant to enterprise risk management.
  • Making the Process Work - Demonstrates a track record of designing, implementing, and improving security governance and risk processes that are both effective and pragmatic. Ensures that security controls and procedures support business operations without introducing unnecessary complexity or friction.

If you would like to find out more about this fantastic opportunity,
please click here for further details
Alongside your salary of £57,028, Medicines and Healthcare Products Regulatory Agency contributes £16,521 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.

  • Annual Leave: 25 days annual leave on entry, rising by one day for each completed year of service to a maximum of 30 days and pro-rata for part-time staff. PLUS 8 bank holidays
  • Privilege Leave: 1 day
  • Hours of Work: 37 hours (net) per week for full time staff in all geographical locations, including London and pro rata for part-time staff
  • Occupational Sick Pay (OSP): One month full pay/one month half pay on entry, rising by one month for each completed year of service to a maximum of five months full pay/five months half pay
  • Mobility: Mobility clause in contracts allowing staff to be mobile across the Civil Service
  • Civil Service Pension Scheme. Please see the link for further information For enquiries relating to the Civil Service Pension Schemes please contact MyCSP's Pension Service Centre directly on
  • Flexible working to ensure staff maintain a healthy work-life balance
  • Interest free season ticket loan or bike loan
  • Employee Assistance Services and access to the Civil Service Benevolent Fund
  • Eligibility to join the Civil Service Motoring Association (CSMA)
  • Variety of staff and Civil Service clubs
  • On-going learning and development

Selection process details

*The Selection Process:*
We use the Civil Service Success Profiles to assess our candidates, find out more here.

  • Application, which will include a CV, which should demonstrate how you meet the Experience and Technical Success Profile criteria. Please submit your application to Michael Page by visiting this website Senior Cyber Security Risk Manager - Information Security - JN , Michael Page
  • Presentation, to be prepared as part of your interview, with further information being supplied when you reach this stage
  • Interview, which can include questions based on the Behaviour, Experience, Technical and Strengths Success Profiles.

Closing date: 19 November 2025

Shortlisting date: 24 November 2025

Interview date: 04 & 05 December 2025

Candidates will be contacted within a week of the sift and the interviews completed to inform them of the outcome.

Candidates will be subject to UK immigration requirements as well as Civil Service nationality rules. Further information on whether you are able to apply is available here.

Successful candidates must pass a disclosure and barring security check as well as animal rights and pro-life activism checks. People working with government assets must complete basic personnel security standard checks.

Certain Roles Within The MHRA Will Require Post Holders To Have Vaccinations, And In Some Circumstances, Routine Health Surveillance. These Roles Include:

  • Laboratory-based roles working directly with known pathogens
  • Maintenance roles, particularly those required to work in laboratory settings
  • Roles that involve visiting other establishments where vaccination is required
  • Roles required to travel overseas where specific vaccination may be required.

Applicants who are successful at interview will be, as part of pre-employment screening subject to a check on the Internal Fraud Database (IFD). This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued. Any applicant's details held on the IFD will be refused employment. A candidate is not eligible to apply for a role within the Civil Service if the application is made within a 5 year period following a dismissal for carrying out internal fraud against government.

Any move to the MHRA from another employer will mean you can no longer access childcare vouchers. This includes moves between government departments. You may however be eligible for other government schemes, including Tax-Free Childcare. Determine your eligibility here.

Successful candidates may be subject to annual Occupational Health reviews dependent on role requirements. If you have any queries, please contact

In accordance with the Civil Service Commissioners' Recruitment Principles our recruitment and selection processes are underpinned by the requirement of selection for appointment on the basis of merit by a fair and open competition. If you feel your application has not been treated in accordance with the Recruitment Principles and you wish to make a complaint, you should firstly contact Florentina Oyelami, Head of Talent Acquisition –

If you are not satisfied with the response you receive, you can contact the Civil Service Commission at:

Civil Service Commission

Room G/8

1 Horse Guards Road

London

SW1A 2HQ

Feedback will only be provided if you attend an interview or assessment.

Security

Successful candidates must undergo a criminal record check.

People working with government assets must complete baseline personnel security standard (opens in new window) checks.

Successful candidates must undergo a criminal record check.

People working with government assets must complete baseline personnel security standard (opens in new window) checks.

Nationality requirements

This Job Is Broadly Open To The Following Groups:

  • UK nationals
  • nationals of the Republic of Ireland
  • nationals of Commonwealth countries who have the right to work in the UK
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
  • individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
  • Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service

Further information on nationality requirements (opens in a new window)

Working for the Civil Service

The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.

We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).

The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.

The Civil Service also offers a Redeployment Interview Scheme to civil servants who are at risk of redundancy, and who meet the minimum requirements for the advertised vacancy.

The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.

We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).

The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.

The Civil Service also offers a Redeployment Interview Scheme to civil servants who are at risk of redundancy, and who meet the minimum requirements for the advertised vacancy.

Diversity and Inclusion

The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).

Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.

Contact point for applicants

Job Contact :

  • Name : Ben Si
  • Email :

Recruitment team

  • Email :

Further information

In accordance with the Civil Service Commissioners' Recruitment Principles our recruitment and selection processes are underpinned by the requirement of selection for appointment on the basis of merit by a fair and open competition. If you feel your application has not been treated in accordance with the Recruitment Principles and you wish to make a complaint, you should contact the Resourcing Team at , in the first instance. If you are not satisfied with the response you receive you can contact the Civil Service Commission at: - - Civil Service Commission Room G/8 1 Horse Guards Road London SW1A 2HQ