About The Role

Role: Principal Cyber Risk Management and Assurance Advisor
Contract Length: 6 months
Location: Hybrid/London, Manchester or Bristol - onsite expectation is officially x 3 days per week, however, some flexibility could be offered on this.
IR35: Inside
Pay Rate to Intermediary: £750 per day
Security Clearance: SC requested

Spinwell is recruiting for a Principal Cyber Risk Management and Assurance Advisor for an excellent opportunity within the public sector.

 

RESPONSIBILITIES OF THE PRINCIPAL CYBER RISK MANAGEMENT AND ASSURANCE ADVISOR

  • Lead cyber and information security risk management, assurance, and architectural advisory for major applications and digital services during alpha, beta, and early live phases.
  • Deliver critical security assessments and IT Health Checks, providing expert assurance across portfolio projects, with a focus on SaaS tooling compliance against NCSC Cloud Security Principles.
  • Facilitate and oversee Security Working Groups throughout all key development and deployment stages, ensuring risks are tracked, logged, and reported to the Head of Cyber Risk and Assurance, with actionable recommendations provided.
  • Produce formal risk assessments and risk treatment plans (RTPs) for all digital services and associated tooling, ensuring robust protection in accordance with business risk appetite.
  • Develop, review, and advise on Secure by Design policies/practices, including safe use of AI, secure coding, and regulatory compliance frameworks (e.g., OWASP, DPIA, GovAssure).
  • Coordinate cross-platform activities and enable secure delivery of new services, including supporting incident management and continuous improvement of live service security practices.
  • Routinely provide monthly (and ad-hoc) risk briefings to senior leaders, evidencing assurance, identifying risks outside tolerance, mapping exposure, and recommending mitigations and controls.
  • Mentor and train digital service teams and wider Information Security staff, sharing best practices and building internal capability for risk assessment and management.
  • Support implementation and ongoing usage of risk management tooling, ensuring all details are uploaded promptly and appropriately, such as the SureCloud risk register.
  • Engage proactively with senior internal and external stakeholders, promoting security culture and enabling confident delivery aligned with organisational priorities.
  • Future line management activities as the team grows

SKILLS/EXPERIENCE OF THE PRINCIPAL CYBER RISK MANAGEMENT AND ASSURANCE ADVISOR

  • Demonstrable experience delivering high-quality, detailed cyber security risk assessments and assurance in large, fast moving, complex digital environments, ideally government or critical infrastructure.
  • In-depth understanding of cyber risk management, threat modelling, security architectural advice, and formal IT Health Checks, including experience with SaaS environments and cloud security principles.
  • Experience interpreting and applying relevant cyber security standards, regulatory frameworks, and secure by design principles within a multi-disciplinary digital team.
  • A self-starter, using your considerable experience and skills to work independently and with confidence
  • Track record of building cross-functional relationships and leading multi-platform security initiatives, with the ability to brief, influence, and advise senior stakeholders.
  • Strong written, verbal, and interpersonal communication skills, able to distil complex findings into actionable recommendations for non-technical and executive audiences.
  • Evidence of personal commitment to continuous learning and sharing of best practices, with experience mentoring, coaching, or enabling capability-building in others.
  • Ability to assess the implications and risks of emerging technologies (such as AI, SaaS, cloud services) and proactively recommend security interventions.
  • Knowledge of Civil Service values: respect, collaboration, inclusivity, and commitment to public service, with a strong focus on organisational culture.

If you are a Principal Cyber Risk Management and Assurance Advisor, apply now or send your CV to Spinwell!

 

We welcome all applications regardless of background, in line with our commitment to diversity, equality and inclusion.

Applying to this or any other vacancy advertised by Spinwell Ltd constitutes an agreement for Spinwell Ltd to hold your details for 24 months for the purpose of assessing suitability for the advertised position and to make you aware of any other positions deemed suitable of which You will make you aware by means of either email, text or phone. In line with GDPR regulations you are able to request your details be removed from the company data at any time by emailing us

Other jobs like this