> Markdown version of [/jobs/ext/1868845-cyber-risk-manager-active-security-clearance-required](https://www.wearedevelopers.com/jobs/ext/1868845-cyber-risk-manager-active-security-clearance-required). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Risk Manager - Active Security Clearance Required - **Company:** Solirius Limited - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Agile Methodology, Amazon Web Services, Data Analysis, Microsoft Azure, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Information Systems Security Architecture Professional, Google Cloud, Cyber Threat Analysis, Tools for Reporting - **Published:** August 1, 2026 - **Apply:** https://www.careerboard.com/pt/en/find-jobs-in-United-Kingdom/-FB941419D7C5EDB3B8/ ## About the Role You are a motivated and adaptable professional with a strong analytical mindset and a passion for using technology to solve real-world problems. You enjoy working in collaborative, agile teams and take pride in delivering high-quality solutions that make a tangible impact. With strong communication skills and a consultative approach, you're comfortable engaging with clients, understanding their needs, and translating them into effective outcomes., * Demonstrable experience working in cyber security, technology risk, information security, or enterprise risk management roles. * Strong understanding of cyber risk management principles and methodologies. * Experience working with recognised frameworks and standards, including: * NIST Cybersecurity Framework (CSF) * NCSC Cyber Assessment Framework (CAF) * ISO/IEC 27001 and ISO/IEC 27005 * CIS Critical Security Controls * COBIT Experience analysing risk data and translating findings into meaningful recommendations and reporting outputs. Experience maintaining risk registers and tracking remediation activities. Strong stakeholder management skills, with experience engaging senior leaders, executive audiences, and external organisations. Ability to communicate technical risks effectively to both technical and non-technical stakeholders. Experience facilitating workshops and conducting interviews to gather evidence and validate risk assessments. Experience operating within Agile and multidisciplinary delivery environments. Knowledge of cloud security risks and controls across platforms such as Azure, AWS, or Google Cloud is beneficial. Experience within Local Government, the wider public sector, or regulated environments would be highly advantageous. Experience using data and reporting tools to develop metrics and management information would be beneficial. Desirable Certifications * CISSP (Certified Information Systems Security Professional) * CISM (Certified Information Security Manager) * CRISC (Certified in Risk and Information Systems Control) * CISA (Certified Information Systems Auditor) * ISO 27001 Lead Implementer or Lead Auditor * NCSC or other recognised cyber security and risk management certifications. ## Description We are looking for an experienced Cyber Risk Manager to join our growing cyber practice on a permanent basis, supporting major public sector clients, with a particular focus on Local Government. You will work closely with client stakeholders to identify, assess, manage, and communicate cyber risks across a variety of programmes and operational environments. Acting as a trusted advisor, you will help organisations establish effective cyber risk management practices, improve governance processes, and implement proportionate controls aligned to their risk appetite. You will play a key role in supporting the continued evolution of our Local Digital Cyber Risk capability, helping to mature reporting processes, strengthen risk insights, and enhance the use of the NCSC Cyber Assessment Framework (CAF) to support informed decision-making across the sector. You will be a fundamental member of the team, responsible for leading cyber risk activities, supporting and developing colleagues, fostering best practice, and ensuring our clients remain resilient against an evolving threat landscape. Requirements * Leading and facilitating cyber risk assessments across programmes, projects, and operational environments. * Supporting and maintaining the Cyber Risk reporting process for the Local Government sector, ensuring timely and accurate reporting of cyber risks and emerging trends. * Supporting the continued development and maturity of the Local Digital Cyber Risk function through the enhancement of metrics, reporting frameworks, and governance structures. * Analysing NCSC Cyber Assessment Framework (CAF) returns to identify themes, trends, and actionable risk insights that inform decision-making and prioritisation. * Planning and executing assessments to determine the cyber risk levels associated with strategic departmental goals, programmes, and initiatives. * Providing a cyber risk perspective on the development, refinement, and implementation of the CAF process to ensure it remains effective and aligned to organisational objectives. * Directly engaging with councils, when required, to validate risk profiles, understand local challenges, and provide pragmatic risk-based guidance. * Developing and maintaining cyber risk registers, ensuring risks are appropriately documented, prioritised, assigned, and managed through to resolution. * Assessing the effectiveness of security controls and recommending proportionate improvements to reduce risk exposure. * Producing high-quality risk reports, dashboards, and presentations for senior stakeholders and governance forums. * Providing risk-based guidance to technical and business teams throughout project lifecycles. * Conducting third-party and supplier cyber risk assessments where appropriate. * Supporting internal and external audits, assurance reviews, and regulatory activities. * Monitoring emerging threats and vulnerabilities to assess potential impacts to client environments. * Promoting cyber risk awareness and embedding a positive security culture across client organisations. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)