Job summary
- Main area
- Workplace, and Health & Safety - Protective Security
- Grade
- Civil Service: Senior Executive Officer (SEO)
- Contract
- Permanent: Loan, Secondment
- Hours
- Full time
- Part time
- Job share
- Flexible working
- Job ref
- 919-SH-633004162-EXT
- Employer
- UK Health Security Agency
- Employer type
- Public (Non NHS)
- Site
- Hybrid working at our London Canary Wharf HQ
- Town
- London Canary Wharf
- Salary
- £46,310 - £52,113 per annum, pro rata
- Salary period
- Yearly
- Closing
- 30/10/2026 23:59
Employer heading
Senior STRAPSO, Governance & Rosa Manager
Civil Service: Senior Executive Officer (SEO)
Job overview
We are currently seeking a Senior STRAPSO, Governance & Rosa Manager to manage the risks identified by both the Physical Security and Personal Security. They will manage the Security Risk Assurance Decision (SRAD) process and work with risk managers to implement contingencies to resolve, reduce or manage the identified risk.
This role will also require the post holder to be inducted onto the STRAP regime. STRAP is a regime that regulates access to sensitive intelligence material which requires more protective handling than is afforded by the standard arrangements for government assets. To be eligible to apply for STRAP, applicants must hold full UK Nationality or dual/multi-nationality, subject to one part being British and the other part/s to be reviewed on a case-by-case basis. Please note those whose right to work in the UK is subject to immigration controls are ineligible to apply for this role.
Clearance also typically requires a 10-year, verifiable UK-based footprint, where individuals have not been out of the UK 3 months or more in any 12-month period during that time. More information can be found about the vetting and clearance levels before completing your application.
Please note, this is a reserved post.
Main duties of the job
- Set and lead people strategy aligned to organisational objectives
- Actively manage UKHSA SRAD Process, identifying recording and mitigating security risk management proposals with senior risk owners across UKHSA
- Dynamically addressing new and emergent risks and advising on the escalation of the risk to the SRAD process
- Manage the SRAD data base ensuring risk owners update their risk interventions and ensuring that appropriate risks are raised at the corporate risk governance meeting according to threat harm risk likelihood RAG matrix status
- Draft and publish UKHSA policy and direction on Security Risk Management Framework
- Produce management information (KPQs and KPIs) and risk reporting for ExCo, the UKHSA Departmental Security Health Check (DSHC) and assist in the preparation of the UKHSA Annual Security Report
- Manage ROSA accounts across the UKHSA, validate security clearance and manages account suspensions and terminations
- Enrol users and reset PINs Issue and manage two-factor authentication keys appoints and train enrollers
- Review usage and coordinate budget with service lead, maintain partner key information sheet
- Deliver STRAPSO Security Policy Framework, liaise across government and with the central STRAP Authority
- Ensure STRAP information and assets are handled, stored, transmitted and destroyed according to SPF deliver briefings and inductions, liaison and compliance
This is not an exhaustive list.
Working for our organisation
We pride ourselves as being an employer of choice, where Everyone Matters promoting equality of opportunity to actively encourage applications from everyone, including groups currently underrepresented in our workforce. UKHSA ethos is to be an inclusive organisation for all our staff and stakeholders. To create, nurture and sustain an inclusive culture, where differences drive innovative solutions to meet the needs of our workforce and wider communities. We do this through celebrating and protecting differences by removing barriers and promoting equity and equality of opportunity for all. Please visit our careers site for more information https://gov.uk/ukhsa/careers
Detailed job description and main responsibilities
- Manage and administer applications for clearances and role changes liaising with line management regarding sensitive enquiries
- Provide secure administrative management and control of material and environments in order to protect highly sensitive material and maintain accreditation requirements
- Support good information management compliance in accordance with policies, procedures and government standards in relation to access to and use of classified material and classified IT
- Support the wider security function of protecting and securing personnel, physical and information assets
- Manage routine security and access control, secure environments in accordance with associated security standards engaging with the authorities
- Provide day-to-day advice and assistance to colleagues regarding sensitive material and IT systems
- Manage and administer applications for clearances and role changes liaising with line management regarding sensitive enquiries
- Manage/administer account applications and access to IT
- Maintain accurate records of inductions/de-inductions and IT accounts
- Conduct briefings and familiarisation sessions for IT systems to colleagues of all grades
- Manage access to secure meeting rooms and video conferencing facilities liaising with partners across government regarding clearances and related matters
The Senior STRAPSO, Governance & Rosa Manager will be required to identify interdependencies between physical and personnel security issues as well as those which cross over into information and cyber security functions working closely with both the UKHSA Cyber and inform risk managers.
They will report to the UKHSA Security Advisor in order to drive forward a coordinated process driven security risk management culture within the UKHSA. This will require engagement across the UKHSA and then out into DHSC. They will often talk to new people from across the UKHSA advising, guiding, and informing them of the UKHSA policies.
They will also be deputy Rosa manager. Rosa is the cross-government information management system for data assets protectively marked ‘secret’.
They will be required to liaise across government and with the central STRAP Authority.
They will advise on the UKHSA Security Risk Management Security policies and guidance across all the roles and responsibilities and interpret the CEO and Executive Committee risk tolerance and advise Risk Owners how to navigate and manage individual risk profiles according to this established risk tolerance on a case by case basis.
This role is part of the wider Government Security Profession.
The above is only an outline of the tasks, responsibilities and outcomes required of the role. You will carry out any other duties as may reasonably be required by your line manager.
The job description and person specification may be reviewed on an ongoing basis in accordance with the changing needs of the organisation.
Essential Criteria
- Policy development and delivery experience
- Experience of identifying, recording and mitigating security risks, and working with risk owners to implement risk management proposals
- Experience of managing security risk management processes, databases, records and reporting to support organisational governance and decision-making
- Experience of handling, storing, transmitting and protecting highly sensitive or classified information in accordance with security policies, procedures and government standards
- Experience of managing and administering security clearances, access controls, account applications or secure information systems
- Experience of providing advice, guidance, briefings or training to stakeholders on security policies, procedures and compliance requirements
Desirable Criteria
- Membership or associate of the Security Institute would be advantageous
- Knowledge of NPSA
- Security experience
Selection Process Details
This vacancy is using Success Profiles Success Profiles - GOV.UK and will assess your Behaviours and Experience.
Stage 1: Application & Sift
At sift stage you will be assessed against the 6 Essential Criteria listed in this job advert. You will be required to complete:
- An Application Form (‘Employer/Activity history’ section on the application)
- A 1500 word Supporting Statement - do not exceed 1500 words as we will not consider any words over this amount
This should outline how you consider your skills, experience and knowledge provide evidence of your suitability for the role, with reference to the 6 Essential Criteria listed in this advert.
You will receive a joint score for your application form and statement. The application form is the kind of information you would put into your CV – please note you will not be able to upload or email us your CV. Please complete the application form in as much detail as possible.
Longlisting
In the event of a large number of applications, we may longlist into 3 piles of:
- Meets all Essential Criteria
- Meets some Essential Criteria
- Meets no Essential Criteria
Only those that 'Meets all Essential Criteria' will progress to Shortlisting.
Shortlisting
In the event of a large number of applications, we may conduct an initial sift on the following Essential Criteria:
- Experience of identifying, recording and mitigating security risks, and working with risk owners to implement risk management proposals
- Experience of managing security risk management processes, databases, records and reporting to support organisational governance and decision-making
Desirable criteria may be used in the event of a large number of applications/successful candidates.
If you are successful at this stage, you will progress to interview and assessment. Feedback will not be provided at this stage.
Stage 2: Interview
You will be invited to a single remote interview. Interview location and date(s) to be confirmed.
The Behaviours being tested at interview stage be:
- Making Effective Decisions - Lead Behaviour
- Communicating and Influencing
- Managing a Quality Service
- Delivering at Pace
Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.
Additional Information
The Chief Operating Officer (COO) group, where this role sits, is undergoing organisational change over the next 12–18 months. While the process is still in the planning stage, some roles may be affected by future restructuring. We are committed to keeping candidates informed and will share updates as they become available.
Eligibility Criteria
Open to all external applicants (anyone) from outside the Civil Service as well as internal applicants.
Reserved Posts
Only UK nationals may be employed in reserved posts in the Civil Service. Reserved posts are generally those which, due to the sensitive nature of the work, require special allegiance to the Crown such that they can only be held by a UK national. Irish nationals and Commonwealth citizens are also eligible for employment in reserved posts if they were in the Civil Service at 31 May 1996 or before or were appointed from a recruitment scheme with a closing date for receipt of applications before 1 June 1996.
Sponsorship and Visas
Those whose right to work in the UK is subject to immigration controls are ineligible to apply for this role. Sponsorship cannot be provided.
Salary Information
Civil Service: Senior Executive Officer (SEO)
SEO Inner: £46,310 - £52,113 per annum, pro-rata
If you are successful at interview, and are moving from another government department, NHS, or Local Authority, the relevant starting salary principles for level transfers or promotions will apply. Otherwise, roles are offered at the pay scale minimum for the grade, but in exceptional circumstances there may be flexibility if you are able to demonstrate you are already in receipt of an existing, higher salary. Pay increases are through the relevant annual pay award for the role and terms.
Location
This role is being offered as hybrid working based at our core HQ in London Canary Wharf - 10 South Colonnade, London E14 4PU.
We offer great flexible working opportunities at UKHSA and operate using a hybrid working model where business needs allow. This provides us with greater flexibility about how and where we work, to get the best from our workforce. As a hybrid worker, you will be expected to spend a minimum of 60% of your contractual working hours (approximately 3 days a week pro rata, (averaged over a month) working at UKHSA's core London Canary Wharf HQ.
Our core HQ offices are modern and newly refurbished with excellent city centre transport links and benefit from co-location with other government departments such as the Department for Health and Social Care (DHSC).
Security Clearance Level Requirement
Successful candidates must pass an Enhanced disclosure and barring security check.
Successful candidates must meet the security requirements before they can be appointed. The level of security needed is Developed Vetting (DV).
For meaningful National Security Vetting checks to be carried out individuals need to have lived in the UK for a sufficient period of time. You should normally have been resident in the United Kingdom for the last 10 years as the role requires DV clearance. UK residency less than the outlined periods may not necessarily bar you from gaining national security vetting and applicants should contact the Resourcing Support Officer listed in this advert for further advice.
Person specification
Application Form & Supporting Statement
Essential criteria
- Application Form & Supporting Statement
Behaviours
Essential criteria
- Making Effective Decisions - Lead Behaviour
- Communicating and Influencing
- Managing a Quality Service
- Delivering at Pace
Documents to download
Further details / informal visits contact
- Name
- Sarah Handy
- Job title
- Resourcing Support Officer
- Email address
- [email protected]
List jobs with UK Health Security Agency in Administrative Services or all sectors






