About the job
Job summary
This vacancy is open to employees who already hold the substantive grade for the post and to those on promotion who were appointed to the Civil Service on merit following a fair and open competition; or were appointed to a permanent Civil Service post through an exception in the Civil Service Commissioners’ rules.
This vacancy is open to Department for Education employees only, as a lateral move and on promotion.
These are exciting times at the Department for Education (DfE).
Throughout 2023, we’ll continue to build services for all our users – children, adults, and those in social care.
Our diverse and inclusive culture reflects the society we live in, helping us to achieve better outcomes for all.
We work in multi-disciplinary teams using Agile methods to innovate and radically improve services that:
- Raise standards of education.
- Provide the best start in life for children.
- Drive economic growth.
- Support disadvantaged and vulnerable children and young people.
You can read more about our strategy on the DfE digital and technology strategy blog, by visiting our Linkedin page or by following us on Twitter @DfE_DigitalTech.
Job description
This is a great opportunity if you want a challenge at a National level. Joining CIS means you will help to safeguard children and ensure their education and care is delivered effectively by building ways of working and systems that adapt to evolutions in technology, methodology and threat.
Person specification
We are looking for a Supply Chain Security Officer (SCSOs) with the skills and experience to work as a member of a small team developing a supply chain security assurance function as well as identifying, tracking and mitigating supplier-related security risks.
The National Cyber Security Centre says:
“A series of high profile, very damaging attacks on companies has demonstrated that attackers have both the intent and ability to exploit vulnerabilities in supply chain security. This trend is real and growing. So, the need to act is clear”.
You will be involved with defining security requirements that suppliers need to meet, validating supplier assessments, and developing/delivering assurance processes that protect the DfE information and services entrusted to our suppliers.
You will be a member of a team managing the day-to-day security risk of the supply chain through all stages of the DfE supplier lifecycle: from supplier selection and on-boarding, ongoing supplier assessments, supplier issue management and status reporting, through to end of contract.
Successful candidates must be willing to undertake National Security Vetting SC clearance prior to taking up duty. Travel to all DfE sites and, potentially, supplier sites will be required.
Previous experience in Government is not required, but you will be expected to quickly get up to speed with the Department’s existing culture and processes – not least so you are in a strong position to shape and develop that culture around the delivery of digital services.
As a member of the team it will be your responsibility to:
- Ensure that suppliers effectively risk-manage departmental information. You will be involved in the design and operation of our overarching assurance framework and processes towards supply chain security, which will:
– focus attention and resources onto the highest impact suppliers/contracts.
– improve supplier compliance with recognised security standards and best practice.
– identify potential information risks that can arise from contracting with a specific supplier, so that proportionate and appropriate arrangements are put in place.
- Conduct supplier security assessments (via remote questionnaire or on-site visits).
- Advise business areas to include proportionate and appropriate security requirements and due diligence within supplier bid / procurement processes.
- Set up and operate mechanisms to monitor the effectiveness of the supplier security assurance framework, adjusting these as necessary.
- Produce regular Management Information/reporting.
- Maintain and develop the department’s standard security requirements for contracts, ITTs and RFQs.
- Establish and maintain excellent relationships with internal and external partners to influence their activities and promote and enhance supplier security assurance.
Essential Criteria
It is essential that you have:
- A clear understanding of information security and risk management and the ability to assess business context and apply it to security assurance.
- Experience of undertaking technical and information risk assessments.
- Experience of analysing disparate sources of security information quickly to provide sound advice and recommendations on requirements to stakeholders at all levels.
- Excellent written and verbal communication skills to be able to influence a range of stakeholders at different levels and the ability to build strong working relationships with people both internally and externally.
- Effective decision making, using evidence, available data and personal knowledge to provide clear, accurate and professional decisions.
- A broad knowledge of technologies, including common vulnerabilities and exploits with a good knowledge of security controls.
Desirable Criteria
It is desirable that you have:
Familiarity with the HMG/NCSC suite of security policy, guidance and standards and experience in using good practice standards such as ISO 27001.
- Collaboration and partnering skills and experience of working with legal and commercial teams to deliver security outcomes (e.g. through contract requirements).
- Strong security and technical background along with relevant formal qualifications such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM).
Desirable criteria will only be assessed in the event of a tie break situation to make an informed decision.
Technical skills
We’ll assess you against these technical skills during the selection process:
- SFIA Information Security (SCTY) – Responsibility Level 6 (see https://sfia-online.org/en/sfia-8/skills/information-security)
- SFIA Information Assurance (INAS) – Responsibility Level 6 (see https://sfia-online.org/en/sfia-8/skills/information-assurance)