Location
About the job
Job summary
Would you be interested in making a meaningful contribution to the UK’s national security, whilst enjoying an enviable work-life balance, 25 days holiday (rising to 30), all with the added benefits of a civil service pension scheme?
You’re home.
Whilst we sit in an established government department, the team structure and ethos is dynamic and agile, more akin to a modern tech start-up. We are pioneering new ways of delivering classified technology services across government, and we’re having fun doing it.
Job description
The post holder’s responsibilities will cover all appropriate security and information management areas (physical, personnel, information assurance, cyber and third-party suppliers); in particular, the safeguarding of the department’s assets in relation to confidentiality, integrity and availability of information. They will work with Rosa Security Group and wider RSO teams and work closely with the Security Assurance team to support them in security information matters.
The job involves providing good customer service, support and advice on departmental security. It requires effective decision making and implementing solutions to resolve problems. Identify and respond to emerging security issues and risk(s). Analyse, interpret and produce reports on security information matters. Contribute to the development of policies, procedures and an effective security culture.
Responsibilities
Reporting to the Senior Security Advisor (SSA), this role will:
- Act as the RSO’s focal point and facilitator for Information Security advice and expertise.
- Lead on the development and implementation of Information Security standards and policy
- Understand externally mandated standards (e.g. HMG SC, Sec-007 Cabinet Office minimum baseline security standard) and ensure these are translated into policy, communicated, and implemented as appropriate.
- Maintenance of the NIST 800-53 Framework.
- Engage and build relationships across RSO and other Government departments to identify opportunities for collaboration and sharing best practice.
- Continually explore and undertake personal and professional development opportunities
- Document issues and present formal reports to project teams and/or senior management.
- Manage improvements to security measures based on findings from audits or investigations.
- Ensure that all projects and tickets receive timely updates, and all requests are updated within the team’s tracking tools.
Person specification
Essential Skills
- Stakeholder management and engagement.
- The ability to work autonomously, showing judgement on when to progress opportunities and when to consult/escalate.
- Ability to work at pace in a fast-moving environment;
- Excellent communication skills;
- Good understanding of Microsoft Office 365
- Strong decision and justification skills;
Desirable Skills
- Experience working on NIST 800-53 framework
- Experience working on Information Security
- Experience working on national security issues
- Membership of a relevant Security Professional Association
Behaviours
We’ll assess you against these behaviours during the selection process:
- Delivering at Pace
- Making Effective Decisions
- Communicating and Influencing
Technical skills
We’ll assess you against these technical skills during the selection process:
- Threat Understanding (Working)
- Risk Understanding and Mitigation (Working)
- Protective Security (Working)
Benefits
-
We understand that people are at the heart of our success. We promote and encourage all our staff to follow continued professional development, offering our staff access to a range of learning and development opportunities.
- An environment with flexible working options
- A culture encouraging inclusion and diversity
- A Civil Service pension with an average employer contribution of 27%