Location
About the job
Job summary
Are you ready to work in one of the most interesting cyber security environments and share your experience to support national security?
Cyber security plays an integral role in protecting the UK against external and internal threats, acting as a deterrence to ensure that our Armed Forces have the strong cyber defences they need.
The Cyber Assessment and Advisory Service (CySAAS) provides assurance, support and advice to teams across defence. It consists of sub teams which assess specialist ICT, communication, and weapons systems.
The team is within the Cyber Defence and Risk (CyDR) organisation which sits at the forefront of Cyber Security and Information Technology within Defence. It is responsible for enabling Defence, through the provision of specialist assurance and cyber security services, across UK Defence including industry partners, other Government Departments and our international allies.
CyDR sits within Defence Digital who provide digital and technology services to our Armed Forces. Defence Digital operates at scale, with an annual budget in excess of £2Bn and a diverse team of 2,500 colleagues, aiming to make our Armed Forces some of the most technologically advanced in the world.
With a fantastic growing team of military and civilian staff operating across the UK it is a great time to be a cyber security professional in the Ministry of Defence. If you can see yourself contributing to the world of CySAAS the next chapter of your career may be with us!
This position is advertised at 37 hours per week.
Job description
As a Cyber Security Risk Assessor within the CySAAS team, you will provide timely, impartial and consistent assessment and advisory services across the department and our industry partners. You will also lead a small team providing assessment and advisory services.
Your knowledge and experience will provide the expertise to ensure an accurate understanding of through-life cyber security risks and to assist in making informed business decisions. You will work with projects that involve complex technical and security challenges, which may include highly sensitive networks, cryptography and next-generation platforms. Along the way, you will strengthen links with other cyber security bodies and business functions, including business delivery partners, who provide project-based assurance activities.
Thought leadership will be a key aspect of the role and you’ll need to demonstrate a talent for solving complex problems through innovation. You’ll have the ability to advise on complex risk balance decisions and explaining cyber security policy, governance and technology to non-experts. With you on board, we will develop a culture across UK Defence which values and protects data.
In return, you will benefit from excellent learning and development opportunities tailored to your role and beyond. Whilst in post, you’ll be able to gain industry recognised qualifications, such as CISSP or CRISC and more and we’ll support you throughout the process. You’ll also be able to take advantage of our excellent benefits package, including flexible working, generous leave allowance and a market-leading Civil Service pension.
For this role, a Recruitment and Retention Allowance (RRA) of up to £9k per annum may also be payable; this is paid in increments, upon reaching the required level of competence.
We are a small, highly specialised team, performing a critical role in Defence Digital, offering an exciting opportunity to join us and become part of our journey!
Responsibilities include:
- Provide line management of civilian and military Cyber Security Assessment personnel, ensuring that workloads are balanced efficiently and training and development needs are managed.
- Lead the promotion of cyber security standards and best practice across Defence, guiding and influencing project and policy decision making as appropriate and seeking novel solutions to challenging security issues.
- Ensure the risk assessment process against approved frameworks (e.g., NIST).
- Review risk management evidence to confirm that risk assessments and risk treatment plans are consistent with business requirements.
- Confirm that residual security risks have been captured and accepted by the appropriate risk owner, in accordance with the risk owner’s delegated authority.
- Recognise risk management and security decisions that have an implication beyond their level of responsibility, experience or delegated risk tolerance and escalate accordingly.
- Explain the Cyber assessment to the risk owner, in terms of business objectives threats, risks, vulnerabilities, controls and business impacts.
- Liaise with appropriate subject matter experts across Defence including the National Cyber Security Centre (NCSC), Cryptographic Service for Defence, Joint Cyber Unit and, where appropriate other Government Departments and Security Agencies.
Person specification
If you have the following skills and experience, we would love to hear from you!
We would expect to see some previous experience in Cyber Security Governance and Management, Risk Management and/or Operational Security Management and ideally you’ll have the following skills:
- The ability to build strong working-relationships
- Great communication skills, able to converse at a wide variety of levels
- Able to lead both technical and non-technical teams
Qualifications: Your experience is key but if you have any of the following industry qualifications that would great; if not, we’ll help you attain them. You’ll need to have the motivation and desire to continue to learn and develop and we’ll provide opportunities to gain these in post:
- Certificate in Information Security Management Principles (CISMP)
- Certificate in Information Security Management (CISM)
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Control
- Certified Cyber Professional (CCP)
Memberships: If you aren’t already a member, we’ll help you with the process and if/when you are, we’ll assist you in supporting & maintaining them:
- CIISEC
- BCS
Allowances: A Recruitment and Retention Allowance (RRA) of up to £9k may be payable with this post, paid in increments upon reaching the required level of competence.
This job role is suitable for hybrid working, which is an informal, non-contractual and voluntary arrangement, blending a balance of attendance in the workplace (your permanent duty station which is based on business assessment of where the work is best done) and working from home as a personal choice (if the role is suitable for this). If you are successful, any opportunities for hybrid working will be discussed with you prior to you taking up your post.
We anticipate that the successful candidate will be required to attend the office for a minimum of 1-2 days per week, occasionally at short notice, with travel to other sites and additional office attendance determined by the business needs.
Dependent on the business need, there may be a requirement to travel to meetings within the UK (or potentially occasional overseas visits).
If not already held, successful candidates will be required to undergo DV clearance. This position is open to sole UK Nationals only.
Behaviours
We’ll assess you against these behaviours during the selection process:
- Leadership
- Communicating and Influencing
- Seeing the Big Picture
- Delivering at Pace
Technical skills
We’ll assess you against these technical skills during the selection process:
- Information risk assessment and risk management
- Applied security capability
Benefits
- Learning and development tailored to your role with a dedicated minimum of 5 days per year
- Flexible working options
- 25 days paid annual leave rising (by 1 day per year) to 30 days upon completion of five years’ service
- Ability to roll up to 10 days annual leave per year
- In addition to eight public holidays per year, you will also receive leave for HM The King’s birthday
- A Civil Service pension with an average employer contribution of 27%
- Parental and Adoption Leave
- Discounts on a range of services within and external to the civil service – Defence Discount Service, Civil Service societies for Sports and Leisure, Healthcare, Insurance, Motoring, Company discounts with Virgin, Vodafone, and Microsoft Office
- In year rewards and ‘thank you’ schemes such as vouchers and gift cards
- A culture encouraging inclusion and diversity
- Please see Benefits Leaflet for more detail