Location
About the job
Job summary
#DESNZ
The responsibilities for the Department for Energy Security & Net Zero for 2023 are as follows:
- Delivering security of energy supply
- Ensuring properly functioning energy markets
- Encouraging greater energy efficiency
- Seizing the opportunities of net zero to lead the world in new green industries
For 2023, our priorities are:
- Ensure security of energy supply this winter, next winter and in the longer-term – bringing down energy bills and reducing inflation.
- Ensure the UK is on track to meet its legally binding Net Zero commitments and support economic growth by significantly speeding up delivery of network infrastructure and domestic energy production.
- Improve the energy efficiency of UK homes, businesses and public sector buildings to meet the 15% demand reduction ambition.
- Deliver current schemes to support energy consumers with their bills and develop options for long-term reform to improve how the electricity market works for families and businesses.
- Seize the economic benefits of Net Zero, including the jobs and growth created through investment in new green industries.
- Pass the Energy Bill to support the emerging CCUS and hydrogen sectors; to update the governance of the energy system; and to reduce the time taken to consent offshore wind.
Our Inclusive Environment
We are building an inclusive culture to make the Department a brilliant place to work where our people feel valued, have a voice and can be their authentic selves. We value difference and diversity, not only because we believe it is the right thing to do, but because it will help us be more innovative and make better decisions.
We offer first-class flexible working benefits, excellent employee well-being support and a great pension. We are fortunate to have a range of excellent staff networks and are proud to be a Disability Confident Leader employer. We will support talented people from all backgrounds to build a career and thrive.
We actively welcome applications from anyone who shares our commitment to inclusion. We will fully support candidates with a disability or long-term condition who require adjustments in our recruitment process.
Job description
Are you interested in joining a high-performing team of security professionals? If you are ready to challenge yourself and become a member of a specialist security team, then we have a great opportunity for you!
We need an organised, proactive, and flexible individual to a provide Cyber Security Risk Management Lead functions to two Departments, Department for Energy Security & Net Zero, Department for Science Innovation & Technology and in the Departmental Security Unit (DSU).
The Cyber Security Risk Manager Lead identifies, understands, and mitigates cyber-related risks. They will identify and evaluate security risks to information, systems and processes owned and used by both organisations, and proactively provide appropriate advice, drawing on a wide variety of sources, to stakeholders across the organisations and at a variety of levels. They will provide the appropriate guidance to risk, service owners and seniors, allowing them to make well informed, risk-based decisions.
This role is full time only. Applicants who wish to work an alternative pattern are welcome to apply however your preferred working pattern may not be available and you should discuss this with the vacancy holder before applying.
Person specification
• Independently undertake risk management activities within a given area of practice or expertise, usually within established security and risk management governance structures
• Lead the analysis and derivation of business-supporting security needs, undertake Cyber Security related risk assessments, conduct tailored threat assessment and other risk management activities, and ensure activities are consistent with applicable regulations and legislation.
• Provide tailored advice to a range of stakeholders on how to remedy identified risks by proportionately applying security capabilities, using published guidance, standards, and drawing on a range of experts as well as personal expertise.
• Provide expert security advice that highlights Cyber Security related risks, so risk or service owners can make well-informed and auditable decisions.
• Support the planning, development, implementation and management of organisation-wide policies, processes, and procedures for the management of cyber security risk. Protecting the organisation’s assets and business services.
• Review internal controls following any security breach, providing advice on how to remediate any vulnerabilities discovered. Agreeing and overseeing remedial solutions, controls and safeguards that are the most appropriate and beneficial for the organisation.
• Lead, mentor, and support others to perform to their full potential and driving succession planning.
• Be part in an on-call rota providing out of hours cover, including public and bank holidays. We will provide training and pay an allowance for the time you are on duty.
Skills and experience
Have a demonstrable passion for Cyber & Information Security, with the following skills or experience aligned with the Government Security Profession Career Framework:
• Information Risk Assessment & Risk Management: be able to review risk assessments using appropriate methods and can inspect and report security characteristics of systems.
• Applied security capability: Elicit security requirements based on straightforward approaches such as threat/vulnerability/impact analysis. Can use control frameworks appropriately understanding their strengths and limitations.
• Threat understanding – keep up to date with the cyber threat landscape and be able to understand, contextualise and communicate any potential impact to the business
• Communicate effectively with both technical and non-technical stakeholders, and articulate threat intelligence and risk assessments in terms of their impact to the business.
• Build effective relationships with senior stakeholders in order to raise awareness of the importance of security issues, as well as communicating the outcome of audits and investigations.
Behaviours
We’ll assess you against these behaviours during the selection process:
- Working Together
Technical skills
We’ll assess you against these technical skills during the selection process:
- Risk Assessment – Methodologies and Frameworks used to Risk Assess
- Risk Management – Process of managing risk identified as potentially affecting the organisation
- Threat understanding – Understanding the cyber threat landscape and associated impact on the business. Ability to identify appropriate mitigation
- Critical thinking – Analysis of facts and evidence in order to form a judgement by the application of rational, unbiased analyses and evaluation
Benefits
BEIS offers a competitive mix of benefits including:
A culture of flexible working, such as job sharing, homeworking and compressed hours.
Automatic enrolment into the Civil Service Pension Scheme, with an average employer contribution of 27%.
A minimum of 25 days of paid annual leave, increasing by 1 day per year up to a maximum of 30.
An extensive range of learning & professional development opportunities, which all staff are actively encouraged to pursue.
Access to a range of retail, travel and lifestyle employee discounts.
A hybrid office/home based working model where staff will spend a norm of 40-60% of their time in the office (minimum of 40%) over a month with flex dependent on balancing business and individual need (from September 2021, depending on how the public health guidance evolves).