x

Cyber Security Risk Manager Lead

Birmingham, Cardiff, Darlington, Edinburgh, London, Salford

Job summary

#DESNZ

The responsibilities for the Department for Energy Security & Net Zero for 2023 are as follows:

  • Delivering security of energy supply
  • Ensuring properly functioning energy markets
  • Encouraging greater energy efficiency
  • Seizing the opportunities of net zero to lead the world in new green industries

For 2023, our priorities are:

  • Ensure security of energy supply this winter, next winter and in the longer-term – bringing down energy bills and reducing inflation.
  • Ensure the UK is on track to meet its legally binding Net Zero commitments and support economic growth by significantly speeding up delivery of network infrastructure and domestic energy production.
  • Improve the energy efficiency of UK homes, businesses and public sector buildings to meet the 15% demand reduction ambition.
  • Deliver current schemes to support energy consumers with their bills and develop options for long-term reform to improve how the electricity market works for families and businesses.
  • Seize the economic benefits of Net Zero, including the jobs and growth created through investment in new green industries.
  • Pass the Energy Bill to support the emerging CCUS and hydrogen sectors; to update the governance of the energy system; and to reduce the time taken to consent offshore wind.

Our Inclusive Environment

We are building an inclusive culture to make the Department a brilliant place to work where our people feel valued, have a voice and can be their authentic selves. We value difference and diversity, not only because we believe it is the right thing to do, but because it will help us be more innovative and make better decisions.

We offer first-class flexible working benefits, excellent employee well-being support and a great pension. We are fortunate to have a range of excellent staff networks and are proud to be a Disability Confident Leader employer. We will support talented people from all backgrounds to build a career and thrive.

We actively welcome applications from anyone who shares our commitment to inclusion. We will fully support candidates with a disability or long-term condition who require adjustments in our recruitment process.

Job description

Are you interested in joining a high-performing team of security professionals?  If you are ready to challenge yourself and become a member of a specialist security team, then we have a great opportunity for you!

We need an organised, proactive, and flexible individual to a provide Cyber Security Risk Management Lead functions to two Departments, Department for Energy Security & Net Zero, Department for Science Innovation & Technology and in the Departmental Security Unit (DSU).

The Cyber Security Risk Manager Lead identifies, understands, and mitigates cyber-related risks. They will identify and evaluate security risks to information, systems and processes owned and used by both organisations, and proactively provide appropriate advice, drawing on a wide variety of sources, to stakeholders across the organisations and at a variety of levels. They will provide the appropriate guidance to risk, service owners and seniors, allowing them to make well informed, risk-based decisions.

This role is full time only. Applicants who wish to work an alternative pattern are welcome to apply however your preferred working pattern may not be available and you should discuss this with the vacancy holder before applying.

Person specification

• Independently undertake risk management activities within a given area of practice or expertise, usually within established security and risk management governance structures

• Lead the analysis and derivation of business-supporting security needs, undertake Cyber Security related risk assessments, conduct tailored threat assessment and other risk management activities, and ensure activities are consistent with applicable regulations and legislation.

• Provide tailored advice to a range of stakeholders on how to remedy identified risks by proportionately applying security capabilities, using published guidance, standards, and drawing on a range of experts as well as personal expertise.

• Provide expert security advice that highlights Cyber Security related risks, so risk or service owners can make well-informed and auditable decisions.

• Support the planning, development, implementation and management of organisation-wide policies, processes, and procedures for the management of cyber security risk. Protecting the organisation’s assets and business services.

• Review internal controls following any security breach, providing advice on how to remediate any vulnerabilities discovered. Agreeing and overseeing remedial solutions, controls and safeguards that are the most appropriate and beneficial for the organisation.

• Lead, mentor, and support others to perform to their full potential and driving succession planning.

• Be part in an on-call rota providing out of hours cover, including public and bank holidays. We will provide training and pay an allowance for the time you are on duty.

Skills and experience 

Have a demonstrable passion for Cyber & Information Security, with the following skills or experience aligned with the Government Security Profession Career Framework:

• Information Risk Assessment & Risk Management: be able to review risk assessments using appropriate methods and can inspect and report security characteristics of systems.

• Applied security capability: Elicit security requirements based on straightforward approaches such as threat/vulnerability/impact analysis. Can use control frameworks appropriately understanding their strengths and limitations.  

• Threat understanding – keep up to date with the cyber threat landscape and be able to understand, contextualise and communicate any potential impact to the business

• Communicate effectively with both technical and non-technical stakeholders, and articulate threat intelligence and risk assessments in terms of their impact to the business.

• Build effective relationships with senior stakeholders in order to raise awareness of the importance of security issues, as well as communicating the outcome of audits and investigations.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Working Together

Technical skills

We’ll assess you against these technical skills during the selection process:

  • Risk Assessment – Methodologies and Frameworks used to Risk Assess
  • Risk Management – Process of managing risk identified as potentially affecting the organisation
  • Threat understanding – Understanding the cyber threat landscape and associated impact on the business. Ability to identify appropriate mitigation
  • Critical thinking – Analysis of facts and evidence in order to form a judgement by the application of rational, unbiased analyses and evaluation
Alongside your salary of £50,305, Department for Business, Energy & Industrial Strategy contributes £13,582 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.

BEIS offers a competitive mix of benefits including:

A culture of flexible working, such as job sharing, homeworking and compressed hours.

Automatic enrolment into the Civil Service Pension Scheme, with an average employer contribution of 27%.

A minimum of 25 days of paid annual leave, increasing by 1 day per year up to a maximum of 30.

An extensive range of learning & professional development opportunities, which all staff are actively encouraged to pursue.

Access to a range of retail, travel and lifestyle employee discounts.

A hybrid office/home based working model where staff will spend a norm of 40-60% of their time in the office (minimum of 40%) over a month with flex dependent on balancing business and individual need (from September 2021, depending on how the public health guidance evolves).

Home Office Intelligence – Immigration Enforcement – Marriage Referral Assessment Unit – Intelligence Support Officer

Liverpool The Capital

Job summary

Home Office Intelligence brings together a number of existing teams involved in the collection and analysis of border and immigration related intelligence. It delivers Intelligence Collection, Development, Analysis, Targeting (Data Analytics) and Watchlisting capabilities within the Home Office and to its partners across Government and Law Enforcement. Learn more on the HO Intelligence careers page.

Job description

Home Office Intelligence is comprised of a number of teams involved in the collection and analysis of border and immigration related intelligence. The Command has colleagues based across the UK and international locations who are focused on threats related to Organised Crime, National Security and Revenue. The Command’s remit is to deliver Intelligence Collection, Development, Analysis, Targeting (Data Analytics) and Watchlisting capabilities within the Home Office and to its partners across Government and Law Enforcement.

The Marriage Referral Assessment Unit [MRAU] operates within the Home Office Intelligence Command. This is a specialist team that handles referrals made by registrars under the UK’s marriage and civil partnership referral scheme. The team manages Intelligence-based risk profiles to identify referrals that are high risk for sham relationships and then tasks such referrals for an investigative response.

Person specification

As a member of the MRAU, you will be expected to work both independently and as part of a team. You will prioritise specific tasks to meet service level agreements in delivery of the organisation’s high priority aims.

The Administrative Officer is responsible for processing referrals from registrars under the statutory scheme, ensuring that the resulting casework is handled efficiently, accurately, and lawfully. This includes assessing referrals which are scored as high-risk for sham marriage, using evidence-based criteria to task referrals to Immigration and Enforcement Teams for further investigation action.

You will strive to provide a quality service through effective management of written correspondence with customers referred under the scheme.

You will maintain and develop relationships with internal and external partners including designated registry offices throughout the UK. The role involves regular communication with partners by phone, including managing an enquiries line.

The Administrative Office will play a pivotal role in supporting the organisation’s key priority of deterring individuals from entering a sham marriage within the UK.

Essential criteria

A successful candidate should be able to demonstrate:

• The ability to prioritise workload/tasks in order to meet organisation deadlines

• Excellent written, verbal communication and interpersonal skills

• The ability to establish and maintain effective working relationships with partners internally and externally.

• A proven track record to plan, organise and manage time to deliver the best quality and efficient service.

• Understanding of sensitive data handling in accordance with business procedures and/or legislation.

• A good working knowledge of Microsoft Office – Word, Excel, and Outlook.

Desirable criteria

• Previous experience of roles involving the application of the Public Sector Equality Duty, or equivalent provisions.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Managing a Quality Service
  • Delivering at Pace
  • Working Together

We only ask for evidence of these behaviours on your application form:

  • Managing a Quality Service
Alongside your salary of £22,400, Home Office contributes £6,048 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.
  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • Civil Service pension with an average employer contribution of 27%

Lead Intelligence Officer

Hybrid

Job summary

About us

The Information Commissioner’s Office (ICO) is the independent regulator of information rights. In a data-driven world, we provide advice, guidance, and support to organisations enabling compliance with their obligations, as well as protecting individuals and their personal data.

As an employer, we are passionate about making a positive difference to the lives and careers of our people, and we empower you to be curious, impactful, collaborative and respectful.

Job description

About the role

As a department of skilled intelligence professionals, we use information from a wide range of internal and external sources to produce high quality, meaningful intelligence analysis. This analysis, through a suite of relevant intelligence products, is used to inform and lead tactical and strategic decisions across the office, allowing the ICO to prioritise work where it has greatest value and impact.

The Lead Intelligence Officer is responsible for conducting general and themed research and analysis, developing, and completing intelligence collection plans, understanding, and interpreting intelligence products, building intelligence pictures and identifying new and emerging trends to facilitate a risk-based approach to regulatory activity.

Key responsibilities include:

  • To undertake detailed research and analysis to inform the focus of office wide ICO activity.

  • To collect, evaluate and analyse data from various sources, with a view to identifying trends, resulting in the prioritisation and direction of ICO resources both at the tactical and strategic level.

  • To provide intelligence support to significant ICO priority workstreams including criminal and  civil investigations.
  • To produce appropriate intelligence products that include strategic and tactical assessments, problem, and target profiles.

  • To maximise  the use of structured analytical techniques to understand, develop and communicate concerns in relation to a range of information rights issues.
  • To identify intelligence requirements and formulate intelligence collection plans to focus intelligence gathering and inform resourcing decisions.

  • To exploit intelligence sources that will

enable us to make informed choices about the action we take and the interventions we make  to improve standards of information rights practice.

  • To liaise clearly and confidently at all levels throughout the organisation and with regulatory bodies and other stakeholders nationally and internationally, presenting analysis as appropriate.

  • To develop and maintain legislative expertise, keeping abreast of developments in data protection, freedom of information and associated legislation. To be conversant with other related legislation and political, social, technical, and legal developments that may impact the work of the Intelligence Department and wider ICO.

Person specification

About you

  • Educated to degree level or Substantial work experience demonstrating graduate level ability

  • Worked in a similar intelligence or analytical environment in a large organisation.

  • Experience of applying data protection or freedom of information legislation, or other similarly complex legislation.

  • Carried out duties / work involving research tasks including analysis of information, monitoring patterns and trends, and associated administrative functions.

  • Ability to rapidly analyse and understand large data sets

  • Experience of preparing/presenting  complex reports and producing statistics/charts etc.

  • Ability to use and assess computer software applications relating to the charting and analysis of intelligence to assist in the identification of patterns and trends.

  • Able to demonstrate an analytical approach to problem solving.

  • Experience of liaising with all levels of staff, presenting analysis as appropriate.

  • Experience of providing advice to managers.

  • Prepared to maintain standards of professional practice and to keep abreast of changes in legislation, policies, and procedures within the intelligence environment.

Equality, diversity, and inclusion

The ICO is committed to promoting and enhancing equality, diversity, and inclusion. We are focused on developing a workforce that is representative of the communities we serve and together we are building an inclusive workplace where all of our colleagues have the opportunity to make a real difference. We are championing this through our Equality Diversity and Inclusion Board together with a number of staff networks. Read more about our commitment on our website.

If you have a disability or impairment and have difficulty using our online application system, please email the HR team at recruitment@ico.org.uk who can arrange for you to submit an application via an alternative method.

Please visit ico.jobs for full details, including salary and benefits.

Enterprise Security Risk Business Manager

Bristol, South West England, BS2 0ES : Cardiff, Wales, CF10 1EP : Salford, North West England, M3 5BS : Newcastle upon Tyne, North East England, NE98 1ZZ : Telford, West Midlands (England), TF3 4NT

Job summary

At HMRC we are committed to creating a great place to work for all our colleagues; an inclusive and respectful environment that reflects the diversity of the society we serve.

We want to maximise the potential of everyone who chooses to work for us and we offer a range of flexible working patterns and support to make a fulfilling career at HMRC accessible to you.

Diverse perspectives and experiences are critical to our success and we welcome applications from all people from all backgrounds with the experience and skills needed to perform this role.

See what it’s like to work at HMRC: find out more about us or ask our colleagues a question. Questions relating to an individual application must be emailed as detailed later in this advert.

Job description

HM Revenue & Customs (HMRC) is one of the largest Government Departments and one of the UK’s biggest organisations. Almost every individual and business in the UK is a direct customer of HMRC. We collect in excess of £500 billion a year in revenue from over 50 million customers across the UK.

This is an exciting opportunity to be at the heart of security risk management in HMRC and to be part of the Government Security Function, working to keep the UK safe.

Working with us means making a real impact on millions of people’s lives. It also means gaining new skills, growing your knowledge and taking your expertise further across a range of fascinating and vitally important work. This role is aligned to the Government Security Profession Career Framework: – Risk Management at Principal level, part of the Corporate Enablers security specialism.

This is an exciting time to join the HMRC Security community. Our mission is to reduce HMRC’s security risk exposure whilst enabling HMRC to meet its business objectives effectively and to maintain public confidence in our services. We do this by providing expert security risk-based assurance, oversight and challenge.

Working within HMRC Security’s Governance, Risk and Compliance (GRC) function, you will be responsible for; collating and analysing enterprise security risk data, presentation of enterprise risk data for senior managers, helping to identify trends and areas of concern or improvement. Outputs in the form of dashboards and reports will be used to increase security risk maturity and enhance accountability across the department.

GRC’s Enterprise Security Risk, Transformation Project, is currently developing high level security risk dashboards and a Security Risk Analysis Hub, to assist in the assessment and promotion of HMRC’s enterprise wide security issues. A key element of the role of the Enterprise Security Risk Business Manager will be the development and ongoing maintenance of these tools.

Person specification

Purpose of role:

  • To develop and maintain close working relationships with stakeholders to obtain high quality security risk data.
  • Develop and maintain systems and processes for gathering and storing security risk data
  • Aggregating data from multiple sources to provide a comprehensive assessment of risk exposure
  • Maintaining a library of relevant security data, ensuring it is accessible for those that need to access and use this data.
  • Provide clear and concise material for senior leaders that clearly articulates security performance and concerns.

Post holder expectations;

  • Strong organisational skills are a critical element of this role, as is the ability to prioritise and manage a workload, analyse complex information, present recommendations and make effective decisions.
  • Experience of building a network of colleagues and contacts to achieve progress.
  • You must be able to show evidence that you are organised and can run a number of areas of work concurrently.
  • You should be able to demonstrate that you are able to work with minimal direction and have the ability to make risk-based decisions based on the evidence available to you at the time.
  • Experienced in using data handling and presentation tools such as Excel and Power BI.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Managing a Quality Service
  • Delivering at Pace
  • Changing and Improving
Alongside your salary of £41,782, HM Revenue and Customs contributes £11,281 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.
  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • Civil Service pension with an average employer contribution of 27%

Security Architect

Cheltenham

Job summary

Are you an experienced Security Architect, or a Security Engineer, Technical/Cloud Architect keen to move into a Security Architect role? Looking for a unique challenge?

GCHQ is offering an exciting opportunity to come and join our team of experienced technical Security Architects, you’ll consult on the secure design, build, and be involved in the operation of some of the most important systems in the UK.  

We work on a wide range of projects critical to our business, helping pioneer a new kind of security to stay ahead of our adversaries. We face a variety of novel and complex technical challenges and with the help of our research teams and through collaboration with our partners, we provide vital up-to-date guidance on the application of cutting-edge technologies.

Job description

You’ll combine broad technical and security skills with strong business acumen, consultancy, and communication skills. We’re looking for people who are experienced in the design and build of a range of systems and services using modern technologies and cloud services. You’ll be able to identify vulnerabilities in systems design and work with Engineers, System Owners, and Seniors to explain these issues and identify alternative approaches. 

You’ll have plenty of opportunities to collaborate and influence widely within the UK Government and beyond. Working with customers as a Security Architect, you’ll take the initiative, in the pursuit to balance security versus agility. 

While the role is challenging, our flexible working policy ensures a healthy work-life balance. We accommodate compressed hours, mixed office/home working or job share options, balanced against business needs. We actively support ongoing personal development through training opportunities combined with a strong team dynamic which promotes discussion and sharing of ideas.

Person specification

You’ll have experience analysing customer requirements and making design decisions across a range of technologies and business contexts such as regulated industries, the commercial sector or wider government. With a broad understanding of security challenges, their potential impact and mitigation options, you’ll be comfortable influencing stakeholders to make informed risk-based decisions. You’ll have an appreciation of customers’ needs and experience delivering technology solutions to address their concerns. You may have contributed to development of strategy, policy, patterns or principles to drive an organisations response to new challenges. A passion for technology is vital – you’ll be motivated to maintain and develop your technical skills, learn from others, and share your knowledge with the wider technical community. You’ll be comfortable working as part of a team on a broad range of projects, collaborating on solving problems and sharing ideas.

Training and Development

At GCHQ we’re proud to offer an inclusive and supportive working environment. As an organisation that values and nurtures talent, we are committed to helping you fulfil your potential. We value your ability to learn and to adapt to new challenges, so we’ll invest in your skills and the way you like to learn, from books, study, courses, conferences to stretching work with support of the team.
 
You’ll be encouraged to drive and shape your own personal development and you’ll have access to learning and development opportunities tailored to your role. You’ll be supported to gain professional qualifications and certifications and to seek out opportunities to continually learn and develop, supported through career development guidance, mentoring, and buddying in addition to formal training opportunities.

Rewards and Benefits

You’ll receive a starting salary of £36,836, you may also be eligible for additional annual skills payments of between £8,000 and £13,000 subject to assessment at interview and revalidation, and we may offer you a one-off recruitment bonus, plus other benefits including:

  • 25 Days Annual Leave automatically rising to 30 days after 5 years’ service and an additional 10.5 days public and privilege holidays.
  • Opportunities to be recognised through our employee performance scheme.
  • Interest-free season ticket loan.
  • Excellent pension scheme.
  • Cycle to work scheme.
  • Facilities such as a subsidised gym and restaurant, and on-site coffee bars.
  • Paid parental and adoption leave.

SAP Facility Security Manager

Marham, East of England, PE33 9NP

Job summary

The role involves being an integral part of the Special Access Programme Security Team that ensures that a high level of security is delivered to protect the F-35 air system. The post will be based within one of the F-35 high security facilities and is an important enable for the F-35 pilots and operations staff to plan their missions in a secure environment and on accredited and assured information systems. The role will require interaction across the F-35 Lightning Enterprise to ensure network and security system security is maintained to exacting high standards and sustain the accredited status to operate.
This post is an exciting opportunity to be at the forefront of this security area at the very spearhead of the Royal Air Force’s combat air capability.

This post is offered at 37 hours per week.

Job description

  1. Provide the overall security administration and management of the SAP facilities (SAPFs) by ensuring that the accreditation/certification is in accordance with UK & US guidelines. This includes facilitating electronic processing systems authorised to handle classified
  2. Establish and maintain personnel security and access controls including clearance/access 
    arrangements for personnel accessing the SAP.
  3. Deliver all types of compartment information related security education and training relating to the SAP to ensure personnel are knowledgeable of UK/US regulations and are aware of the appropriate control of all levels of classified information and material.
  4. Managing provision of on-site security of compartmented information and material 
    contained within the SPAFs including developing procedures for responding to security 
    incidents, for investigation, reporting security infractions or incidents, as appropriate.
  5. Review, develop and maintain documentation to support accreditation and certification of SAPFs and applicable Information Systems.
  6. Ensure all SAP documentation held in the UK is marked in Accordance with extant rules & regulations.
  7. Ensure accountability for the records and periodic inventory of all compartmented 
    information materials held within SAPFs including management of annual UK/US inspection holdings.
  8. Assist in the conduct of security audits & inspections
  9. When required, act as courier in assistance to other team members to facilitate the manual transmission of SAP material.
  10. To oversee the management of the UK information Assurance ensuring that information systems used to process SAP information comply with the UK and US security regulations.
  11. Oversee the IAM and system administrators ensuring they receive the appropriate technical and security training to carry out their duties, including the continued development of the training materials for information systems
  12. Conduct weekly audits and surveys
  13. Ensure the IAM produces and maintains all UK information system security plans and associated documentation for RMF (Risk Management Framework).
  14. Co-ordinate, develop and implement local security policy guidance specifying procedures that are consistent with maintaining adequate segregation and protection of the compartmented information stored within SAPs
  15. Support ISSM/ISSO to the generation of SyOps for IS
  16. Manage all project security risks• Ensure adherence to UK & US National security guidelines in accordance with the UK SAPCO MOU, JSP440, JAFAN 6/0, RMF, and the UK/US JSF Access Management Control Plan.
  17. Line-management responsibilities for the administration and training of the Security Admin Assistants, while overseeing and ensuring the security office meets the objectives of the organisation;
  18. Managing a Monday to Friday back shift pattern to cover a 0600 – 2359 hrs operating window.
  19. Operating a 24/7 call-out roster
  20. Report to the GSSO any significant changes or risks which could impact the facility.

Person specification

1.Essential: Developed Vetting (or ability to obtain and maintain DV clearance).

2. Ability to be read onto STRAP.

3. Desirable: Security professions SQEP.

4. Mandatory: Programme level access.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Leadership
  • Working Together
  • Communicating and Influencing
  • Making Effective Decisions
  • Managing a Quality Service
Alongside your salary of £33,830, Ministry of Defence contributes £9,134 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.
  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • Civil Service pension with an average employer contribution of 27%

DDaT – Home Office Cyber Security – Cyber Policy Manager

Croydon – Lunar House, Manchester Soapworks

Job summary

Digital Data and Technology (DDaT) designs, builds and operates services that are critical to the Home Office. From solutions that help manage our borders to services that support policing and counter terrorism, DDaT is at the front line of making the Home Office a modern and capable department at a time of unprecedented global change.

As the Senior Cyber Policy Manager in Home Office Cyber Security (HOCS) you will gain experience of being part of a high performing team that is responsible for the development, implementation and management of policies and standards that underpin the designing, running and decommissioning of technical solutions across the Home Office. Your role will support the delivery of high profile, transformational technology projects, at a time of unprecedented technological and political change.

Your role will report to the Cyber Policy and Standards Manager but on a day to day basis you will be engaging and collaborating with technical experts, stakeholders and peers within the Home Office and other Government Departments to ensure that policies and standards are developed effectively, communicated and implemented clearly and are understood and complied with. You will ensure that our policies align with other policy areas where appropriate, and support gap analysis work to develop new policies for your area.

You will be proactive, detail-oriented, and able to communicate effectively. You will be logical and critical in your thinking, with the ability to assess the impact of policies. You will additionally have a keen focus on continuous improvement to ensure that policies and standards meet departmental and Home Office needs.

Policy specialists within DDaT align to the Civil Service Policy Profession. Is this sentence completed?

Job description

Your main day to day responsibilities will be:

•    Communicating and implementing HOCS policies and standards

•    Devising a schedule of policy / standard compliance reviews and conducting them in collaboration with a broad range of stakeholders across DDaT and wider Home Office portfolios

•    Contributing to the central co-ordination, maintenance and review of policies, standards and other business area artefacts / templates to deliver continuous improvement

•    Developing procedures for appropriate change management and configuration control of policies, standards, business area artefacts / templates

•    Collaborating with Home Office and other Government Department peers to align and deconflict with their related policy areas and support any gap analysis that requires development of new policies.

Due to the nature of this role/business needs, this post is available on full-time and flexible working only but not on part time basis.

Hybrid Working

Hybrid working enables employees to work partly in their workplace(s) and partly at home.  A hybrid working pattern may be available, where business needs allow. Applicants can discuss what this means with the vacancy holder if they have specific questions.  Some occasional travel will be required.

Person specification

You will also be expected to carry out the following day to day activities:

•    Contributing to the development of guidance on policy implementation

•    Keeping up to date with wider policy developments / standards / legislation / technology to ensure policy artefacts remain current

•    Keeping up to date with the latest industry / policy area standards, frameworks and guidance to ensure best practice is reflected in policies and standards across the Home Office e.g the National Cyber Security Centre (NCSC) guidance and the National Institute of Standards and Technology (NIST) Framework.

Essential Criteria:

You will have a passion for the development and implementation of policy, with the following skills or proven experience in:

•    Working in HOCS, including implementing associated policies and standards, understanding best practice in your area of expertise and identifying, resolving and escalating conflicts and risks to appropriate team within HOCS

•    Building, co-ordinating and managing complex stakeholder relationships across DDaT and wider Home Office

•    Delivering continuous improvement initiatives

•    Analysing and interpreting legislation and other key information

•    Demonstrating strong written and verbal communication skills with the ability to tailor your messaging to meet the needs of different audiences

•    Working with diverse teams across multiple locations

The skills outlined above are reflective of the specialist skills listed in the Home Office Enabling Professions Skills and Development Model.

Desirable Criteria:

Ideally you will also have the following skills or some experience in:

•    Demonstrating close attention to detail, excellent organisational skills

•    Working in a technology focussed industry / environment

•    Having an awareness of Cyber Security or a related policy area

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Seeing the Big Picture
  • Changing and Improving
  • Communicating and Influencing
  • Delivering at Pace
  • Working Together

Technical skills

We’ll assess you against these technical skills during the selection process:

  • Cyber Policy
Alongside your salary of £39,000, Home Office contributes £10,530 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.
  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • Civil Service pension with an average employer contribution of 27%

Head of Risk and Control

Telford, Salford, Newcastle, Edinburgh, Bristol, London.

Job summary

Enterprise security risk management (ESRM) is key to enabling HMRC to deliver secure operations, with lines of business owning and actively managing security risk. 

Your team are an integral part of ESRM, setting the security controls, including security policies, that HMRC should adopt, assessing what this means for security risk across the enterprise and ensuring we scan future developments and threats to adapt and leverage our security controls.

This role will have a pivotal part to play in developing and embedding security risk management in the business, as well as 

Assessing the aggregation of risk across the whole organisation through the tier 2 and tier 1 security risk domains.  You will own ESRM messaging, working across the organisation to improve the security risk management culture within HMRC. 

ESRM is part of the work of The Security Operating Model (SOM) which is changing how security is delivered.  The risk and controls team is a cornerstone in HMRC Security.  Your support of the SOM will present opportunities for efficiencies and scalability, as well as seeking to improve and mature the operation of ESRM.

At HMRC we are committed to creating a great place to work for all our colleagues; an inclusive and respectful environment that reflects the diversity of the society we serve.   

We want to maximise the potential of everyone who chooses to work for us and we offer a range of flexible working patterns and support to make a fulfilling career at HMRC accessible to you.  

Diverse perspectives and experiences are critical to our success and we welcome applications from all people from all backgrounds with the experience and skills needed to perform this role. 

See what it’s like to work at HMRC: find out more about us or ask our colleagues a question. Questions relating to an individual application must be emailed as detailed later in this advert.

Job description

The enterprise security risk and controls teams sit within the Governance, Risk and Compliance team in HMRC Security.

The team is responsible for owning and managing the enterprise level security risks at tier 1 and tier 2, setting and assessing the departmental security risk appetite and tolerance and defining the associated security controls, including the security policies and standards.

You will manage and support the security policy team and use insights from the risk team and data to assess the performance of HMRC security policies.  You and your team shall identify areas for compliance activity and policy review where deficiencies or a changing landscape means these are no longer fit for purpose.  Through your leadership, the team will support the adoption of and compliance with HMRC security policy through a range of avenues including the commissioning of education and awareness, reporting and governance channels.

You will own the development and adoption of a clear methodology to measure and report HMRC performance against enterprise security controls and risk.  You will call out to the HMRC senior leadership team areas of deficiency and practices that impact the improvement of the HMRC security risk posture.  You will take action proportionately, having the ability to balance business need with operating in a secure enough environment.

You will line manage the team directly involved in this work and take responsibility for several key reporting actions in the strategic risk process, this includes input to senior briefing including Audit and Risk Committee and Excom as well as ensuing policy reviews are scheduled and completed timeously. 

You and your team focus on priority risk and controls. Your skill in adeptly assessing priorities enables you to often make difficult decisions on where to focus your resource.  You’ll be responsible for the reporting and assessment of the HMRC security position, which includes measuring risk appetite and tolerance levels.

You always direct your teams to provide timeous reporting and flag risks before they become issues.  You provide support to your team to work holistically, providing a global picture of security risk for HMRC.

You clearly give direction to the enterprise security risk and controls team, ensuring that they are not only focused on current risk exposure, but horizon scanning and managing new environmental, technological and security threat data to support HMRC to manage and be prepared for any changes in the security landscape.

This role is pivotal in ensuring that security controls are measured, proportionate and effective.  This must be aligned to the central HMRC risk and controls frameworks, directed centrally.  You and your team develop and maintain good working relationships with a wide variety of teams across the organisation.

Person specification

Essential criteria

The successful candidate must have a deep understanding of the risk and controls landscape.

The successful candidate must have an appreciation for the concept of enterprise security risk.

This role supports senior level reporting and will work closely with the Deputy Director and their broader team to set the context and direction for enterprise security.  You must be a strong communicator, with the ability to transform complex and sometimes technical content into a simple and impactful narrative.

You must be able to work collaboratively across teams, acting as a critical friend and a challenge function out into HMRC to embed and improve the adoption and performance of security controls to mitigate risk.

Desirable criteria

Knowledge of security risk and controls and how they support secure operations would be advantageous.

Experience in drafting, testing, and evaluating policy.

Experience of drafting and reporting to senior stakeholders and taking ownership of challenging messages to those stakeholders.

You should be an engaging leader and able to take your team with you, particularly through the change journey.

You should be adept at both using governance and networks to achieve outcomes.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Seeing the Big Picture
  • Communicating and Influencing
Alongside your salary of £64,693, HM Revenue and Customs contributes £17,467 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.
  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • Civil Service pension with an average employer contribution of 27%

Find more about HMRC benefits in ‘Your little extras and big benefits handbook’ for further information or visit Thinking of joining the Civil Service.

Security Governance Analyst (Ref: 76234)

East Midlands (England), East of England, London (region), North East England, North West England, Scotland, South East England, South West England, Wales, West Midlands (England), Yorkshire and the Humber

Job summary

Please refer to Job Description

Job description

We encourage applications from people from all backgrounds and aim to have a workforce that represents the wider society that we serve. We pride ourselves on being an employer of choice. We champion diversity, inclusion and wellbeing and aim to create a workplace where everyone feels valued and a sense of belonging. To find out more about how we do this visit: https://www.gov.uk/government/organisations/ministry-of-justice/about/equality-and-diversity.

Job Title / Group / Directorate

Security Governance Analyst, Security Information Group, Chief Operating Officer Group.

Reports To

Security Function and Reporting Analyst, MoJ Group Security, Governance Team.

Location & Terms of appointment

This is a permanent post based Nationally.

Salary and Grade

This post is band EO (Executive Officer)

New entrants to the Civil Service will be expected to join on the minimum of the pay range. Existing Civil Servants will have their salary calculated in accordance with the Department’s pay on transfer / pay on promotion rules.

Background

The role of MoJ Group Security is to protect people and assets from damage or harm, drive successful change through delivery of strategic objectives and ensure good governance principles and practices are applied to achieve successful daily operations. Its key objectives are to:

  • Ensure government personnel and physical security shared services address departmental security needs.
  • Seek to raise standards for personnel and physical security in line with the Government Functional Standards.
  • Ensure the department is aligned with and influencing the Cabinet Office Vetting Modernisation Programme.
  • Provide structure and processes for effective decision making, accountability and influencing how objectives are achieved. Ensuring risk is monitored and addressed and performance optimised.
  • Foster effective communication and collaboration and the sharing of best practice, ensuring consistency of approach and standards.
  • Provide expertise on protective security and governance to improve the business of our customers, creating better and safer outcomes for both our customers and department.

The Governance team within MoJ Group Security ensures a proportionate and risk managed approach to security to enable government business to operate effectively, safely, and securely. It provides confidence to senior leaders and stakeholders of secure and successful delivery of security standards and ensures compliance with mandated cross-government assurance activities, as coordinated by the Cabinet Office.

Role Purpose

The Governance team within MoJ Group Security is looking to recruit an Executive Officer to provide specialist administrative support, advice, and guidance to the Governance Team.

The post holder will be responsible for investigating and reporting upon security incidents including ensuring that reporting packs and incident logs are updated and maintained, and any actions / lessons learned are addressed. As well as incident reporting, the team deliver the Departmental Security Health Check, so the role is key in administering the security improvement plan and reporting on security risks to help provide a specialist service to the whole of MoJ.

The role is also about being a team player in the field of security within MoJ HQ by providing support to the line manager and the wider team.  This includes supporting the Information Risk and Security Board on an eight weekly basis to seek assurances that the Senior Responsible Owners and Subject Matter Experts across HQ and the Executive Agencies are implementing departmental security and information policies and managing associated risks. 

The role also includes risk reporting on broader security issues, risk, and other administrative topics. 

Main Activities/Responsibilities

Provide administrative support for the MoJ Information Security Risk (ISR) Board by drafting agendas, creating, and collating papers, and managing the actions log.

Ensure the monthly reporting packs and incident logs are updated and maintained, and any actions / lessons learned are identified and acted upon.

Provide administrative support on Group Security corporate issues to optimize the running of the team, helping to maintain effective security governance for the benefit of the Chief Security Officer.  This will include the maintenance of the Business Continuity programme and other overarching pieces of work.

Collaborate effectively with other teams throughout the Ministry of Justice HQ, Executive Agencies and ALBs, building relationships which aim to embed the reputation and performance of the security teams across the wider Ministry of Justice.

Assist in developing and maintaining comprehensive and up-to-date electronic filing systems that support the delivery of services and are effective in storing and retrieving data, ensuring access and structure are appropriately managed.

Provide support to the line manager on a variety of ad hoc tasks, including responding (sometimes at short notice) to emerging security matters and administration.

Knowledge, Skills, and Behaviours

Experience of and a high-level of competence in, administrative tasks gained through working in an office-based or other relevant environment (private/public sector).

Experience of stakeholder management and customer service provision.

An understanding of the principles of data protection and a strong commitment to confidentiality and discretion when handling sensitive personal or organisational data.

A high level of competence with MS Office 365 products, including MS Word and MS Excel.

A proven ability to deliver an “at volume” service consistently and at pace, whilst adhering to service and policy standards.

Desirable

Qualifications and/or experience in Power BI and Power Automate.

Application Process

The application will assess you on behaviours. Behaviours are the actions and activities that people do which result in effective performance in a job. The Civil Service has defined a set of behaviours that, when demonstrated, are associated with job success. Civil Service Behaviours are specific to the grade level of the job role. The examples of the behaviours are designed to give an overview of what is expected of individuals at each level. There is no expectation that all individuals will need to demonstrate every part of each example to be successful.

To apply for this position please complete the online application form, ensuring you submit the following two application documents:

An up-to-date copy of your CV which details your experience and achievements

A 250-word suitability statement against each of the following Success Profile Behaviours (Level 2):

  • Making Effective Decisions
  • Working Together

Dependent on volumes of applications received the sift stage may be based on the lead behaviour, which is Making Effective Decisions. 

If selected for interview, along with being assessed against the Success Profile behaviours above you will also be tested against the following (to Level 2):

  • Changing and Improving
  • Working Together
  • Managing a Quality Service

Strengths will also be assessed at interview, but these are not shared in advance.  Please also note that interviews will be conducted via video conference.

Further information on Success Profiles and the required standards for this post (Level 2) can be found at: https://www.gov.uk/government/publications/success-profiles

A Merit List of applicants meeting the required criteria may be kept for up to 12 months.

Person specification

Please refer to Job Description

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Changing and Improving
  • Making Effective Decisions
  • Working Together
  • Managing a Quality Service
  • Access to learning and development
  • A working environment that supports a range of flexible working options to enhance your work life balance
  • A working culture which encourages inclusion and diversity
  • Civil Service pension with an average employer contribution of 27%
  • Annual Leave
  • Public Holidays
  • Season Ticket Advance

For more information about the recruitment process, benefits and allowances and answers to general queries, please click the below link which will direct you to our Candidate Information Page.

Link: https://justicejobs.tal.net/vx/candidate/cms/About%20the%20MOJ

Futures Officer

Multi-location from one of our FSA Offices (Belfast, Cardiff or York), or home based in the UK. Please be aware that this role can only be worked within the UK and not overseas. Travel across the UK will be required on an occasional basis, possibly with overnight stays.

Job summary

Do you enjoy developing strong working relationships?

Do you thrive on delivering projects to meet timescale and quality requirements?

Are you looking for a new challenge in an organisation that makes a real difference to everyone?

If the answer is yes – the Food Standards Agency (FSA) has an exciting opportunity for you as a Futures Officer in the National Food Crime Unit (NFCU), building our resilience and capability to ensure that we are in a position to deliver our best work for years to come.

The FSA is a non-ministerial department of over 1300 people. We play a critical role in protecting public health and consumers’ wider interests in food across England, Wales and Northern Ireland. Our vision is an important one – to drive change, delivering “food we can trust” and working towards a healthier and more sustainable food system.

Our National Food Crime Unit (NFCU) plays a vital role in keeping food safe across the UK. Disrupting and deterring those who commit food crimes, their work is a major part of ensuring that the food on our tables is exactly what it says it is. The NFCU faces many challenges as it seeks to carry out its remit, and these challenges are always evolving as threats develop to take advantage of new technology, or our changing food landscapes.

Job description

Working as one of our Futures team, you’ll have the opportunity to help us prepare for these unique challenges. Engaging with projects that seek to examine what the NFCU will come up against and build organisational capabilities to address the threats, helping to develop new processes and optimise approaches that will support our needs.

You’ll have experience in delivering operational outcomes across a range of timeframes and will be able to balance competing priorities to ensure that we can effectively build the NFCU in a way that will keep food safe in the face of an ever-changing food landscape.

If you are excited by the idea of working collaboratively with our fantastic team to make a lasting impact on the food eaten across the country and understand what it takes to deliver effective change that will make the difference necessary, apply today and help us in our mission to keep food safe and ensure that it is what it says it is.

Person specification

Please read the attached Candidate Pack to discover further details about the role, our organisation, who we are looking for and the criteria we will assess against during the selection process.

We look forward to receiving your application and wish you every success.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Seeing the Big Picture
  • Changing and Improving
  • Communicating and Influencing
  • Delivering at Pace
Alongside your salary of £30,957, Food Standards Agency contributes £7,311 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.
Our candidate pack details the benefits that the FSA has to offer. Please also refer to the attached Terms and Conditions statement.

Account Visibility

Please confirm you are happy to be listed on the Members List

Yes, please add me to the list No, please hide me from the list