Location
About the job
Job summary
Enterprise security risk management (ESRM) is key to enabling HMRC to deliver secure operations, with lines of business owning and actively managing security risk.
Your team are an integral part of ESRM, setting the security controls, including security policies, that HMRC should adopt, assessing what this means for security risk across the enterprise and ensuring we scan future developments and threats to adapt and leverage our security controls.
This role will have a pivotal part to play in developing and embedding security risk management in the business, as well as
Assessing the aggregation of risk across the whole organisation through the tier 2 and tier 1 security risk domains. You will own ESRM messaging, working across the organisation to improve the security risk management culture within HMRC.
ESRM is part of the work of The Security Operating Model (SOM) which is changing how security is delivered. The risk and controls team is a cornerstone in HMRC Security. Your support of the SOM will present opportunities for efficiencies and scalability, as well as seeking to improve and mature the operation of ESRM.
At HMRC we are committed to creating a great place to work for all our colleagues; an inclusive and respectful environment that reflects the diversity of the society we serve.
We want to maximise the potential of everyone who chooses to work for us and we offer a range of flexible working patterns and support to make a fulfilling career at HMRC accessible to you.
Diverse perspectives and experiences are critical to our success and we welcome applications from all people from all backgrounds with the experience and skills needed to perform this role.
See what it’s like to work at HMRC: find out more about us or ask our colleagues a question. Questions relating to an individual application must be emailed as detailed later in this advert.
Job description
The enterprise security risk and controls teams sit within the Governance, Risk and Compliance team in HMRC Security.
The team is responsible for owning and managing the enterprise level security risks at tier 1 and tier 2, setting and assessing the departmental security risk appetite and tolerance and defining the associated security controls, including the security policies and standards.
You will manage and support the security policy team and use insights from the risk team and data to assess the performance of HMRC security policies. You and your team shall identify areas for compliance activity and policy review where deficiencies or a changing landscape means these are no longer fit for purpose. Through your leadership, the team will support the adoption of and compliance with HMRC security policy through a range of avenues including the commissioning of education and awareness, reporting and governance channels.
You will own the development and adoption of a clear methodology to measure and report HMRC performance against enterprise security controls and risk. You will call out to the HMRC senior leadership team areas of deficiency and practices that impact the improvement of the HMRC security risk posture. You will take action proportionately, having the ability to balance business need with operating in a secure enough environment.
You will line manage the team directly involved in this work and take responsibility for several key reporting actions in the strategic risk process, this includes input to senior briefing including Audit and Risk Committee and Excom as well as ensuing policy reviews are scheduled and completed timeously.
You and your team focus on priority risk and controls. Your skill in adeptly assessing priorities enables you to often make difficult decisions on where to focus your resource. You’ll be responsible for the reporting and assessment of the HMRC security position, which includes measuring risk appetite and tolerance levels.
You always direct your teams to provide timeous reporting and flag risks before they become issues. You provide support to your team to work holistically, providing a global picture of security risk for HMRC.
You clearly give direction to the enterprise security risk and controls team, ensuring that they are not only focused on current risk exposure, but horizon scanning and managing new environmental, technological and security threat data to support HMRC to manage and be prepared for any changes in the security landscape.
This role is pivotal in ensuring that security controls are measured, proportionate and effective. This must be aligned to the central HMRC risk and controls frameworks, directed centrally. You and your team develop and maintain good working relationships with a wide variety of teams across the organisation.
Person specification
Essential criteria
The successful candidate must have a deep understanding of the risk and controls landscape.
The successful candidate must have an appreciation for the concept of enterprise security risk.
This role supports senior level reporting and will work closely with the Deputy Director and their broader team to set the context and direction for enterprise security. You must be a strong communicator, with the ability to transform complex and sometimes technical content into a simple and impactful narrative.
You must be able to work collaboratively across teams, acting as a critical friend and a challenge function out into HMRC to embed and improve the adoption and performance of security controls to mitigate risk.
Desirable criteria
Knowledge of security risk and controls and how they support secure operations would be advantageous.
Experience in drafting, testing, and evaluating policy.
Experience of drafting and reporting to senior stakeholders and taking ownership of challenging messages to those stakeholders.
You should be an engaging leader and able to take your team with you, particularly through the change journey.
You should be adept at both using governance and networks to achieve outcomes.
Behaviours
We’ll assess you against these behaviours during the selection process:
- Seeing the Big Picture
- Communicating and Influencing
Benefits
- Learning and development tailored to your role
- An environment with flexible working options
- A culture encouraging inclusion and diversity
- A Civil Service pension with an average employer contribution of 27%
Find more about HMRC benefits in ‘Your little extras and big benefits handbook’ for further information or visit Thinking of joining the Civil Service.