Location
About the job
Job summary
Working to the Deputy Director, Security Governance, Culture and Engagement in HMRC Security, the Head of Security Culture, Education and Awareness will lead and deliver HMRC Security’s culture, education and awareness capability and services, including delivering an ongoing programme of innovative industry standard security awareness campaigns, activities and responses, based on empirical evidence, emerging threat and risk. Leading an energetic and enthusiastic team and working in partnership with our Enterprise Security Programme, the post holder will monitor and evaluate all activity that influences HMRC’s security culture posture, whilst driving both continual innovation in security culture and awareness delivery and the improvement in the security culture posture within HMRC and VOA. They will deliver activities that support HMRC business to mitigate security risks to our services, information, premises, customers and colleagues and make ‘security’ an intrinsic part of HMRC business and staff DNA.
At HMRC we are committed to creating a great place to work for all our colleagues; an inclusive and respectful environment that reflects the diversity of the society we serve.
We want to maximise the potential of everyone who chooses to work for us and we offer a range of flexible working patterns and support to make a fulfilling career at HMRC accessible to you.
Diverse perspectives and experiences are critical to our success and we welcome applications from all people from all backgrounds with the experience and skills needed to perform this role.
See what it’s like to work at HMRC: find out more about us or ask our colleagues a question. Questions relating to an individual application must be emailed as detailed later in this advert.
Job description
Personal Specification:
We are looking for an inclusive leader with proven experience of delivering innovative culture, education and awareness activities, with the ability to maximise cross-government, public sector and private sector relationships and engagement to make HMRC a pioneer in security culture management, and work in partnership with HMRC Business to make security inherent in organisational culture and business delivery (Business and Personal DNA).
Key Responsibilities include:
- Create and execute the strategy and plan for promoting, embedding and maintaining a security focused culture and good security management practices across HMRC, VOA and Third-Party Suppliers, aligned to key HMRC and cross-government objectives.
- Establish a security culture baseline; monitor, evaluate and report on HMRC Security, Programme and Business activities that influence the baseline to the Chief Security Officer and other key stakeholders as appropriate.
- Co-ordinate and oversee the governance of Security Culture, Education and Awareness activity and response through chairing of and representation at appropriate forums.
- Lead, deliver and assure HMRC security culture, education and awareness capability and services, delivering an ongoing programme of innovative industry standard security awareness campaigns, activities and responses, based on empirical evidence, emerging threat and risk; ensure programme is delivered to appropriate professional standards, within budget and to timescales.
- Lead the design, implementation and maintenance of a new programme of mandatory security learning for HMRC, VOA and Third-Party suppliers which meets Government Security Standards, delivers the right knowledge at the right time to the right roles, balancing the security requirements with the needs of the business and their objectives.
- Champion and drive continual improvement in the maturity of HMRC security culture, pro-actively collaborating with and influencing senior managers across HMRC business areas to gain top down buy in for Security Culture, Education and Awareness activities across HMRC and VOA.
- As a Business owner and key stakeholder, work in partnership with Enterprise Security Programme to oversee the procurement, implementation and management of new, innovative digital platforms and products that improve the delivery of Security Education and Awareness within HMRC where appropriate and/or work in partnership with other areas of HMRC business to embed products within their business and products.
- Work in partnership with the Enterprise Security Programme to transform and automate how HMRC Security monitors the departments security culture posture in an agile way enabling more effective, prioritised and targeted responses.
- Working in partnership with Enterprise Security Programme, lead the establishment and maintenance of positive vendor and stakeholder relationships to ensure new technologies and products are embedded as business as usual activities with effective governance, budgetary management, evaluation and compliance regimes in place as appropriate.
- Work in partnership with Chief Data Officer and the Office of the Data Protection Officer to maximise the impact of the Data Protection and Security interventions.
- Build and maximise relationships across the Public and Private Sector enabling HMRC to be a pioneer in Security Culture Management and Innovation.
- Represent HMRC and play a pro-active role, influencing and shaping Security Culture initiatives cross-government working with Government Security Group, NTAs, Security Education and Awareness Centre (SEAC); ensuring that HMRC CEA utilises and shares best practice and to ensure value for money.
- Lead, motivate, develop and appraise a small team applying a consistent vision, energy and drive that motivates the team to meet business objectives, setting them in the context of wider security and Departmental objectives. Pro-actively cultivate talent and foster an inclusive, diverse and motivated workforce, while building the right culture to deliver a customer-centric, effective, coherent and continuously-improving security organisation. Lead and manage others to achieve an inclusive culture and the specific goals outlined by HMRC’s and the relevant profession’s diversity and inclusion strategy. Create and champion an environment of continuous improvement across the team, where learning from feedback, security risks, events, incidents, investigations and trends becomes integral to business design and processes.
- Being a leadership role model for the Government security community and modelling Civil Service values to foster and develop the profession across government. Acting as a security professional, championing and sharing best practice through the community and embedding and championing government security culture within the department. Work in strong partnership with peers across HMRC, the intelligence agencies and other government departments, and personally create the environment for joint successes.
Person specification
The successful candidate will need to demonstrate the following skills and experience as a minimum against the following Essential Criteria:
- Experience of setting direction and meeting strategic objectives through the development of high-level strategies and plans aligned to business objectives.
- Ability to gather and use data to evaluate and improve performance.
- Experience of building strong working relationships with senior stakeholders and influencing strategic direction.
- Ability to influence senior stakeholders whilst understanding their concerns and needs.
Desirable:
- Experience of delivering successful culture and awareness programmes of activity where the outcomes have influenced organisational culture and behaviours in a large organisation.
- Ability to work collaboratively across business areas and networks, supporting the joint development of concise, compelling and realistic strategies with clear outcomes.
- Experience in coaching and developing staff to grow capability and ensure team members are equipped with the skills and knowledge to effectively undertake their job roles.
- Experience of working effectively with managed suppliers and vendors.
- Background in either cyber, personnel, physical or information security.
- Experience of budgetary, risk and/or project management, with the ability to manage and maintain a complex programme of initiatives.
Behaviours
We’ll assess you against these behaviours during the selection process:
- Leadership
- Seeing the Big Picture
- Communicating and Influencing
- Managing a Quality Service
Benefits
- Learning and development tailored to your role
- An environment with flexible working options
- A culture encouraging inclusion and diversity
- A Civil Service pension with an average employer contribution of 27%