x

Head of Security Culture, Education and Awareness

Bristol, South West England, BS2 0ES : Cardiff, Wales, CF10 1EP : Edinburgh, Scotland, EH8 8FT : Leeds, Yorkshire and the Humber, LS1 4AP : Salford, North West England, M3 5BS : Newcastle upon Tyne, North East England, NE98 1ZZ : Telford, West Midlands (England), TF3 4NT

Job summary

Working to the Deputy Director, Security Governance, Culture and Engagement in HMRC Security, the Head of Security Culture, Education and Awareness will lead and deliver HMRC Security’s culture, education and awareness capability and services, including delivering an ongoing programme of innovative industry standard security awareness campaigns, activities and responses, based on empirical evidence, emerging threat and risk. Leading an energetic and enthusiastic team and working in partnership with our Enterprise Security Programme, the post holder will monitor and evaluate all activity that influences HMRC’s security culture posture, whilst driving both continual innovation in security culture and awareness delivery and the improvement in the security culture posture within HMRC and VOA. They will deliver activities that support HMRC business to mitigate security risks to our services, information, premises, customers and colleagues and make ‘security’ an intrinsic part of HMRC business and staff DNA.

At HMRC we are committed to creating a great place to work for all our colleagues; an inclusive and respectful environment that reflects the diversity of the society we serve.   

We want to maximise the potential of everyone who chooses to work for us and we offer a range of flexible working patterns and support to make a fulfilling career at HMRC accessible to you.  

Diverse perspectives and experiences are critical to our success and we welcome applications from all people from all backgrounds with the experience and skills needed to perform this role.

See what it’s like to work at HMRC: find out more about us or ask our colleagues a question. Questions relating to an individual application must be emailed as detailed later in this advert.

Job description

Personal Specification: 

We are looking for an inclusive leader with proven experience of delivering innovative culture, education and awareness activities, with the ability to maximise cross-government, public sector and private sector relationships and engagement to make HMRC a pioneer in security culture management, and work in partnership with HMRC Business to make security inherent in organisational culture and business delivery (Business and Personal DNA).    

Key Responsibilities include:

  • Create and execute the strategy and plan for promoting, embedding and maintaining a security focused culture and good security management practices across HMRC, VOA and Third-Party Suppliers, aligned to key HMRC and cross-government objectives.
  • Establish a security culture baseline; monitor, evaluate and report on HMRC Security, Programme and Business activities that influence the baseline to the Chief Security Officer and other key stakeholders as appropriate.
  • Co-ordinate and oversee the governance of Security Culture, Education and Awareness activity and response through chairing of and representation at appropriate forums.
  • Lead, deliver and assure HMRC security culture, education and awareness capability and services, delivering an ongoing programme of innovative industry standard security awareness campaigns, activities and responses, based on empirical evidence, emerging threat and risk; ensure programme is delivered to appropriate professional standards, within budget and to timescales.
  • Lead the design, implementation and maintenance of a new programme of mandatory security learning for HMRC, VOA and Third-Party suppliers which meets Government Security Standards, delivers the right knowledge at the right time to the right roles, balancing the security requirements with the needs of the business and their objectives.
  • Champion and drive continual improvement in the maturity of HMRC security culture, pro-actively collaborating with and influencing senior managers across HMRC business areas to gain top down buy in for Security Culture, Education and Awareness activities across HMRC and VOA.
  • As a Business owner and key stakeholder, work in partnership with Enterprise Security Programme to oversee the procurement, implementation and management of new, innovative digital platforms and products that improve the delivery of Security Education and Awareness within HMRC where appropriate and/or work in partnership with other areas of HMRC business to embed products within their business and products.
  • Work in partnership with the Enterprise Security Programme to transform and automate how HMRC Security monitors the departments security culture posture in an agile way enabling more effective, prioritised and targeted responses.
  • Working in partnership with Enterprise Security Programme, lead the establishment and maintenance of positive vendor and stakeholder relationships to ensure new technologies and products are embedded as business as usual activities with effective governance, budgetary management, evaluation and compliance regimes in place as appropriate.
  • Work in partnership with Chief Data Officer and the Office of the Data Protection Officer to maximise the impact of the Data Protection and Security interventions.
  • Build and maximise relationships across the Public and Private Sector enabling HMRC to be a pioneer in Security Culture Management and Innovation.
  • Represent HMRC and play a pro-active role, influencing and shaping Security Culture initiatives cross-government working with Government Security Group, NTAs, Security Education and Awareness Centre (SEAC); ensuring that HMRC CEA utilises and shares best practice and to ensure value for money.
  • Lead, motivate, develop and appraise a small team applying a consistent vision, energy and drive that motivates the team to meet business objectives, setting them in the context of wider security and Departmental objectives. Pro-actively cultivate talent and foster an inclusive, diverse and motivated workforce, while building the right culture to deliver a customer-centric, effective, coherent and continuously-improving security organisation. Lead and manage others to achieve an inclusive culture and the specific goals outlined by HMRC’s and the relevant profession’s diversity and inclusion strategy. Create and champion an environment of continuous improvement across the team, where learning from feedback, security risks, events, incidents, investigations and trends becomes integral to business design and processes.
  • Being a leadership role model for the Government security community and modelling Civil Service values to foster and develop the profession across government. Acting as a security professional, championing and sharing best practice through the community and embedding and championing government security culture within the department. Work in strong partnership with peers across HMRC, the intelligence agencies and other government departments, and personally create the environment for joint successes.

Person specification

The successful candidate will need to demonstrate the following skills and experience as a minimum against the following Essential Criteria:

  • Experience of setting direction and meeting strategic objectives through the development of high-level strategies and plans aligned to business objectives.
  • Ability to gather and use data to evaluate and improve performance.
  • Experience of building strong working relationships with senior stakeholders and influencing strategic direction.
  • Ability to influence senior stakeholders whilst understanding their concerns and needs.

Desirable:

  • Experience of delivering successful culture and awareness programmes of activity where the outcomes have influenced organisational culture and behaviours in a large organisation.
  • Ability to work collaboratively across business areas and networks, supporting the joint development of concise, compelling and realistic strategies with clear outcomes.
  • Experience in coaching and developing staff to grow capability and ensure team members are equipped with the skills and knowledge to effectively undertake their job roles.
  • Experience of working effectively with managed suppliers and vendors.
  • Background in either cyber, personnel, physical or information security.
  • Experience of budgetary, risk and/or project management, with the ability to manage and maintain a complex programme of initiatives.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Leadership
  • Seeing the Big Picture
  • Communicating and Influencing
  • Managing a Quality Service
Alongside your salary of £64,693, HM Revenue and Customs contributes £6,757 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.
  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • Civil Service pension with an average employer contribution of 27%

DIO – Ministry of Defence Guard Service – Security Officer Shift Worker

Abbey Wood, Bristol, BS34 8JH; Northleigh House, Lime Kiln Close, Bristol, BS34 8SU

Job summary

Join the Defence Infrastructure Organisation (DIO) and have a future that matters: Be proud; Be challenged; Be unique.

Job description

The Challenge

Do you want to join the 2021 Government Security team of the year and be part of our Gold Standard security service?

The Ministry of Defence Guard Service (MGS) provides high quality security services at approximately 100 MOD sites across Great Britain. The MGS has guarded the Defence Estate for over 25 years including high profile locations such as MOD Main Building in London and His Majesty’s Naval Bases at Portsmouth, Devonport and the Clyde. We provide access control, military working dogs, control room operations and other security services. We play a vital role supporting the Defence Mission and work to protect the defence estate and personnel from crime, terrorism, espionage and sabotage threats.

The MGS is part of the Defence Infrastructure Organisation (DIO) and employs over 2,500 staff. MGS Officers are often the first point of contact with the MOD for employees, visitors and contractors and we pride ourselves on our professional, customer-focused culture.

All our Security Officers are required to have excellent customer service skills and must be willing to go above and beyond to support security operations across the defence estate. Due to the high profile and strategic locations of the sites we guard, it is essential our Security Officers have a strong work ethic, are able to work as part of a team, are observant to threats and are capable to challenge and de-escalate difficult situations if required. We also require our Security Officers to have good written and verbal communication skills. Our Officers must have resilience and remain positive and friendly in all weather conditions and on all occasions.

We provide our staff with a market leading salary, excellent sickness benefits, together with a defined benefit civil service pension. Free full uniform will be provided.

We are a growing organisation with opportunities for good quality staff to progress their security careers.

The MGS holds the Committed to Equality Gold Standard and we positively encourage applications from all under-represented communities and from all types of working backgrounds.

See more information about the MGS, please read the candidate pack and watch our Security Officer YouTube video https://youtu.be/nzSK9OPOoDI

About MGS

The Ministry of Defence Guard Service (MGS) is a professionally qualified body of Civil Servants who provide unarmed guarding services at approximately 100 MOD sites across Great Britain. The MGS has guarded the Defence Estate for over 25 years including high profile locations such as MOD Main Building in London and His Majesty’s Naval Bases at Portsmouth, Devonport and the Clyde. The MGS plays a vital role supporting the Defence Mission and works closely with its security partners.

The MGS is part of the Defence Infrastructure Organisation (DIO) and  employs over 2,500 operational and support staff. The MGS is managed by a Head Office team, dispersed strategically around the country.

MGS officers are very often the first point of contact with the MOD for employees, visitors and contractors and we pride ourselves on a customer-focused culture, working to DIO’s Values as well as our own core values of honesty, integrity, professionalism and efficiency.

We are passionate about the services we deliver and work hard to keep pace with developments in the security industry, as we seek to be the unarmed guarding provider of choice. The MGS holds the Committed to Equality Gold Standard and we positively encourage applications from all under-represented communities.

Person specification

Main Responsibilities

The key duties of a Security Officer are as follows.

Please note that these duties can vary from site to site.

  • Controlling vehicular and pedestrian access and exit to/from site
  • Issue of passes using site IT systems
  • Reporting of environmental issues
  • Issue and receipt of keys
  • Patrolling on foot and in a vehicle
  • Searching of vehicles, baggage, personnel, buildings and open areas
  • Escorting visitors
  • Traffic management
  • Checking identity on site (ad hoc)
  • Writing reports on breaches of security or defects and maintaining daily logs
  • Referral of complaints
  • Reporting MGS infrastructure defects
  • Dealing with demonstrators and intruders as directed by those holding operational control
  • Safeguarding classified information and material
  • Cooperating with other security providers
  • Collaborating with emergency services and invoking emergency procedures
  • Operating and monitoring security systems; CCTV and alarms etc
  • Operating and communicating effectively over the telephone and/or radio
  • Reporting safety hazards and accidents in accordance with current instructions
  • Carrying out, if required, initial action at the scene of any incident
  • Other tasks commensurate with the grade

Desirable Experience & Skills

A background, qualification or interest in the delivery of site security and/or customer service will be an advantage.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

Travel Requirements

Where close area working arrangements are in place staff may be required to attend other sites within their travel to work area (one hour from their home) on a detached duty basis.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Leadership
  • Managing a Quality Service
  • Communicating and Influencing

We enable our people to work at the right place, with the right people, at the right time.

We believe that if we look after our people, they will be passionate about delivering great things for our customers.

The MOD Discover My Benefits page lists the full set of benefits. Some of the many benefits you will receive include:

  • Civil Service pension with an average employer contribution of 27%
  • Free Uniform
  • 25 days (215 hours) annual leave rising (1 day per year, 8.6 hours) to 30 days (258 hours) upon completion of 5 years’ service
  • Ability to roll over up to 10 days (86 hours) annual leave per year
  • Minimum of 15 Days Special Leave in a rolling 12-month period to for volunteer military or emergency service reserve commitments
  • Special Paid Leave for volunteering up to 6 days a year
  • Enhanced parental leave
  • Employee Assistance Programme to support your wellbeing
  • Most sites have good travel links with free car parking; many also have other facilities such as a Sports & Social Club, Gym and / or site shops
  • The possibility to gain a financial in-year reward after successful completion of six months probation and a further in-year reward after your 12 month anniversary and throughout your career with the MGS.

DIO – Ministry of Defence Guard Service – Security Officer Day Worker

RAF Lakenheath, Brandon, Suffolk, IP27 9PN

Job summary

Join the Defence Infrastructure Organisation (DIO) and have a future that matters: Be proud; Be challenged; Be unique.

Job description

The Challenge

Do you want to join the 2021 Government Security team of the year and be part of our Gold Standard security service?

The Ministry of Defence Guard Service (MGS) provides high quality security services at approximately 100 MOD sites across Great Britain. The MGS has guarded the Defence Estate for over 25 years including high profile locations such as MOD Main Building in London and His Majesty’s Naval Bases at Portsmouth, Devonport and the Clyde. We provide access control, military working dogs, control room operations and other security services. We play a vital role supporting the Defence Mission and work to protect the defence estate and personnel from crime, terrorism, espionage and sabotage threats.

The MGS is part of the Defence Infrastructure Organisation (DIO) and employs over 2,500 staff. MGS Officers are often the first point of contact with the MOD for employees, visitors and contractors and we pride ourselves on our professional, customer-focused culture.

All our Security Officers are required to have excellent customer service skills and must be willing to go above and beyond to support security operations across the defence estate. Due to the high profile and strategic locations of the sites we guard, it is essential our Security Officers have a strong work ethic, are able to work as part of a team, are observant to threats and are capable to challenge and de-escalate difficult situations if required. We also require our Security Officers to have good written and verbal communication skills. Our Officers must have resilience and remain positive and friendly in all weather conditions and on all occasions.

We provide our staff with a market leading salary, excellent sickness benefits, together with a defined benefit civil service pension. Free full uniform will be provided.

We are a growing organisation with opportunities for good quality staff to progress their security careers.

The MGS holds the Committed to Equality Gold Standard and we positively encourage applications from all under-represented communities and from all types of working backgrounds.

See more information about the MGS, please read the candidate pack and watch our Security Officer YouTube video https://youtu.be/nzSK9OPOoDI

About MGS

The Ministry of Defence Guard Service (MGS) is a professionally qualified body of Civil Servants who provide unarmed guarding services at approximately 100 MOD sites across Great Britain. The MGS has guarded the Defence Estate for over 25 years including high profile locations such as MOD Main Building in London and His Majesty’s Naval Bases at Portsmouth, Devonport and the Clyde. The MGS plays a vital role supporting the Defence Mission and works closely with its security partners.

The MGS is part of the Defence Infrastructure Organisation (DIO) and  employs over 2,500 operational and support staff. The MGS is managed by a Head Office team, dispersed strategically around the country.

MGS officers are very often the first point of contact with the MOD for employees, visitors and contractors and we pride ourselves on a customer-focused culture, working to DIO’s Values as well as our own core values of honesty, integrity, professionalism and efficiency.

We are passionate about the services we deliver and work hard to keep pace with developments in the security industry, as we seek to be the unarmed guarding provider of choice. The MGS holds the Committed to Equality Gold Standard and we positively encourage applications from all under-represented communities.

Person specification

Main Responsibilities

The key duties of a Security Officer are as follows.

Please note that these duties can vary from site to site.

  • Controlling vehicular and pedestrian access and exit to/from site
  • Issue of passes using site IT systems
  • Reporting of environmental issues
  • Issue and receipt of keys
  • Patrolling on foot and in a vehicle
  • Searching of vehicles, baggage, personnel, buildings and open areas
  • Escorting visitors
  • Traffic management
  • Checking identity on site (ad hoc)
  • Writing reports on breaches of security or defects and maintaining daily logs
  • Referral of complaints
  • Reporting MGS infrastructure defects
  • Dealing with demonstrators and intruders as directed by those holding operational control
  • Safeguarding classified information and material
  • Cooperating with other security providers
  • Collaborating with emergency services and invoking emergency procedures
  • Operating and monitoring security systems; CCTV and alarms etc
  • Operating and communicating effectively over the telephone and/or radio
  • Reporting safety hazards and accidents in accordance with current instructions
  • Carrying out, if required, initial action at the scene of any incident
  • Other tasks commensurate with the grade

Desirable Experience & Skills

A background, qualification or interest in the delivery of site security and/or customer service will be an advantage.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

Travel Requirements

Where close area working arrangements are in place staff may be required to attend other sites within their travel to work area (one hour from their home) on a detached duty basis.

Licences

Full UK Driving Licence required due to close area working.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Leadership
  • Managing a Quality Service
  • Communicating and Influencing

We enable our people to work at the right place, with the right people, at the right time.

We believe that if we look after our people, they will be passionate about delivering great things for our customers.

The MOD Discover My Benefits page lists the full set of benefits. Some of the many benefits you will receive include:

  • Civil Service pension with an average employer contribution of 27%
  • Free Uniform
  • 25 days (215 hours) annual leave rising (1 day per year, 8.6 hours) to 30 days (258 hours) upon completion of 5 years’ service
  • Ability to roll over up to 10 days (86 hours) annual leave per year
  • Minimum of 15 Days Special Leave in a rolling 12-month period to for volunteer military or emergency service reserve commitments
  • Special Paid Leave for volunteering up to 6 days a year
  • Enhanced parental leave
  • Employee Assistance Programme to support your wellbeing
  • Most sites have good travel links with free car parking; many also have other facilities such as a Sports & Social Club, Gym and / or site shops
  • The possibility to gain a financial in-year reward after successful completion of six months probation and a further in-year reward after your 12 month anniversary and throughout your career with the MGS.

Site Security Manager

Job Description

Do you want to work for a leading employer who excels in security and client excellence, A business that cares about sustainability and is committed to the future of our planet.

We are an employer that lives by our core values and delivers on our goals.

In this role you will work in true partnership with our client, they want to be first in class with their security provision and are truly invested in making it happen.

Opportunities like this don’t come up often, so, apply now and change your future!

We are recruiting for a Site Security Manager to support one of our key Global Clients in providing best-in-class security services.

Our client is a trail blazer in sustainable technologies, using pioneering and scientific knowledge to maximise the efficiency of our planet’s natural resources. With such an innovative and forward-thinking client, we are looking for a Site Security Manager who can push boundaries, challenge, and think innovatively in order to ensure that we provide exceptional service and added value wherever possible.

Working with and across multiple internal and client stakeholders in the UK and at times globally the Site Security Manager will be responsible for the development and execution of client excellence – implementing solutions enabling efficiency programmes, growing and strategically developing a strong partnership and network at all levels.

The Site Security Manager works at a senior level engaging with the client on a regular basis. You will be a tactical leader, accountable for driving and implementing projects through to their satisfactory completion, on time, on budget and against pre-defined objectives.

You will lead a team of supervisors and security officers, ensuring appropriate standards of performance, conduct and behaviour are always displayed, motivating and encouraging the team, as well as setting strong moral and ethical standards.

Additional Information

Reporting to the Key Accounts Director

Essential Skills

To be successful in this role, you should:

  • Lead by example and be able to demonstrate Securitas’ cultural values of Integrity, Vigilance and Helpfulness. 
  • Have a passion for providing advice and solutions to improve culture, process and infrastructure throughout the client business
  • Be a true relationship builder with the willingness to be a team player.
  • Data driven with a desire to review and evolve to get the best results possible
  • An innovator who is willing to challenge the status quo
  • Have a genuine interest in Health & Safety and how it impacts everyone around us
  • Be a promoter of positive change with the drive and focus to implement new methods of working.

·          

    •  

You will need to have:

  • Strong Security Supervisory experience in a corporate or manufacturing environment
  • SIA License
  • Excellent communication skills

Desired Skills

It would be great if you also had:

  • Security/Risk Management Qualifications (or working towards)
  • IOSH qualification  

But if not we could support you in this in the future

About Company

Securitas Benefits: 

  • Company pension and life assurance scheme
  • Wellness advice and support
  • Cycle to Work Scheme, car lease and new car purchasing schemes 
  • Employee discounts and cashback savings across hundreds of your favourite high street brands, gyms, online shopping, holidays, days out, cars and even household appliances!
  • C&G, ILM and Highfield accredited training program for professional and personal development.

IntegrityVigilance, and Helpfulness are the core values that Securitas is built on to shape a long-term, financially successful enterprise for our customers, employees, and shareholders.

With roots dating back to 1934, Securitas is one of the largest security service organisations in the world. We are a company that offer career progression and development, providing access to training and the ability to gain professionally recognised qualifications.

Securitas is an all-inclusive employer, and we encourage individuality within our company. If you want to know more about why Securitas is the world’s leading security group, and our continuing work in the diversity & inclusion space, please visit: www.securitas.uk.com/en-GB/ 

Join the Securitas Team today!

Defence Digital – Assistant Head – Cyber Risk Management

MOD Main Building, Whitehall, London SW1A 2HB

Job summary

Are you ready to work in one of the most interesting cyber security environments and share your experience to support national security?

Cyber security plays an integral role in protecting the UK against external and internal threats, acting as a deterrence to ensure that our Armed Forces have the strong cyber defences they need.

The Cyber Defence and Risk (CyDR) team is at the forefront of Cyber Security and Information Technology within Defence and is responsible for enabling Defence through the provision of specialist assurance and cyber security services across UK Defence, including industry partners, other Government Departments and our international allies.

CyDR sits within the Defence Digital team who provide digital and technology services to our Armed Forces.  Defence Digital operates at scale, with an annual budget in excess of £2Bn and a diverse team of 2,500 colleagues, it aims to make our Armed Forces some of the most technologically advanced in the world.

With a fantastic growing team of military and civilian staff operating across the UK, it is a great time to be a cyber security professional in the Ministry of Defence.

If you can see yourself contributing to the world of CyDR the next chapter of your career may be with us!

This position is advertised at 37 hours per week

Job description

The Assistant Head – Cyber Risk Management position sits within the Governance, Risk and Compliance (GRC) area within CyDR directorate in Defence Digital. We develop and maintain a wider understanding of cyber risks and capabilities, across Defence’s complex and challenging environments and identify possible gaps and issues to inform key defence programmes on how to mitigate these and understand how the resulting activity will help to reduce risks.

The role will require identifying, understanding and mitigating cyber-related risks and provides risk or service owners with advice, to help them make well informed risk-based decisions.

Defence Digital’s Cyber Defence & Risk Directorate (CyDR) provides leadership across defence to ensure threats, advised by DI and other Gov Agencies, are understood and that explicit risks are identified and translated into appropriate mitigation. 

This position will lead a team which will develop and maintain a wider understanding of cyber risks and capabilities, across Defence’s complex and challenging environments. The role is to identify possible gaps and issues to help key Defence programmes mitigate issues and understand how the resulting activity will help to reduce risks. It provides upward reporting and briefings on cyber activity and risk assessments, to enable seniors (including the Defence Board) to make informed investment decisions.

This role is key to management and oversight of Defence’s Cyber Risks, including cyber criticalities driven via engagement with the Cabinet Office and enabling other key stakeholders to reduce and understand Defence’s overarching Cyber Risk.

We will offer excellent learning and development opportunities tailored to your role and beyond. Whilst in post, you’ll be able to gain industry recognised qualifications and we’ll support you throughout the process.

A Recruitment and Retention Allowance (RRA) of up to £9k per annum may be payable with this post, paid in increments upon reaching the required levels of competence.

You’ll also be able to take advantage of our excellent benefits package, including flexible working, generous leave allowance, great discount services and a market-leading Civil Service pension.

The Cyber Risk Management team has exciting plans for growth, so now is a great time to join us and be part of our journey!

Person specification

The post holder is expected to:

  • Independently undertake risk management activities within a given area of practice or expertise, within an established security and risk management governance structure


  • Lead the analysis and derivation of business-supporting security needs, undertake Cyber Security related risk assessments, conduct tailored threat assessment and other risk management activities, and ensure activities are consistent with applicable regulations and legislation


  • Provide tailored advice to a range of stakeholders on how to remedy identified risks, by proportionately applying security capabilities, using published guidance, standards and drawing on a range of experts, as well as personal expertise


  • Provide expert security advice that highlights Cyber Security related risks, so risk or service owners can make well-informed and auditable decisions

More specifically:

  • Lead, on behalf of Defence, to accurately report on the Defence Board’s strategic cyber resilience risk across Defence.


  • Lead and oversee the analysis of mitigation plans for cyber risks held across defence, building knowledge of common themes and identifying gaps. Analyse risk response plans with a view to identifying gaps, reporting accordingly.


  • Ensure that analytical findings are reported to stakeholders, including into policy branches, as well as into the programme assurance process.


  • Engage with all key stakeholders involved in cyber risk management, building the community of interest and promoting cyber risk knowledge sharing. Work with Cyber Risk Management (CRM) partners as part of the Cyber Security Operations Capability (CSOC) in the pursuit of the above objectives and in the interest of the broader aims of CRM.

We are committed to encouraging and enabling our staff to develop in and above their role and we will support you in undertaking further learning and development opportunities, within your designated field and beyond. Wherever possible, we will provide upskill learning options and further training to support your continuous professional development.

Person Specification

If you have the following knowledge, skills and experience, we would love to hear from you!

We would expect to see some previous experience in Cyber Security governance and risk management, threat assessment and/or information risk management/assurance and ideally you’ll have the following skills:

  • The ability to build strong working-relationships
  • Great communication skills, both written and verbal and able to converse at a wide variety of levels
  • Able to consolidate data and produce and present reports
  • Able to build, lead and maintain high performing teams, both technical and non-technical
  • The ability to support a team, as well as form effective partnerships across different organisations.
  • The ability to quickly assess information and make recommendations.

Qualifications: A degree in Cyber Security or a similar subject would be desirable but your experience is key and if you have any of the following industry qualifications that would great. You’ll need to have the motivation and desire to continue to learn and develop and we’ll provide opportunities to gain these in post:

  • Certified Information Systems Security Professional (CISSP)
  • Certificate in Information Security Management Principles (CISMP)
  • Certificate in Information Security Management (CISM)
  • Certified in Risk and Information Systems Control
  • Certified Cyber Professional (CCP)

Dependent on the business need, there will be a requirement to travel to meetings within the UK (or potentially occasional overseas visits).

At certain times and dependent on the priorities of the role, this job role may be suitable for hybrid working, which is an informal, non-contractual and voluntary arrangement, blending a balance of attendance in the workplace (your permanent duty station, which is based on business assessment of where the work is best done) and working from home as a personal choice (if the role is suitable for this).

If not already held, the successful candidate will be required to undergo DV clearance. This position is open to sole UK nationals only.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Leadership
  • Seeing the Big Picture
  • Making Effective Decisions
  • Communicating and Influencing
  • Working Together
  • Delivering at Pace

Technical skills

We’ll assess you against these technical skills during the selection process:

  • Information risk assessment and risk management
Alongside your salary of £56,530, Ministry of Defence contributes £15,263 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.
  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • Civil Service pension with an average employer contribution of 27%
  • Family Friendly – Maternity, Paternity and Adoption Leave.
  • A wide range of discounts – Defence Discount Service, Civil Service societies for Sports and Leisure, Healthcare, Insurance, Motoring, company discounts with Virgin, Vodafone, and Microsoft Office.
  • 5 days per year Learning & Development
  • In year rewards and ‘thank you’ schemes.
  • Flexible working.
  • Generous leave allocations.
  • Please see Benefits Leaflet for more detail

Senior Business Support Officer

*London, Bristol, Warrington, Birmingham, Belfast, Slough, Leicester, Normanton(Calder), Gartcosh, Crawley, Gillingham(Kent) & Exeter – *Under the NCA Estates Strategy, the London office is part of a planned relocation to a new NCA HQ in Stratford, London. Relocation is expected to take place in 2025. If you are successful for a London role, please be aware that your post will be relocated.

Job summary

Serious and organised crime may feel far removed from our everyday lives, but it kills more people than all other national security threats combined. The NCA sits at the heart of the UK’s response.

We tackle those that pose the greatest risk to our safety and security. We operate proactively at the high end of high risk, undertaking investigations to bring offenders to justice.

The NCA has a wide remit and we are looking for committed individuals to join us in a Business Support capacity, to provide vital administrative and professional expertise across all departments in the NCA.

There are business support roles within our operational and capabilities functions.


Applicants will be considered for business support roles in its broadest sense across the Agency, but we appreciate that candidates will have preferences in terms of the sorts of areas that they would like to support, and in deed that they may bring qualifications and experience that may make them particularly suitable for some positions. The location and preferences available are clearly set out in the Application Process section should you choose to specify.

Job description

To provide an efficient support service to National Crime Agency operations, corporate and service functions, programmes or projects, contributing towards the successful delivery of business objectives across the organisation.

***All NCA officers must hold SC Enhanced upon entry as a minimum. To meet the National Security Vetting requirements for this role you will need to have resided in the UK for a minimum of 3 out of the past 5 years. For more information please see the Candidate information Pack***

Person specification

As a Senior Business Support Officer in an operational environment you could be assigned of the following operational teams:


Investigations, Intelligence, Threat Leadership, Safe Guarding, Operational Standards, Cyber Crime & Financial Investigations. We have a wide variety of business support opportunities within our Capabilities function, which are Human Resources, Corporate Business Services (CBS), Corporate Strategy and Performance, Transformation & Digital Data and Technology (DDaT).

Your responsibilities will include:

  • To manage and lead a team responsible for providing business support and governance to operations, corporate and central functions, and contribute towards the achievement of the strategic objectives of the NCA.
  • To develop, implement and improve core delivery functions and support services and support the development and implementation of strategy and policy.
  •  Manage projects, resources, programmes, planning activities to ensure work is completed within agreed timescales/budgets and quality standards, in line with NCA policy.
  • Develop and manage high level relationships with key partners to ensure productive collaborative working.
  • Manage change activity and communicate proposed changes with staff and stakeholders.
  • Manage the quality, secure handling and dissemination of data/ information and develop policy, reports, procedures and manage data systems across business area.
  • Manage/coach and develop staff


You may be expected to work directly or indirectly in tackling child sexual exploitation and abuse. This may involve exposure to child sexual abuse images and material. All officers working on or supporting this type of operational activity will undergo a psychological assessment on taking up the role and at regular intervals once in post.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Leadership
  • Managing a Quality Service

Technical skills

We’ll assess you against these technical skills during the selection process:

  • Demonstrate an ability to make decisions which meet business needs and customer requirements.
  • Demonstrate an ability to encourage and initiate problem solving and ability to manage change.
  • Experience of adapting communication styles for different audiences
  • Experience of working to tight deadlines in a fast paced environment
Alongside your salary of £38,642, National Crime Agency contributes £10,433 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.

Whatever your role, we take your career and development seriously, and want to enable you to build a really successful career with the Agency and wider Civil Service.

If you are an active police pension member immediately prior to joining the NCA, you can continue your membership throughout your employment with us as if you were a serving police officer. If you do remain an active member and subsequently return to a police force, you should be able to continue your membership there too.

All officers in the NCA are members of the UK Civil Service. You will be eligible for:

  • Civil Service pension scheme
  • 26 days annual leave rising to 31 on completion of 5 years continuous service
  • Training and development opportunities
  • Cycle2work scheme

We take the welfare of NCA officers very seriously. All staff have access to Occupational Health services and there are a number of staff representative groups. We also have a range of sporting and other activities on offer.

We can provide flexible working arrangements if the role in question is suitable. These include flexi-time, job sharing and compressed hours (working contracted hours over a shorter period).

GSG Cyber Operations Vulnerabilities Lead

London

Job summary

The UK government processes a mass of sensitive data, provides a critical service to the public, operates an extensive and complex IT estate, and faces a significant and growing cyber threat. In response we invest in a well funded and innovative cyber-security programme and we are looking for talented individuals who can bring a range of skills and experience to the department.

The Cyber Directorate within GSG(also known as GSG Cyber) sits within Government Security Group(GSG) and covers all aspects of Defensive Cyber Security for Government from strategy, policy and standards to the operational deliverables of incident, risk, threat intelligence and vulnerability management. We manage investment from the National Cyber Security Programme, outreach and engagement across government and the wider public sector among much else.

The Cyber Operations team provides GSG with reporting cyber operational risk across the government sector, working closely with the Cabinet Office National Security team and the NCSC. The team is responsible for coordinating and understanding operational cyber risk across government.

If you’re passionate about protecting government, want to be part of a security evolution, have a grounding in cyber security and want to learn more, this is the team for you. Come and help make government stronger.

Job description

As the Cyber Operations vulnerabilities manager within GSG you will help protect HMG against systemic vulnerabilities.

The Cyber Operations vulnerabilities manager plays a key role in defining cross government risk and works closely with our threats role to deliver the operational cyber risk picture.

The vulnerability manager will triage vulnerabilities by relevance and criticality to the organisation.The post will work closely with NCSC and CDDO on the identification of critical vulnerabilities which impact government and management of these vulnerabilities across government prioritising, drafting and promulgating protective advice.

You will be responsible for coordinating and understanding vulnerabilities which significantly impact cross government operational capability.. 
You will play a significant role in developing capabilities to increase government awareness of its cyber vulnerabilities such as the expansion of the NCSC’s Vulnerability reporting service to secure government digital infrastructure.

As part of the wider cyber operations team, you will also support the delivery of the Government Cyber Coordination Centre(GCCC) by driving collaboration across the vulnerability management community, working with NCSC and CDDO in developing innovative ways to work with government data and processes, in support of the Government Cyber Security Strategy(GCSS) and the requirement to “Defend as One.”

Successful candidates must meet the security requirements before they can be appointed. The level of security needed is Security Check (SC) but must be willing to undergo Developed Vetting (DV) clearance whilst in post where necessary.

Responsibilities 

  • Work with NCSC on operationalising and managing a cross government Vulnerability Reporting Service (VRS) to ensure that critical notifications are passed in a timely manner to government departments and develop analytical processes and lead the VRS community driving uptake of the vulnerability reporting service across government departments.
  • Working with the Cyber Operations team and closely with NCSC and CDDO on the identification and management of new vulnerabilities
    Create and maintain a process for management of new vulnerabilities which significantly impact the government, and work with NCSC on advice and classification of vulnerabilities.
  • Play a key role in defining cross government risk and work closely with threat intel colleagues to deliver the operational cyber risk picture.
    Management of critical vulnerabilities which impact government, maintaining an active presence in government information sharing spaces ie Slack, CISP or Government Websites.
  • Support wider GSG Cyber Directorate teams providing SME guidance on cyber vulnerabilities.
  • Translate vulnerability management best practice across government through policies, procedures and guidelines. Champion standards and best practice across the security community.
  • The role will also act to support GSG’s cyber incident response function as and when required.

Person specification

Essential Skills/Experience

Experience of working in cyber security, ideally within a SOC/Operations environment.

Knowledge of application, infrastructure and networking security and systems.

Communicate effectively at all levels and present technical information to senior stakeholders in concise business focused language, supplementing own knowledge with research where needed.

Producing well-written, well-structured, timely and impactful products and notifications in clear English, with minimal support that meet the requirements of stakeholders.

Desirable Skills/Experience

  • Experience of working in National Security is desirable
  • Engagement in information sharing forums(internal and external) to enhance understanding of vulnerabilities within HMG.
  • Experience of working with a range of stakeholders is desirable
  • Developed knowledge and understanding of approaches and tooling for performing vulnerability assessment against large and complex infrastructure.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Communicating and Influencing
  • Delivering at Pace
  • Seeing the Big Picture

Technical skills

We’ll assess you against these technical skills during the selection process:

  • Candidates will be asked to do a short (5 -10 minutes) presentation on cyber security challenges facing Government departments. Further details will be provided to candidates invited to interview.
  • Learning and development tailored to your role.
  • An environment with flexible working options.
  • A culture encouraging inclusion and diversity.
  • Civil Service Pension which provides an attractive pension, benefits for dependants and average employer contributions of 27%.
  • A minimum of 25 days of paid annual leave, increasing by one day per year up to a maximum of 30.

Senior Data Engineer (Ref: 76031)

East Midlands (England), East of England, London (region), North East England, North West England, Scotland, South East England, South West England, Wales, West Midlands (England), Yorkshire and the Humber

Job summary

Please refer to Job Description

Job description

We encourage applications from people from all backgrounds and aim to have a workforce that represents the wider society that we serve. We pride ourselves on being an employer of choice. We champion diversity, inclusion and wellbeing and aim to create a workplace where everyone feels valued and a sense of belonging. To find out more about how we do this visit: https://www.gov.uk/government/organisations/ministry-of-justice/about/equality-and-diversity.

His Majesty’s Courts and Tribunals Service 

Directorate:  HMCTS Finance, Governance and Performance (within Analysis and Performance)
Job Title:   Senior Data Engineer
Salary:  
£37,683 – £41,506 (National) which may include an additional allowance of up to £15,317
£43,647 – £48,067 (London) which may include an additional allowance of up to £13,753
Number of Jobs: 2
Detail of Reserve List: 12 Months
Pay Band:  SEO 
Post Type: Permanent
Working Pattern: Full Time
Base location:  National (hubs in London, Manchester, Birmingham, Leeds. Other major HMCTS locations will be considered.

Overview 
 
His Majesty’s Court and Tribunals Service is an agency of the Ministry of Justice and provides the supporting administration for the judiciary across England and Wales along with some Tribunals in Scotland.  It delivers services to the public directly in court and tribunal buildings, remotely via business centres and some limited services via the internet. 

HMCTS has embarked on a challenging modernisation programme with the vision to modernise and upgrade our justice system so that it works even better for everyone, from judges and legal professionals, to witnesses, litigants, and the vulnerable victims of crime. This will help consolidate the UK’s position at the forefront of an increasingly competitive international legal market as well as ensuring access to justice for all. This is an exciting time to join the organization and be part of a programme making a real difference.
 
For more information about our digital transformation, watch the Justice Matters video to see the benefits this £1bn investment is delivering to our customers:  https://youtu.be/3_xDMTQ6DJQ 
 
The Analysis & Performance team plays a pivotal role in supporting a whole range of senior leaders across the business through reporting, analysis and insights. Our work supports the organisation’s overall strategy and empowers senior leaders to make strategic, data driven business decisions. In December 2021 we published our Data Strategy, setting out HMCTS’s commitment to becoming a data driven organisation.

HMCTS Data Strategy (publishing.service.gov.uk)
 
As part of this strategy, HMCTS has invested in a cloud-based strategic data platform to transform the ways in which we work with data and enable us to add more value than ever to the organisation and the public. This platform is now technically complete, and we are looking for enthusiastic and motivated individuals to join our team and help us exploit our new technology.

This role will be based in our Data Management and Engineering team responsible for holding, curating, and protecting our data to drive value for our organisation both now and into the future.
 
Job Description

What will the successful candidate be doing?
•    Contribute to the delivery of physical data models and views required for data exploiters to enable visualization of metrics and the provision of insightful analysis for data science projects. 
•    Develop data ingestion and transformation processes for new and existing data sources. 
•    Work with subject matter experts to develop and implement the business rules and definitions underpinning measures, metrics and KPIs. 
•    Collaborate effectively with the operational colleagues across the organisation, internal project teams and other stakeholders to gather, refine and deliver requirements to meet business needs. 
•    Act as technical lead for one or more HMCTS jurisdictions and overall data management framework. 
•    Embed improved ways of working with data across the wider team, including automation of manual tasks and data assurance. 

Essential Criteria

Technical expertise 

•    Experience of ETL and data integration, including exporting data from various source data systems, transforming data against required business rules and data models, or data storage and analysis requirements, and loading data in various storage platforms. 
•    Experience of working with data and databases, ideally involving the development of new and existing data sources in a Data Warehouse environment. 
•    Good understanding of Data Warehouse techniques, including dimensional data modelling and relational database design and concepts (e.g. Kimball).  
•    Strong SQL experience and technical database expertise using relational databases such as Oracle Database & PL-SQL or Microsoft T-SQL. 

Desirable criteria

•    Experience of writing parameterised code in either a programming or scripting language such as PL-SQL or Python/Spark and experienced in delivering metadata driven development processes. 
•    Experience of building pipelines in cloud technologies such as Azure Data Factory/Databricks. 
•    Experience using Python and Apache Spark (Pyspark, Spark SQL). 

Your Development

·    You will have access to a wide range of tools to continually develop and enhance your Data skills, such as: access to Microsoft Azure training courses via our partnership with Microsoft, online training such as DataCamp or Pluralsight, webinars, taught courses, one-to-one coaching and access to a large peer-support network.

Behaviours 

We will assess you against these behaviours (Civil Service Behaviours) during the selection
process: 

•    Changing and Improving 
•    Working Together 
•    Developing Self and Others 
•    Delivering at Pace  
 
Application 
 
We will assess on behaviours and technical skills as listed in the advert. 

CV giving details of your employment history and the role you have played in projects.
Statement of suitability (1,000 words max) outlining how you meet the criteria for the role as described in the Key Responsibilities section above.

For each of the four Success Profile Behaviours please provide a 250-word statement of evidence on how your skills, knowledge and experience meet the behaviour to Level 3 standard.

If we receive high volumes of applications, we will sift only on the lead behaviour of “Changing & Improving”. 
 
Interview 
 
The interview will involve a discussion around the strengths, behaviours & technical skills required for this role. Candidates will also need to prepare a 5-minute verbal presentation (no handouts needed). This will be followed by short follow-up questions. The presentation topic will be sent to candidates before the interview.  

At interview stage there will also be a technical test to assess candidates’ skills in using SQL.

Flexible working options 

HMCTS offers a flexible working system in its offices and hybrid working between office and home is standard across the team. 

 Job Sharing and Reduced Hours 

All applications for job sharing or reduced hours will be treated fairly and on a case-by-case basis in accordance with the MoJ’s flexible working policy and equality policy. 
 
Excess Fares and Relocation Allowances 

This job is not eligible for a relocation allowance, but excess fares may be considered in accordance with MoJ’s excess fares allowance policy. 

Travel
Infrequent travel to attend unit and whole team meetings will be expected. 

DDaT Professional Membership

Please Note: This post aligns to the Digital Data and Technology (DDaT) Data Engineering profession.  This can result in an uplift to the postholders salary and to access this uplift the postholder will need to complete an assessment to demonstrate the required skills for DDaT membership.

Person specification

Please refer to Job Description

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Changing and Improving
  • Working Together
  • Developing Self and Others
  • Delivering at Pace

Technical skills

We’ll assess you against these technical skills during the selection process:

  • Assessment of skills in using SQL.
  • Access to learning and development
  • A working environment that supports a range of flexible working options to enhance your work life balance
  • A working culture which encourages inclusion and diversity
  • Civil Service pension with an average employer contribution of 27%
  • Annual Leave
  • Public Holidays
  • Season Ticket Advance

Higher Data Engineer (Ref: 76025)

East Midlands (England), East of England, London (region), North East England, North West England, Scotland, South East England, South West England, Wales, West Midlands (England), Yorkshire and the Humber

Job summary

This position is based Nationally

Job description

We encourage applications from people from all backgrounds and aim to have a workforce that represents the wider society that we serve. We pride ourselves on being an employer of choice. We champion diversity, inclusion and wellbeing and aim to create a workplace where everyone feels valued and a sense of belonging. To find out more about how we do this visit: https://www.gov.uk/government/organisations/ministry-of-justice/about/equality-and-diversity.

His Majesty’s Courts and Tribunals Service 

Directorate:  HMCTS Finance, Governance and Performance (within Analysis and Performance)
Job Title:   Data Engineer
Salary: 

£31,265 – £34,446 (National) which may include an additional allowance of up to £6,035

£35,405 – £39,000 (London) which may include an additional allowance of up to £6,344

Number of Jobs: 2

Detail of Reserve List: 12 Months

Pay Band:  HEO

Post Type: Permanent

Working Pattern: Full Time

Base location:  National (hubs in London, Manchester, Birmingham, Leeds. Other major HMCTS locations will be considered.

Overview 

His Majesty’s Court and Tribunals Service is an agency of the Ministry of Justice and provides the supporting administration for the judiciary across England and Wales along with some Tribunals in Scotland.  It delivers services to the public directly in court and tribunal buildings, remotely via business centres and some limited services via the internet.

HMCTS has embarked on a challenging modernisation programme with the vision to modernise and upgrade our justice system so that it works even better for everyone, from judges and legal professionals, to witnesses, litigants, and the vulnerable victims of crime. This will help consolidate the UK’s position at the forefront of an increasingly competitive international legal market as well as ensuring access to justice for all. This is an exciting time to join the organization and be part of a programme making a real difference.

For more information about our digital transformation, watch the Justice Matters video to see the benefits this £1bn investment is delivering to our customers:  https://youtu.be/3_xDMTQ6DJQ 

The Analysis & Performance team plays a pivotal role in supporting a whole range of senior leaders across the business through reporting, analysis and insights. Our work supports the organisation’s overall strategy and empowers senior leaders to make strategic, data driven business decisions. In December 2021 we published our Data Strategy, setting out HMCTS’s commitment to becoming a data driven organisation.

HMCTS Data Strategy (publishing.service.gov.uk)

As part of this strategy, HMCTS has invested in a cloud-based strategic data platform to transform the ways in which we work with data and enable us to add more value than ever to the organisation and the public. This platform is now technically complete, and we are looking for enthusiastic and motivated individuals to join our team and help us exploit our new technology.

This role will be based in our Data Management and Engineering team responsible for holding, curating, and protecting our data to drive value for our organisation both now and into the future.

Job Description

What will the successful candidate be doing?

  • Support the delivery of physical data models and views required for data exploiters to enable visualisation of metrics 
  • Support the development of data ingestion and transformation processes for new and existing data sources.
  • Work with subject matter experts to help develop and implement business rules.
  • Assist in ensuring effective collaboration and communication with colleagues from across the organisation, to gather and help deliver requirements to meet business needs.
  • Maintain documentation relating to datasets.
  • Manage processes aimed at assuring data quality.
  • Support the technical lead for one or more HMCTS jurisdictions.
  • Run regular production processes to enable the provision of data outputs.

Essential Criteria

Technical expertise 

  • Some experience of ETL and data integration, including exporting data from various source data systems, transforming data against required business rules and data models, or data storage and analysis requirements and loading data in various storage platforms.
  • Experience of working with new and existing data sources in a Data Warehouse environment.
  • Understanding of Data Warehousing techniques, such as: dimensional data modelling and relational database design and concepts (e.g., Kimball).
  • SQL coding experience.
  • Experience of creating and using data dictionaries.

Desirable criteria

  • Some experience of writing procedural code in either a programming or scripting language such as PL-SQL/T-SQL or Python/Spark and experience in delivering metadata driven development processes.
  • Technical database expertise using relational databases such as Oracle Database or Microsoft SQL Server.
  • Some experience of building pipelines in cloud technologies such as Azure Data Factory/Databricks.
  • Some experience using Python and Apache Spark (PySpark, Spark SQL).
  • Knowledge of data governance principles and processes.

Your Development

  • You will have access to a wide range of tools to continually develop and enhance your Data skills, such as: access to Microsoft Azure training courses via our partnership with Microsoft, online training such as DataCamp or Pluralsight, webinars, taught courses, one-to-one coaching and access to a large peer-support network.

Behaviours 

We will assess you against these behaviours (Civil Service Behaviours) during the selection

process: 

  • Changing and Improving 
  • Working Together 
  • Developing Self and Others 
  • Delivering at Pace  

Application 
 
We will assess on behaviours and technical skills as listed in the advert. 

CV giving details of your employment history and the role you have played in projects.

Statement of suitability (1,000 words max) outlining how you meet the criteria for the role as described in the Key Responsibilities section above.

For each of the four Success Profile Behaviours please provide a 250-word statement of evidence on how your skills, knowledge and experience meet the behaviour to Level 3 standard.

If we receive high volumes of applications, we will sift only on the lead behaviour of “Changing & Improving”. 

Interview 
 
The interview will involve a discussion around the strengths, behaviours & technical skills required for this role. Candidates will also need to prepare a 5-minute verbal presentation (no handouts needed). This will be followed by short follow-up questions. The presentation topic will be sent to candidates before the interview. 

At interview stage there will also be a technical test to assess candidates’ skills in using SQL.

Flexible working options 

HMCTS offers a flexible working system in its offices and hybrid working between office and home is standard across the team.

 Job Sharing and Reduced Hours 

All applications for job sharing or reduced hours will be treated fairly and on a case-by-case basis in accordance with the MoJ’s flexible working policy and equality policy.

Excess Fares and Relocation Allowances 

This job is not eligible for a relocation allowance, but excess fares may be considered in accordance with MoJ’s excess fares allowance policy.

Travel

Infrequent travel to attend unit and whole team meetings will be expected

DDaT Professional Membership

Please Note: This post aligns to the Digital Data and Technology (DDaT) Data Engineering profession.  This can result in an uplift to the postholders salary and to access this uplift the postholder will need to complete an assessment to demonstrate the required skills for DDaT membership.

Person specification

Please refer to Job Description

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Changing and Improving
  • Working Together
  • Developing Self and Others
  • Delivering at Pace

Technical skills

We’ll assess you against these technical skills during the selection process:

  • Demonstration of skills in using SQL
  • Access to learning and development
  • A working environment that supports a range of flexible working options to enhance your work life balance
  • A working culture which encourages inclusion and diversity
  • Civil Service pension with an average employer contribution of 27%
  • Annual Leave
  • Public Holidays
  • Season Ticket Advance

Head of Security Operations

Cardiff, Wales, CF14 3UZ

Job summary

We are looking for an enthusiastic Head of Cyber Security Operations, with great leadership, strong technical skills and a drive to improve the security of our services. You will be responsible for the leadership and strategy of Companies House’s Cyber Security Operations, whilst being hands-on enough to directly work on the analysis and remediation of incidents yourself. You will be user and service focused ensuring that value is delivered through the ongoing protection of delivery pipelines, services and our end-user IT estate. You will be responsible for introducing a strategy for the SecOps Profession and ensuring smooth integration of this profession into broader Companies House Service model.

Companies House leads the way in providing an open and transparent company register.  Our register is searched billions of times a year and estimated that it will be worth over £10 billion to the UK economy, after our Transformation, supporting millions of business decisions every day. Companies House strategy 2020 to 2025. 

Our transformation will create a markedly higher security need and the formation of this role is one of the ways we are preparing for this change. 
 
Come and help us as we embark on a redesign of our digital services and culture.

Find out more about the work we do. Find out more about the services you will be responsible for supporting.

We are currently using a hybrid approach to the way we work. The majority of our digital teams are based in our Cardiff head office. 

At Companies House, hybrid working is about achieving an effective balance between working in the office and working from other appropriate locations. Our approach to hybrid working provides opportunities for you to be adaptable in the way you work so that you can achieve a healthy balance between your work and home life. We currently expect those on hybrid contracts to attend the Cardiff office a minimum of one day a week but the exact degree of choice you have will depend on your role and your day-to-day work activities and should be agreed through discussions with your line manager.

Job description

  • You will manage internal SOC Analysts and the external Cyber Security partner that provides augmented SOC resource.
  • You will be responsible for maintaining and supporting the ongoing operational cyber security of our organisation’s internal and external facing systems. with responsibility for developing our capability in SecOps, shaping the right talent and identifying skills gaps within both the team and the supplier’s capabilities.
  • Implement opportunities to optimise processes; reducing ‘noise’ and best identifying and prioritising alerts. Lead teams of experts in resolving security incidents.
  • Work with IT Services, evaluating and establishing requirements for the implementation of changes by defining Operational Security standards. 
  • You will lead the identification, investigation and resolution of security incidents. Taking accountability of issues that occur and proactively searching for potential solutions ensuring the right actions are taken to investigate, resolve and anticipate future problems. 
  • You will coordinate your teams to investigate problems, implement solutions and take preventive measures and form part of an on-call rota for service continuity.
  • Through the prevention of disruption arising from Cyber Security incidents, support Operational IT colleagues in our collective target of ensuring Operational Continuity to agreed service levels (currently 99.90% availability).
  • Leadership and collaborative working using an inclusive approach to delivery of objectives.
  • Rapid delivery of user centric services whilst focussing on security.
  • Identifying, testing and facilitating the secure adoption of emerging technologies. 
  • Developing the vision, principles and strategy for SecOps practices across the organisation.
  • Cost Centre management with a substantial budget that will be required to be delivered within 1% tolerance.

This is an exciting opportunity, protecting our services and by extension, our users. By helping us to shape our services, you’ll have the opportunity to be at the forefront of digital transformation in government.

Person specification

We are looking for someone with the following: –

  • You ensure the correct implementation of standards and procedures. You can identify capacity issues, stipulating the required changes and instigating these. You know how to initiate remedial action.
  • You can deal with high-impact, complex requests and often ambiguous alerts and warnings. You know how to ensure that detective and preventative controls are applied and managed throughout the delivery lifecycle and on an ongoing basis throughout our Services’ lifespan.
  • You know how to select appropriate design standards, methods and tools and ensure they are applied effectively. You can review the systems designs of others to ensure selection of appropriate monitoring, application of preventative controls and efficient use of resources and the integration of multiple systems and technology so that visibility of these can co-exist within the SIEM and other SOC tooling.
  • You are demonstrably experienced in information security, with a clear specialisation and interest in Security Operations, specifically.
  • You can design, quality-review and quality-assure solutions and services with security controls embedded, specifically engineered as mitigation against security threats as a core part of the solutions and services.
  • You can collaborate with others to review specifications and use these agreed specifications to design, test and document programs using the right standards and tools.
  • You know the direction for future technologies. You can deliver a model to support and maintain future technologies in secure manner. You know how to manage risks and can take preventative action.
  • You understand the difference between user needs and the desires of the user. You can match the detective and preventive controls to the needs of users. You can offer recommendations on the best tools and methods to be used to do so.
  • The ability to credibly handle a serious security incident from identification, through to resolution and enact post-incident enhancements.

About Us
Companies House is an award-winning employer, building brilliant services on cutting edge technology. You’ll join our digital team at a time of transformation and you will be a part of shaping the future of our department. We use Agile methodologies and promote a culture of continuous improvement.







Inclusive and diverse teams are important to us. Wherever we can, we provide opportunities to work part-time, job-share or look for smarter ways of working. We’ll support you to meet other commitments and help you find a better work-life balance. We’re keen to create an environment that works for everyone.

Our aim is to be the best registry in the world achieved through brilliant people working on brilliant systems delivering brilliant services. We are currently delivering an organisation wide transformation programme focussing on a complete redesign of our digital services, target operating model and culture. This change will need different skills, capabilities and mindset where adaptable, bold and curious behaviours are the norm and empowerment is encouraged and utilised.

Companies House values its people, their contributions and has created a real sense of community where people seek to create strong connections. Our commitment to learning and development is exceptional, and we believe passionately in the employee experience with is prevalent through the engagement, wellbeing and development strategies which have resulted in Gold Investors in People and MIND index awards.

We are an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Everyone in Companies House brings something different, and so will you. We are committed to ensuring that we are representative of the citizens that we serve. To fulfill our commitment to recruiting and attracting diverse talent we welcome applications from underrepresented groups.

We encourage professional development, celebrate success and live our values to effect real change.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Changing and Improving
  • Working Together
  • Managing a Quality Service
  • Developing Self and Others

Technical skills

We’ll assess you against these technical skills during the selection process:

  • Knowledge of SIEM and typical SOC tooling
  • Experience involving SIEM and supporting tools
Alongside your salary of £51,000, Companies House contributes £13,770 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.
– Flexible working with no core hours. Work anytime between (6am and 8pm). – Build up to 2.5 days off per month in addition to your annual leave allowance!
– 30 Days Annual Leave, 8 Bank Holidays and 1 Privilege Day.
– Maternity, Adoption and Shared Parental Leave paid at full rate of pay for the 26 weeks of Ordinary Maternity leave, followed by an extra 13 weeks Statutory Maternity Pay and a further 13 weeks leave is also available which is unpaid. We offer 2 weeks statutory paternity leave
– Enrolment into the Civil Service Pension Scheme with a contribution rate averaging 27%.
– 3 Days Volunteering Leave.
– Support for training and certifications with up to 5 days study leave.

We also offer:
– 1 Half Day per week Innovation Time to learn new skills or come up ways to simplify the teams the way of working.

Remote Benefits:
– We will supply a desk, chair, monitor and all the kit you need to work from home in comfort.

Account Visibility

Please confirm you are happy to be listed on the Members List

Yes, please add me to the list No, please hide me from the list