Location
About the job
Job summary
GBS Platforms and Services build, operate and manage, via third-party service providers, a number of back office services, including Recruitment, Learning and Pension platforms. The team also delivers strategic advice and expert technical services within the Shared Service domain across a number of government departments, including leading a number of strategic work streams within the Government Shared Services Strategy.
The role resides within the Platforms and Services directorate but is responsible for information assurance and business continuity services covering the whole of CSHR, GBS and their supply chains, including the provision of the policy, strategic and operational advice and guidance on business continuity and resilience across Government Departments.
Working for the GBS Information Assurance Manager you will be respected in your field and work within a small team of Information Assurance and Data Privacy specialists.
Job description
The Business Continuity Manager is part of the Information Assurance function within Government Business Services (GBS). Reporting to the GBS Information Assurance Manager, the role is responsible for developing and maintaining a Business Continuity Management System (BCMS) for high-volume back office systems and services used across Government.
The team work across a number of specialisms, including but not limited to:
- Information Security Management Systems (ISMS)
- Cyber security compliance, especially to ISO standards most notably 27001 and 22301
- Operational Security oversight and audit
- Business resilience
- Risk management, including suppliers and supply chains
- HMG stakeholder assurance and compliance
- Data Protection/GDPR compliance
- Breach mitigation and reporting
- Critical/Incident planning and management
- CSHR and GBS security culture programs
- Security advice for contracts and information assurance/Security Schedules to contracts
- Migration to cloud platforms (Oracle, SAP, Workday, etc.)
- Embedding Information Assurance in new projects/programmes – ‘security by design’
- Oversee and influence information assurance and business continuity in the development of technology and product roadmaps for shared service platforms
The BCM’s key outputs and deliverables will include:
- Risk Analysis of different functional areas
- Business Impact Analysis
- Business Continuity and Disaster Recovery Plans
- Testing of Business Continuity and Disaster recovery plans
- Effective restoration of key corporate resources and the resumption of critical business processes in the event of a disaster
- Up to date and comprehensive Business Continuity and Disaster Recovery documentation library
- Delivery of improved management information and metrics
Person specification
The successful candidate will be able to demonstrate:-
Essential:
- Experienced Business Continuity Professional with a proven track record in a multi-disciplined environment
- Experience of working in a large complex IT environment
- Experience of Risk and Issue management, governance processes, assurance and reporting
- Experience of conducting risk assessments
- Strong stakeholder management and communication skills, with senior stakeholders and organisations in both the public and private sector
- A self-starter who works well independently with limited supervision
- Ability to manage high workloads and competing deadlines
- Comfortable working with a high degree of ambiguity and changing priorities
- Knowledge of the ISO/NIST suite
Desirable:
- ITIL V3
- Suitable BCI/BSI Business Continuity qualification(s)
- Project and change management experience
- Understanding of how to implement security controls in an enterprise solution
- Experience of managing a service through outsourced contracts
Technical Skills:
The candidate should have:
- The ability to understand security solutions/problems and be able to explain to business users how proposed changes will affect them
- Excellent communication skills to be able to present/demonstrate ideas to key stakeholder groups
- The ability to confidently engage stakeholders, when assessing, defining and justifying needs to arrive at an agreed design.
- An understanding of the CIA triad.
- Ability to identify and pinpoint business opportunities to allow organisations to perform more effectively.
- Experience in Risk and Issue management, governance processes, assurance and reporting.
- A good understanding and application of risk assessments and risk management, ensuring outcomes are aligned with business strategy and service vision – analysing and modelling current and future business landscapes.
- The ability to take a holistic view – Investigate business challenges, problems and opportunities considering all perspectives (people, processes, organisation, information and IT).
- Understands how the digital economy is changing user behaviour and the government landscape.
- Strong stakeholder management and communication skills, with senior stakeholders and organisations in both the public and private sectors.
- Comprehensive experience in implementing/managing/auditing ISO standards most notably 22301 and 27001
- The ability to understand technical solutions/problems and be able to explain to business users how proposed changes will affect them
- The ability to confidently engage stakeholders, when assessing, defining and justifying needs to arrive at an agreed design.
- An understanding of user-centred design practices, to iteratively deliver risk-managed/assessed services to meet end-user needs
- Strong planning ability
- Coordination/delivery of training and experience in building E-Learning content
- High-Quality output and accuracy
- Develop and maintain the BCMS to meet the ISO22301 standard
- Generate and maintain Business Continuity policies and procedures
- Design and coordinate the development, maintenance, and exercising (testing) of the overall business continuity plans for each critical functional area of GBS and ensure that these meet business and regulatory requirements
- Establish business continuity testing methodologies and plans
- Ensure that Business Continuity plans address three major elements of the recovery process
- Emergency Response organisation and procedures for reacting to and coordinating recovery efforts;
- Recovery Support procedures for restoring key organisation resources;
- Business Resumption procedures for the continuation of critical business processes.
- Coordinate the testing of recovery support and business resumption procedures;
- Assure that recovery procedures are effective for the restoration of key corporate resources and for the resumption of critical business processes;
- Conduct business impact analysis and assist in determining critical business processes, assess achievable recovery time objectives, and establish resources required for the successful resumption of business operations during an event;
- Coordinate the efforts of staff members in different functional areas in the development of procedures for the continuity of business processes in a disaster situation;
- Perform risk analysis for business functional areas to identify points of vulnerability and recommend disaster avoidance and reduction strategies;
- Provide guidance to and coordinate the efforts of staff members in the development of recovery procedures for key areas of the organisation;
- Review changes to ensure the effectiveness of the recovery procedures and backup capabilities;
- Develop and maintain standards and procedures for Business Continuity documentation. Maintain a library of recovery support and business resumption procedures;
- Work with other teams and business areas to ensure that as new equipment, facilities, services, and systems are installed that the Business Continuity considerations are addressed;
- Work with central CO teams to ensure Business Continuity priorities are maintained;
- Assist recovery support and business resumption staff during a disaster in the implementation of response and alternate operating strategies;
- Provide Business Continuity support to bids and queries;
- Coordinate ISO and associated audits;
- Act as a coordinator during an emergency situation;
- Provide support to the Information Assurance Managers in relation to audit coordination and support activities;
Any other duties as deemed necessary to achieve department goals.
Behaviours
We’ll assess you against these behaviours during the selection process:
- Changing and Improving
- Communicating and Influencing
- Delivering at Pace
- Making Effective Decisions
- Seeing the Big Picture
Benefits
- Learning and development tailored to your role.
- An environment with flexible working options.
- A culture encouraging inclusion and diversity.
- A Civil Service Pension which provides an attractive pension, benefits for dependants and average employer contributions of 27%.
- A minimum of 25 days of paid annual leave, increasing by one day per year up to a maximum of 30.