Investment Security Advisor

London

Job summary

The National Security Secretariat (NSS) keeps the UK safe, secure and prosperous by bringing together the UK’s national security community, providing high-quality support to the Prime Minister and the National Security Council and maintaining centre-to-centre relationships internationally. Working within the wider Cabinet Secretariat and led by the Prime Minister’s National Security Adviser (NSA), we assist the Prime Minister and the Cabinet in the development, coordination and implementation of its highest priority objectives.

Our overarching strategy is set out in the Integrated Review, which describes the Government’s vision for the UK’s role in the world over the next decade, and the action we will take to 2025.

The NSS value professional and personal development for all of our staff and recognise that a continued focus on learning and development (L&D) will enable us to grow our capability. We are also committed to fostering a culture which welcomes new ideas and fresh perspectives, and supporting diversity and inclusion, including through flexible patterns and ways of working.

We can offer stretching and engaging work to enhance career development and gain highly transferable skills. We expect our staff to rise to new challenges, demonstrating the agility required to respond to urgent and changing events, and to work collaboratively to achieve results both within NSS and across government. A role with the NSS is a real opportunity to impact the lives of our citizens and make a difference every day.

Job description

The role and our team

The National Security and Investment Act 2021, which commenced at the start of January 2022, protects the nation from potential security risks resulting from foreign investment. It bolsters the UK’s status as an attractive place to invest by providing more efficient scrutiny of relevant acquisitions and more certainty and clarity for investors and businesses. 

The Investment Security Unit leads the Government’s screening of foreign investments into UK companies; assessing the risks mergers and acquisitions, investments or the transfer of assets could present to the UK’s national security. With more than a year into delivery of the new National Security and Investment Act (NSIA), the Unit is at the heart of the operational response to changes in the global economy and the balance of power, as it coordinates cross-government responses to protect our capabilities and critical national infrastructure. The Unit is an exciting and diverse place to work, with teams delivering a range of operational, policy, analytical and international activities. Delivery of the legislation remains a Secretary of State top five priority and there is huge interest in this policy area from the Prime Minister and other members of the Cabinet. The Unit is recruiting for roles across its different teams which provide regular opportunities to brief Ministers and Private Office as well as extensive cross-Whitehall engagement.

The Risk Assessment team within the Unit is responsible for leading the cross-Whitehall and intelligence community risk assessment of cases passed on by the Risk Identification and Review team in the Unit. These assessments cover the national security, economic and diplomatic implications of individual investments, identifying remedies to address risks and supporting ministerial decision-making. The Compliance and Enforcement team aims to mitigate national security risks arising from Foreign Direct Investment by: monitoring compliance with the Act; advising the Secretary of State on enforcement action; and supporting the wider ISU in operating the NSI Act.

Person specification

Key responsibilities

Co-ordinating expertise:

You will lead discussions across Government and gather the necessary expertise to assess the risk posed by foreign direct investment. For Compliance and Enforcement roles, you will support ISU colleagues to develop effective remedies that mitigate national security risks, working closely with advisors in other government departments and Legal advisors. For Compliance and Enforcement roles, you will work closely with Legal advisors to respond to instances of non-compliance, develop robust and effective orders and determine how to respond to novel and complex developments in cases.

Analysing information:

You will conduct comprehensive analysis of assessments provided by partners across government, combining them to form your own assessments. You will need to be able to think critically, often balancing competing opinions, to make a judgement on level of risk created by investments. You will consider how those opinions may interact with wider HMG strategies and policies. For Compliance & Enforcement roles, you will support the work of finding effective remedies to national security risks, as well as monitoring for breaches of the Act and developing advice for Ministers on enforcement.

Briefing and advising:

You will regularly produce high-quality written and oral advice to support senior officials and ministerial decision-making. You will play a key role in keeping seniors and Ministers sighted on developments, often at short notice.

Supporting the ISU’s function:

You will support the day-to-day running of the ISU, ensuring that the unit is able to deliver the high-quality service for which it has become known. Including but not limited to:

•  Developing policy responses to real-world challenges arising when using the NSI Act and associated powers.

•  Taking forward secondary legislation to ensure our powers continue to meet our operational needs.

•  Considering links between the ISU’s work and other Government priorities, including Free Trade Agreements and sector strategies.

•  Engaging internal and external stakeholders, including through presentations and publications.

In this, you will work closely with a wide range of different stakeholders and professions within the ISU, across Government, and from the private sector and academia.

You must be prepared to undergo Developed Vetting clearance (if you do not already possess it). This normally requires 10 years’ UK residency in the past 10 years. This is not an absolute requirement but supplementary checks may be required where individuals have not lived in the UK for the required period. This may mean that your security clearance (and therefore your appointment) will take longer or, in some cases, not be possible.

We are supportive of flexible working but these roles require candidates to work from the London office for the majority of the working week. Some degree of regular home working should be possible, subject to business needs, but the role requires regular access to the London office. Any flexible working arrangements would need to be agreed after appointment in line with business need and could be subject to change.

Skills and experience

We’re looking for candidates who can work efficiently in a dynamic operational environment, while also possessing the analytical skills and aptitude to cope with novel policy challenges that can have impacts beyond your area of work. You will need an eye for detail and look for ways to improve current systems and processes. We need candidates who are inquisitive, critical thinkers who will continue to develop their knowledge and experience and apply both to new issues. You will anticipate issues and identify trends which impact your work area. You will be a team player, with a track record of delivering high quality results to tight deadlines.

Essential

•  Ability to confidently analyse information from a wide variety of sources to arrive at a well-reasoned decision;

•  Ability to deliver high quality work at pace;

•  Proven drafting skills;

•  Experience engaging with internal and external stakeholders at a range of levels.

Desirable

•  Understanding of national security policy or operations would be highly desirable in this role;

•  Knowledge or an interest in mergers and acquisitions or investment transactions;

•  Experience of working in a fast-paced operational environment;

•  Experience of tackling new or novel policy problems independently;

•  Experience of assessing intelligence;

•  Experience in working with cross-government groups and agreeing a way forward on issues where there are competing priorities

Please note: that whilst existing DV clearance is not required to be appointed to these roles, successful candidates must be willing to obtain SC and then DV. It is the responsibility of the applicant to have completed and returned an SC security questionnaire to United Kingdom Security Vetting as part of the onboarding process, otherwise a start date cannot be provided. Please note that these are reserved posts and therefore open to UK nationals only.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Making Effective Decisions
  • Delivering at Pace
  • Working Together
  • Seeing the Big Picture

BEIS offers a competitive mix of benefits including:

A culture of flexible working, such as job sharing, homeworking and compressed hours.

Automatic enrolment into the Civil Service Pension Scheme.

A minimum of 25 days of paid annual leave, increasing by 1 day per year up to a maximum of 30.

An extensive range of learning & professional development opportunities, which all staff are actively encouraged to pursue.

Access to a range of retail, travel and lifestyle employee discounts.

A hybrid office/home based working model where staff will spend a norm of 40-60% of their time in the office (minimum of 40%) over a month with flex dependent on balancing business and individual need (from September 2021, depending on how the public health guidance evolves).

Senior Investment Security Advisor

London

Job summary

The National Security Secretariat (NSS) keeps the UK safe, secure and prosperous by bringing together the UK’s national security community, providing high-quality support to the Prime Minister and the National Security Council and maintaining centre-to-centre relationships internationally. Working within the wider Cabinet Secretariat and led by the Prime Minister’s National Security Adviser (NSA), we assist the Prime Minister and the Cabinet in the development, coordination and implementation of its highest priority objectives.

Our overarching strategy is set out in the Integrated Review, which describes the Government’s vision for the UK’s role in the world over the next decade, and the action we will take to 2025.

The NSS value professional and personal development for all of our staff and recognise that a continued focus on learning and development (L&D) will enable us to grow our capability. We are also committed to fostering a culture which welcomes new ideas and fresh perspectives, and supporting diversity and inclusion, including through flexible patterns and ways of working.

We can offer stretching and engaging work to enhance career development and gain highly transferable skills. We expect our staff to rise to new challenges, demonstrating the agility required to respond to urgent and changing events, and to work collaboratively to achieve results both within NSS and across government. A role with the NSS is a real opportunity to impact the lives of our citizens and make a difference every day.

Job description

The role and our team

The National Security and Investment Act, which commenced at the start of January 2022, protects the nation from potential security risks resulting from foreign investment. It bolsters the UK’s status as an attractive place to invest by providing more efficient scrutiny of relevant acquisitions and more certainty and clarity for investors and businesses. 

The Investment Security Unit leads the Government’s screening of foreign investments into UK companies; assessing the risks mergers and acquisitions, investments or the transfer of assets could present to the UK’s national security. Almost a year into delivery of the new National Security and Investment Act, the Unit is at the heart of the operational response to changes in the global economy and the balance of power, as it coordinates cross-government responses to protect our capabilities and critical national infrastructure. The Unit is an exciting and diverse place to work, with teams delivering a range of operational, policy, analytical and international activities.

Delivery of the legislation remains a Secretary of State top five priority and there is huge interest in this policy area from the Prime Minister and other members of the Cabinet. The Unit is recruiting for roles across its different teams which provide regular opportunities to brief Ministers and Private Office as well as extensive cross-Whitehall engagement.

The Risk Assessment team is responsible for leading the cross-Whitehall and intelligence community risk assessment of cases passed on by the Risk Identification and Review team. These assessments cover the national security, economic and diplomatic implications of individual investments, identifying remedies to address risks and supporting ministerial decision-making. The Compliance and Enforcement team aims to mitigate national security risks arising from Foreign Direct Investment by: monitoring compliance with the Act; advising the Secretary of State on enforcement action; and supporting the wider ISU in operating the NSI Act.

Person specification

Key responsibilities

Senior Investment Security Adviser:

Co-ordinating expertise

You will lead discussions across Government  and gather the necessary expertise  to assess the  risk posed by foreign direct investment. For Compliance and Enforcement roles, you will support ISU colleagues to develop effective remedies that mitigate national security risks. You will also work with policy advisors and NSI Legal Advisors to make assessment of how NSIA could be applied to mitigate any national security risks arising from investments. For Compliance and Enforcement roles, you will work closely with Legal advisors to respond to instances of non-compliance, develop robust and effective orders and determine how to respond to novel and complex developments in cases.   

Analysing information

You will lead on conducting comprehensive analysis of views and assessments provided by partners across Government, as well as providing your own assessments.

For Compliance and Enforcement roles, you will monitor for non-compliance and assess its impact in complex cases. You will decide how to respond and advise the Secretary of State on whether and how to take enforcement action. You will also lead engagement with companies subject to the Act, to ensure they can comply easily and effectively You will need to be able to think critically, often balancing competing opinions, to reach a judgement on the risk created by investments. You will consider how those opinions may interact with wider HMG strategies and policies.

Briefing and advising

You will regularly produce high-quality written and oral advice to support senior officials and ministerial decision-making. You will play a key role in keeping seniors and Ministers sighted on developments in high-profile cases, often at short notice.  Including but not limited to:

– Developing policy responses to real-world challenges arising when using the NSI Act and associated powers

– Taking forward secondary legislation to ensure our powers continue to meet our operational needs

– Considering links between the ISU’s work and other Government priorities, including Free Trade Agreements and sector strategies

– Engaging internal and external stakeholders, including through presentations and publication.

In this, you will work closely with a wide range of different stakeholders and professions within the ISU, across Government, and from the private sector and academia.

Leading and managing in the ISU

You will be expected to take a leading role in representing your team’s work across the ISU and wider Whitehall. These roles will likely include line manage of one or more HEOs, who will be responsible for their own casework. You will be expected to provide guidance and constructive challenge to them to ensure they can deliver, while balancing your own priorities and delivering on complex casework.

You will report to the Deputy Head of Risk Assessment or the Deputy Head of Compliance and Enforcement. There will also be opportunity to support wider casework across ISU, including reviewing transactions and considering interventions under the Act.

You must be prepared to undergo Developed Vetting clearance (if you do not already possess it). This normally requires 10 years’ UK residency in the past 10 years.

This is not an absolute requirement but supplementary checks may be required where individuals have not lived in the UK for the required period. This may mean that your security clearance (and therefore your appointment) will take longer or, in some cases, not be possible.

We are supportive of flexible working but these roles require candidates to work from the London office for the majority of the working week. Some degree of regular home working should be possible, subject to business needs, but the role requires regular access to the London office. Any flexible working arrangements would need to be agreed after appointment in line with business need and could be subject to change.  

Skills and experience

We’re looking for someone who can work efficiently in a dynamic operational environment, while also possessing the analytical skills and aptitude to cope with novel policy challenges that can have impacts beyond your area of work. You will need an eye for detail and continuous improvement of systems and processes, as well as novel ways to apply the legislation and make decisions in ambiguous environments where information may be limited.

You should be capable of building knowledge from experience and able to anticipate issues and identify trends which impact your work area. We need people comfortable working as a team, with a track record of delivering high quality results to tight deadlines. If you are someone who cares about keeping the UK safe, someone who seeks a rewarding, challenging and exciting role then we want to hear from you.

Essential criteria

– Quality drafting skills;

– Experience engaging with stakeholders internal and external to government;

– Ability to analyse multiple sources of (sometimes) ambiguous information and make decisions confidently;

– Excellent communication skills, able to communicate persuasively and to deliver difficult messages;

Desirable criteria

– National security policy or operational knowledge;

– Knowledge of, or an interest in, mergers and acquisitions or investment transactions;

– Working in a fast-paced operational environment;

– Tackling new or novel policy problems independently;

– Experience of assessing intelligence;

– Experience in working with cross-government groups and agreeing a way forward on issues where there are competing priorities;

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Making Effective Decisions
  • Seeing the Big Picture
  • Delivering at Pace
  • Working Together

BEIS offers a competitive mix of benefits including:

A culture of flexible working, such as job sharing, homeworking and compressed hours.

Automatic enrolment into the Civil Service Pension Scheme, with an average employer contribution of 27%.

A minimum of 25 days of paid annual leave, increasing by 1 day per year up to a maximum of 30.

An extensive range of learning & professional development opportunities, which all staff are actively encouraged to pursue.

Access to a range of retail, travel and lifestyle employee discounts.

A hybrid office/home based working model where staff will spend a norm of 40-60% of their time in the office (minimum of 40%) over a month with flex dependent on balancing business and individual need (from September 2021, depending on how the public health guidance evolves)

Risk Insurance Manager

We are recruiting into our risk management team at Suntory. A chance to join our growing European GRCL Team.

 

We are looking for a Risk Insurance Manager for Suntory Beverage & Food Europe (SBFE) home to iconic brands like Lucozade, Ribena, Orangina, Schweppes and many others… Reporting directly to the SBFE Head of Risk Management (SBFE HRM), this role will support the delivery of the regional risk management and insurance programmes across SBFE in collaboration with the Suntory Global Insurance Programme Manager.

 

This role can be based in any of our head offices (Paris, Madrid, Amsterdam, London, Dublin).

 

For more information – https://www.linkedin.com/jobs/view/3534285339/

 

Salary up to £65k

Application Security Specialist

Remote working (anywhere in the UK)

Job summary

Soon, our mission will fundamentally change from one that supports downstream consumers of data about Companies, to one where our Register of Company information is instrumental in combating and prosecuting fraud and other serious economic crimes. This change will make our systems a much more attractive target. In anticipation of this, we are upscaling and upskilling our Cyber security capability.
 
As we are building fundamentally new services to support these new powers, we have identified the need for this new role. We need an Application Security Specialist, who’ll be able to build out a multi-layered ‘defence in depth’ approach to application security, spanning the entire SDLC from design, right through to deployment and ongoing operation of systems.

We are currently using a hybrid approach to the way we work. The majority of our digital teams are based in our Cardiff head office. Remote/homeworking contracts will only be offered to successful candidates who are not within a commutable distance to our Cardiff office. If you are located within a commutable distance to one our offices, you will receive a hybrid contract.

At Companies House, hybrid working is about achieving an effective balance between working in the office and working from other appropriate locations. Our approach to hybrid working provides opportunities for you to be adaptable in the way you work so that you can achieve a healthy balance between your work and home life. We currently expect those on hybrid contracts to attend their base office a minimum of one day a week but the exact degree of choice you have will depend on your role and your day-to-day work activities and should be agreed through discussions with your line manager.

Job description

You’ll identify the right places to leverage controls at all stages and lead in moving to a secure-by-default approach that ensures vulnerabilities are caught as early as possible and either eliminated entirely, or that through other measures such as the implementation of detective controls, the risk of these is managed to levels that senior stakeholders are willing to accept. You’ll get to lead in the selection of the right tools and controls and be instrumental in their implementation, not only technically, but at an organisational resourcing capacity, too.

You will become the leading authority on Application Security within Companies House, serving as not only a highly technical Subject Matter Expert to technical colleagues such as Developers and Architects, but also able to translate the risks associated with vulnerabilities to terms stakeholders, who may not have an IT background, will be able to understand and grasp the importance of.

You’ll initially be facilitating an OWASP SAMM assessment to determine where our current maturity is against a recognized framework. This will periodically be revisited by your re-assessments against it to measure our continued progress, as the environment and our organizational needs change.
 
You’ll thrive on the constant stream of developments in Application Security and will be continually updating your skills and knowledge, to address the exciting and rapidly-changing threat landscape. You’ll work with the Head of Development, Development Leads and dedicated Learning and Development colleagues, to help ensure that awareness of Secure coding techniques and the comprehension of the importance of the necessary detective and preventive controls, permeates right across Development and related areas.

As well as directly supporting our in-house Developers yourself, you’ll help colleagues in Vendor Management and Procurement, by ensuring that comparable controls are included as a matter of course in contracts and other vendor-related articles, where development is being performed by third party delivery partners. Similarly, on a technical level, you’ll identify key points within the SDLC and code check-in processes to build in mechanisms to provide suitable independent assurance of the security of code originating within third parties.

Person specification

We’re looking for an Application Security Specialist. Someone who has a naturally curious mind and is passionate about all aspects of application security.

We’re changing as an organization and we’re looking for someone who can help lead us in ensuring that Application Security is one of those things that post-change, our organization is class-leading in.

You’ll get to lead in the establishment of a complete end-to-end application security stack that creates multiple opportunities to identify and reign in poor application security practices, before they lead to a breach.

You’ll be a self-starter, empowered and able to seek out and strike up the necessary relationships within adjacent Professions and the Senior Risk Owners you ultimately serve.
 
You will be strong willed and persistent enough to continually ‘chip away’ at the challenges leading to competition for resourcing, so that over time, it is an accepted and adequately-resourced aspect of business as usual. You’ll ensure that stakeholders such a Programme and Project Management understand, plan and account for, the need not only to perform application security testing, but also the necessary re-work to remediate these findings and then re-testing to validate that these fixes have indeed been successful. Whilst acting with determination, you’ll be able to do so in a tactful and considerate way, that does not unnecessarily upset those upon whom you’ll be reliant to deliver the required change and which strikes the optimal balance in persuading people to invest in this. 
 
Your enthusiasm for the subject will be infectious and will inspire others, who prior to meeting you, might not necessarily have shared this interest to really take an active interest in application security and give it due priority.

We recognize that in a field as fast-paced as Application Security, you need a significant ongoing investment of your time to remain up to date with the latest threats and how to mitigate these. Company House’s strong L&D offering and generous training opportunities, will help supplement your own learning and advancement. The right candidate will possess a genuine passion for Information Security and Application Security and derive a lot of enjoyment from the work. 
 
Although you will become our authority on all things AppSec, you won’t be alone: We’ll support you in your training and development required to really excel in the role. 
 
As part of our broader Cyber Security team, you’ll get to interact with lots of other professions and specialisations within Cyber Security, both with ourselves, other BEIS-partner organisations and central government more generally.  
 
You would also get the unique benefit of being our lead contact with government colleagues in specialist departments such as Government Security Group, NCSC, etc. for everything Application Security related. 
 
We also recognize that many of the most interesting advancements in the field originate outside government. We will support you attending conferences and special interest groups, such as OWASP chapter meetings, to keep your knowledge at the cutting edge.

This is an exciting opportunity in digital services, designing and delivering quality services to our users. By helping us to shape our services, you’ll have the opportunity to be at the forefront of digital transformation in government. 

About Us
Companies House is an award-winning employer, building brilliant services on cutting edge technology. You’ll join our digital team at a time of transformation and you will be a part of shaping the future of our department. We use Agile methodologies and promote a culture of continuous improvement.

Inclusive and diverse teams are important to us. Wherever we can, we provide opportunities to work part-time, job-share or look for smarter ways of working. We’ll support you to meet other commitments and help you find a better work-life balance. We’re keen to create an environment that works for everyone.

Our aim is to be the best registry in the world achieved through brilliant people working on brilliant systems delivering brilliant services. We are currently delivering an organisation wide transformation programme focussing on a complete redesign of our digital services, target operating model and culture. This change will need different skills, capabilities and mindset where adaptable, bold and curious behaviours are the norm and empowerment is encouraged and utilised.

Companies House values its people, their contributions and has created a real sense of community where people seek to create strong connections. Our commitment to learning and development is exceptional, and we believe passionately in the employee experience with is prevalent through the engagement, wellbeing and development strategies which have resulted in Gold Investors in People and MIND index awards.

We are an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Everyone in Companies House brings something different, and so will you. We are committed to ensuring that we are representative of the citizens that we serve. To fulfill our commitment to recruiting and attracting diverse talent we welcome applications from underrepresented groups.

We encourage professional development, celebrate success and live our values to effect real change.


Experience

We recognise that there is not an obvious linear progression into this role. Instead, we list below some examples of paths into this type of role. Where candidates have other experience they believe to be relevant, but not necessarily matching that outlined here, we would encourage them to apply. 
 
NB: Applicants do not need all of these.

  • Three years’ experience in an adjacent Cyber Security discipline.
  • Two years’ experience as a Software Developer or Tester, attached to a Software Development function. Ideally, having acted in a role comparable to a “Security Champion”, or at least supporting other Developers through the sharing of knowledge of secure coding.
  • Two years’ experience as an Application Penetration Tester, or as a demonstrably successful Ethical Hacker/application vulnerability ‘Bug Bounty’ hunter.
  • One year’s experience in a directly comparable role within another organisation.


Technical Skills

Knowledge of Software Development and SDLC (the software development lifecycle specifically) – The person need not necessarily be a software developer themselves, but understanding application development and the challenges facing developers is essential. 

Detailed Knowledge of means of identification of Application Security vulnerabilities – The spectrum of Application Security vulnerabilities is vast and as new technologies appear, the list of vulnerabilities is ever-increasing. Candidates will need to be able to describe the various technologies and methodologies used to detect multiple types of vulnerabilities.  
 
In particular, we will be looking for candidates who recognise that single junctures of detection are inherently fallible. Instead, successful candidates will be able to point to multiple points where detective controls can be layered, throughout the application’s lifecycle. We will want to see that they conceptually grasp ‘defence in depth’. Additionally, we will be looking to see that candidates are able to identify ways that novel threats could be detected, to facilitate the safe adoption of new technologies. 
 
Detailed of Knowledge of means of remediating Application Security vulnerabilities – Identifying vulnerabilities is useful, but it’s only the first part of the job in terms of remediation. The breadth of the field means that no one person will know how to fix all vulnerabilities. We are therefore not looking for an encyclopaedic knowledge of vulnerabilities, but rather that the fundamental ‘general principles’ are covered (EG the use of input validation as a general good practice and examples of attacks this is a useful foil to; as opposed to every last attack that input validation can guard against). Additionally, that the candidate knows where/how to identify information on new vulnerabilities, which sources to trust for this information, etc. and the self-awareness to recognise when the extent of their knowledge has been exhausted and how to go about brining in further assistance. 

There are two levels to which candidates would be required to work: 
-The tactical – How do we fix this specific vulnerability now we know about it? 
-The strategic – Is there some other control that could have detected this sooner? Was this working? Can we introduce such a control? 
 
Generalised Information Security knowledge to a level that allows for unified, end to end controls. For example: We would not expect them to also possess the skills necessary to work in our SOC. We would, however, expect the successful candidate to conceptually understand what a SOC is and how its use can further heighten Application Security and to account for this when designing controls. The candidate would lead, both in identifying such opportunities and also in ensuring that this integration took place. 
 
As an example, if you identified that a vulnerability was introduced due to an unauthorised configuration change, the tactical aspect of resolution would be to ensure it was turned back on. Whilst this would address the short-term fix, this should also be followed up with the more strategic approach of attempting to ensure such a change cannot go undetected in future. One example would be to use File Integrity Monitoring, or some other means of Config Management, to ensure that changes to this are logged and that the specific log event generated when this setting changes, would be followed up with an alert to our SOC. Additionally, that the parties in the SOC knew who to contact in order to resolve this. 
 
Generalised Application Security knowledge as relates to regulation compliance – Although there is a separate ‘Governance’ area of the Cyber team and a broader Risk and Assurance function within CH, this person would be expected to become the authority on any compliance requirements relating to Application Security and ensuring this is met. Including, but not limited to the writing of appropriate policy. EG as NCSC’s CAF (Cyber Assessment Framework) is introduced, our Governance area would look to yourself to review the sections of the standard relating to Application Security, identify any gaps against new requirements and identify and manage the implementation of any remediation required.

  
Qualifications

No formal qualifications are required to apply for this role.
 
Examples of the types of qualifications that would be advantageous and which would be strong indicators of a candidate’s suitability to perform the role, however, include:

– CSSLP, OSCP, OSEP, OSED, OSWE, PenTest+, CISA, CISSP, QSA, PA-QSA, PCI SSF, CEH

We would expect that the suitable applicant would successfully attain a suitable qualification in Application Security within their first two years in post, if they did not already hold one at the time of hire. Companies House would fund and support this training, if it were required for the successful candidate.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Communicating and Influencing
  • Working Together
  • Making Effective Decisions
  • Changing and Improving

Technical skills

We’ll assess you against these technical skills during the selection process:

  • GRS – Coding in the open
  • Penetration Test
  • AI
  • CSRF
– Flexible working with no core hours. Work anytime between (6am and 8pm). – Build up to 2.5 days off per month in addition to your annual leave allowance!
– 30 Days Annual Leave, 8 Bank Holidays and 1 Privilege Day.
– Maternity, Adoption and Shared Parental Leave paid at full rate of pay for the 26 weeks of Ordinary Maternity leave, followed by an extra 13 weeks Statutory Maternity Pay and a further 13 weeks leave is also available which is unpaid. We offer 2 weeks statutory paternity leave
– Enrolment into the Civil Service Pension Scheme with a contribution rate averaging 27%.
– 3 Days Volunteering Leave.
– Support for training and certifications with up to 5 days study leave.

We also offer:
– 1 Half Day per week Innovation Time to learn new skills or come up ways to simplify the teams the way of working.

Remote Benefits:
– We will supply a desk, chair, monitor and all the kit you need to work from home in comfort.

Senior Security Engineer

Remote working (anywhere in the UK)

Job summary

We are looking for an enthusiastic Principal Infrastructure Engineer (Security) with great leadership and technical skills and a passion to improve. You will be responsible for the leadership and development of Security Engineering practices right across our IT and Digital Service landscape, as we transition from on-site data centres to a cloud hosted solution. You will be user and service focused ensuring that value is delivered through improvement and automation of secure configuration and design, using a modern standards approach.

Companies House leads the way in providing an open and transparent company register. Our register is searched billions of times a year and estimated that it will be worth over £10 billion to the UK economy, after our Transformation, supporting millions of business decisions every day. Companies House strategy 2020 to 2025. 

Our transformation will create a markedly higher security need and the formation of this role is one of the ways we are preparing for this change.

We are currently using a hybrid approach to the way we work. The majority of our digital teams are based in our Cardiff head office. Remote/homeworking contracts will only be offered to successful candidates who are not within a commutable distance to our Cardiff office. If you are located within a commutable distance to one our offices, you will receive a hybrid contract.

At Companies House, hybrid working is about achieving an effective balance between working in the office and working from other appropriate locations. Our approach to hybrid working provides opportunities for you to be adaptable in the way you work so that you can achieve a healthy balance between your work and home life. We currently expect those on hybrid contracts to attend their base office a minimum of one day a week but the exact degree of choice you have will depend on your role and your day-to-day work activities and should be agreed through discussions with your line manager.

Job description

  • You will lead several technical teams in the design, implementation, administration and support of the technical security of our infrastructure solutions and services.
  • You will ensure the correct implementation of security standards and procedures (EG the adaptation of generic hardening standards to versions which can be deployed within Companies House).
  • You will be responsible for developing the capability to support this transition, shaping the right talent and identifying security skills gaps within the teams delivering and managing the systems you will be securing.
  • Implement opportunities to optimise processes, and lead teams of experts to deliver service security improvements.  Evaluating and establishing requirements for the implementation of changes by setting policies and standards.
  • You will lead the investigation and resolution of outages or disruptions caused by misconfiguration of security controls. Taking accountability of issues that occur where security measures have caused these and proactively searching for potential solutions ensuring the right actions are taken to investigate, resolve and anticipate future problems.
  • You will coordinate with colleagues in both Security and Operational IT to investigate problems, implement solutions and take preventive measures.
  • Through the prevention of disruption arising from Cyber Security incidents or disruption arising from misconfigured security measures, support Operational IT colleagues in our collective target of ensuring Operational Continuity to agreed service levels (currently 99.90% availability).
  • Leadership and collaborative working using an inclusive approach to delivery of objectives.
  • Support in the rapid delivery of user centric services whilst focussing on performance and security.
  • Identifying, testing and being able to champion the secure adoption of emerging technologies.

This is an exciting opportunity, protecting our services and by extension, our users. By helping us to shape our services, you’ll have the opportunity to be at the forefront of digital transformation in government.

Person specification

We are looking for someone with the following: –

  • You can identify capacity issues and incompatibilities, stipulating the required changes and instigate these. You know how to own remedial action. 
  • You can deal with high-impact, complex change requests. You ensure that secure configuration and security controls are applied, monitored and managed throughout delivery and Service lifecycles. 
  • You will select appropriate secure design standards, methods and security tools and ensure they are applied effectively.  
  • You can review the systems designs of others to ensure secure use of technology, efficient use of resources and the integration of multiple systems and technologies, so they can safely co-exist with the current environment. 
  • You are experienced in information security, and can design, quality-review and quality-assure solutions and services with security controls embedded, specifically engineered as mitigation against security threats as a core part of the solutions and services.
  • You can collaborate with others to review specifications and use these agreed specifications to design, code, test and document programs using the right standards and tools. 
  • You know the direction for future technologies. You can deliver a model to support and maintain future technologies. You know how to manage risks and can take preventative action. 
  • You are experienced in leading and directing infrastructure teams in building, managing, supporting and maintaining secure solutions in a hybrid cloud environment. 
  • You will act as technical Cyber Security subject matter expert for the teams you are supporting. 

About Us
Companies House is an award-winning employer, building brilliant services on cutting edge technology. You’ll join our digital team at a time of transformation and you will be a part of shaping the future of our department. We use Agile methodologies and promote a culture of continuous improvement.

Inclusive and diverse teams are important to us. Wherever we can, we provide opportunities to work part-time, job-share or look for smarter ways of working. We’ll support you to meet other commitments and help you find a better work-life balance. We’re keen to create an environment that works for everyone.

Our aim is to be the best registry in the world achieved through brilliant people working on brilliant systems delivering brilliant services. We are currently delivering an organisation wide transformation programme focussing on a complete redesign of our digital services, target operating model and culture. This change will need different skills, capabilities and mindset where adaptable, bold and curious behaviours are the norm and empowerment is encouraged and utilised.

Companies House values its people, their contributions and has created a real sense of community where people seek to create strong connections. Our commitment to learning and development is exceptional, and we believe passionately in the employee experience with is prevalent through the engagement, wellbeing and development strategies which have resulted in Gold Investors in People and MIND index awards.

We are an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Everyone in Companies House brings something different, and so will you. We are committed to ensuring that we are representative of the citizens that we serve. To fulfill our commitment to recruiting and attracting diverse talent we welcome applications from underrepresented groups.

We encourage professional development, celebrate success and live our values to effect real change.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Changing and Improving
  • Working Together
  • Managing a Quality Service
  • Making Effective Decisions
– Flexible working with no core hours. Work anytime between (6am and 8pm). – Build up to 2.5 days off per month in addition to your annual leave allowance!
– 30 Days Annual Leave, 8 Bank Holidays and 1 Privilege Day.
– Maternity, Adoption and Shared Parental Leave paid at full rate of pay for the 26 weeks of Ordinary Maternity leave, followed by an extra 13 weeks Statutory Maternity Pay and a further 13 weeks leave is also available which is unpaid. We offer 2 weeks statutory paternity leave
– Enrolment into the Civil Service Pension Scheme with a contribution rate averaging 27%.
– 3 Days Volunteering Leave.
– Support for training and certifications with up to 5 days study leave.

We also offer:
– 1 Half Day per week Innovation Time to learn new skills or come up ways to simplify the teams the way of working.

Remote Benefits:
– We will supply a desk, chair, monitor and all the kit you need to work from home in comfort.

Clearance Officer (UKSV)

This role will be based in either York or Glasgow. UKSV operates a hybrid working policy. There is flexibility to split your working week but with a minimum requirement of 40-60% in the listed Cabinet Office Hubs.

Job summary

UK Security Vetting is going through a really exciting period of modernisation where we are starting to digitise more of what we do and trial different ways of working. To enable this, we have set up a Model Office, which is our opportunity to devise the way we work in the future. The Model Office knits together the people, process, and technology components to allow us to work smarter and more efficiently whilst still ensuring a quality product is delivered.

Job description

We are seeking individuals with a wide range of skills and experience to enhance our organisation and assist in implementing new ways of working to make us more efficient and effective. You will join a new team where you will prototype new processes and give us feedback and suggestions on where improvements can be made. You may also assist in the continuous improvement of existing processes. You will however have the support of existing staff within UKSV as we move through an exciting period of change and vetting transformation. You will be at the forefront of this change, helping to challenge and shape the way we conduct vetting interviews. Clearance interviews are undertaken with individuals at all levels across Government, for example, the Foreign Office, Home Office, Police Forces, Defence Industry, and private sector so you must be at ease talking to people from all walks of life.

As a Clearance Officer, your key duties will include:

  • Engage with our applicants, conducting targeted interviews/ assessments online via video calls in your area of expertise
  • Utilising your personal skills and experience to set a safe environment for applicants to feel at ease
  • Effectively listen and assess sensitive information shared at interview, showing empathy and understanding of difficult conversations without being judgemental
  • Produce high quality reports, making informed decisions and recommendations as to suitability of an individual holding security clearance, taking into account any risk factors identified
  • Using your knowledge and experience to help devise new processes and challenge how we do things
  • Play an active role within the wider team to support colleagues of all grades across the business to achieve common goals

Person specification

As the Model Office progresses we want people who are keen to embrace change, who are assertive and willing to challenge how we do things. These skills will follow through into the interviews being undertaken, whereby you show empathy, are self confident and have fantastic relationship building skills. The ability to converse and communicate clearly with a wide range of people is crucial.

Our people make us who we are and we pride ourselves on being a diverse and inclusive organisation, and it’s important you can feel you belong here. We value everybody for who they are and what they bring to the table, supporting one another as we continue to deliver for our customers and applicants. So, we are looking for people with lots of different skills and experience and people who are open to change and quick to learn. People who are enthusiastic, positive and collaborative.

We don’t expect you to hit the ground running. Our comprehensive training programme will give you everything you’ll need to become a well-rounded Specialist Clearance Officer. And this programme is just the first stage of a wider career path within Government Security, so this is more than a job, it could be the start of a whole new career. You may have a background in areas like (but not limited to) Psychology, Travel, Social Work, Finance, HR or Teaching, and if a role that sits at the heart of National Security is a career path you are interested in, we encourage you to apply.

As a Clearance Officer – we are looking for people that have the following experience and skills:

  • Experience of working in a professional area requiring empathy and analysis of complex factors e.g. Psychology, Social Work, HR, Finance, Teaching etc
  • Experience of working in a customer facing work environment
  • Experience of managing difficult conversations
  • Excellent verbal and written communication skills with the ability to communicate complex information in a clear and concise manner
  • The ability to work with a range of data points to identify key issues and areas of risk
  • Proficient use of IT including Microsoft Office or equivalent

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Delivering at Pace
  • Changing and Improving
  • Communicating and Influencing
  • Learning and development tailored to your role.
  • An environment with flexible working options.
  • A culture encouraging inclusion and diversity.
  • Civil Service Pension which provides an attractive pension, benefits for dependants and average employer contributions of 27%.
  • A minimum of 25 days of paid annual leave, increasing by one day per year up to a maximum of 30.
  • This role will be based in either York or Glasgow. UKSV operates a hybrid working policy. There is flexibility to split your working week but with a minimum requirement of 40-60% in the listed Cabinet Office Hubs.

Defence Digital – Cyber Security Assessor

MOD Corsham, Westwells Road, Corsham, Wiltshire SN13 9NR

Job summary

Are you ready to work in one of the most interesting cyber security environments and share your experience to support national security?

Cyber security plays an integral role in protecting the UK against external and internal threats, acting as a deterrence to ensure that our Armed Forces have the strong cyber defences they need.

The Cyber Assessment and Advisory Service (CySAAS) provides assurance, support and advice to teams across defence. It consists of sub teams which assess specialist ICT, communication, and weapons systems.

The team is within the Cyber Defence and Risk (CyDR) organisation which sits at the forefront of Cyber Security and Information Technology within Defence. It is responsible for enabling Defence, through the provision of specialist assurance and cyber security services, across UK Defence including industry partners, other Government Departments and our international allies.

CyDR sits within Defence Digital who provide digital and technology services to our Armed Forces.  Defence Digital operates at scale, with an annual budget in excess of £2Bn and a diverse team of 2,500 colleagues, aiming to make our Armed Forces some of the most technologically advanced in the world.

With a fantastic growing team of military and civilian staff operating across the UK it is a great time to be a cyber security professional in the Ministry of Defence. If you can see yourself contributing to the world of CySAAS the next chapter of your career may be with us!

This position is advertised at 37 hours per week.

Reserved posts are open to UK nationals only, while non reserved are open to UK, Commonwealth, EEA and certain non-EEA nationals. Contact your recruitment team if you’re unsure about this job’s status.

Job description

As a Cyber Security Assessor within the CySAAS team, you will provide timely, impartial and consistent assessment and advisory services across the department and our industry partners. You will also lead a small team providing assessment and advisory services.

Your knowledge and experience will provide the expertise to ensure an accurate understanding of through-life cyber security risks and to assist in making informed business decisions. You will work with projects that involve complex technical and security challenges, which may include highly sensitive networks, cryptography and next-generation platforms. Along the way, you will strengthen links with other cyber security bodies and business functions, including business delivery partners, who provide project-based assurance activities.

Thought leadership will be a key aspect of the role and you’ll need to demonstrate a talent for solving complex problems through innovation. You’ll have the ability to advise on complex risk balance decisions and explaining cyber security policy, governance and technology to non-experts. With you on board, we will develop a culture across UK Defence which values and protects data.

In return, you will benefit from excellent learning and development opportunities tailored to your role and beyond. Whilst in post, you’ll be able to gain industry recognised qualifications, such as CISSP or CRISC and we’ll support you throughout the process. You’ll also be able to take advantage of our excellent benefits package, including flexible working, generous leave allowance and a market-leading Civil Service pension.

For this role, a Recruitment and Retention Allowance (RRA) of up to £9k may also be payable; this is paid in increments, upon reaching the required level of competence.

We are a small, highly specialised team, performing a critical role in Defence Digital, offering an exciting opportunity to join us and become part of our journey!

Person specification

Responsibilities include:

  • Provide line management of civilian and military Cyber Security Assessment personnel, ensuring that workloads are balanced efficiently and training and development needs are managed.
  • Lead the promotion of cyber security standards and best practice across Defence, guiding and influencing project and policy decision making as appropriate and seeking novel solutions to challenging security issues.
  • Ensure the risk assessment process against approved frameworks (e.g., NIST)
  • Review risk management evidence to confirm that risk assessments and risk treatment plans are consistent with business requirements.
  • Confirm that residual security risks have been captured and accepted by the appropriate risk owner, in accordance with the risk owner’s delegated authority.
  • Recognise risk management and security decisions that have an implication beyond their level of responsibility, experience or delegated risk tolerance and escalate accordingly.
  • Explain the Cyber assessment to the risk owner, in terms of business objectives threats, risks, vulnerabilities, controls and business impacts.
  • Liaise with appropriate subject matter experts across Defence including the National Cyber Security Centre (NCSC), Cryptographic Service for Defence, Joint Cyber Unit and, where appropriate other Government Departments and Security Agencies.

Person specification

If you have the following skills and experience, we would love to hear from you!

We would expect to see some previous experience in Cyber Security Governance and Management, Risk Management and/or Operational Security Management and ideally you’ll have the following skills:

  • The ability to build strong working-relationships
  • Great communication skills, able to converse at a wide variety of levels
  • Able to lead both technical and non-technical teams

Qualifications: Your experience is key but if you have any of the following industry qualifications that would great; if not, we’ll help you attain them. You’ll need to have the motivation and desire to continue to learn and develop and we’ll provide opportunities to gain these in post:

  • Certificate in Information Security Management Principles (CISMP)
  • Certificate in Information Security Management (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Control
  • Certified Cyber Professional (CCP)

Memberships: If you aren’t already a member, we’ll help you with the process and if/when you are, we’ll assist you in supporting & maintaining them:

  • CIISEC
  • BCS

Allowances: A Recruitment and Retention Allowance (RRA) of up to £9k may be payable with this post, paid in increments upon reaching the required level of competence.

This job role is suitable for hybrid working, which is an informal, non-contractual and voluntary arrangement, blending a balance of attendance in the workplace (your permanent duty station which is based on business assessment of where the work is best done) and working from home as a personal choice (if the role is suitable for this).  If you are successful, any opportunities for hybrid working will be discussed with you prior to you taking up your post.

We anticipate that the successful candidate will be required to attend the office for a minimum of 1-2 days per week, occasionally at short notice, with travel to other sites and additional office attendance determined by the business needs.

Dependent on the business need, there may be a requirement to travel to meetings within the UK (or potentially occasional overseas visits).

If not already held, successful candidates will be required to undergo DV clearance.

This position is open to sole UK Nationals only.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Leadership
  • Communicating and Influencing
  • Seeing the Big Picture
  • Delivering at Pace

Technical skills

We’ll assess you against these technical skills during the selection process:

  • Information risk assessment and risk management
  • Applied security capability
  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • Civil Service pension with an average employer contribution of 27%
  • Family Friendly – Enhanced Parental and Adoption Leave.
  • A wide range of discounts – Defence Discount Service, Civil Service societies for Sports and Leisure, Healthcare, Insurance, Motoring, company discounts with Virgin, Vodafone, and Microsoft Office.
  • 5 days per year Learning & Development
  • In year rewards and ‘thank you’ schemes.
  • Flexible working.
  • Generous leave allocations.

The Defence Debriefing Programme (DDP), DI HUMINT.

RAF Wyton

Job summary

Based in the Pathfinder Building at RAF Wyton, Huntingdon, The Defence Debriefing Programme (DDP), within DI HUMINT, conducts voluntary debriefs of individuals with knowledge of topics of interest to Defence Intelligence.

In Defence Intelligence (DI) our people solve problems, create understanding and give perspective to the diverse and complex Defence threats and challenges in a rapidly changing world. Together our civilians and military personnel inform decision making in Defence, manage complex finance programmes and develop new technology.

In DI we believe your unique experiences, view and understanding of the world could provide a vital perspective and contribution to our work. We recognise that great minds do not think alike and are striving to increase our diversity representation at all levels.  As an equal opportunities employer we hire, train and promote people based on merit and inspire to create an inclusive workplace free of discrimination. We also offer flexible working arrangements such as flexitime, job share and compressed hours.

All jobs adverts in DI are subject to fair and open competition.

This post is advertised for 37 hours per week

Job description

As a Defence Debriefer you will manage your own workload in support of wider DDP objectives. You will be responsible for planning and preparing operational activity, to include accommodation, travel and linguistic support in order to effectively conduct strategic debriefs of HUMINT sources against Defence Intelligence requirements. DDP debriefers are also required to support broader DDP and DI HUMINT activities as required.

Person specification

As a Defence Debriefer you would be expected to:

  • Manage your own workflow, and conduct regular, ongoing liaison with OGDs in support of wider programme objectives.
  • Undertake all aspects of preparation for debriefs, including detailed background research, analyst/customer liaison, the collation of supporting material, and the organisation of suitable travel and accommodation.
  • Effectively conduct strategic debriefs of HUMINT sources against Defence Intelligence requirements.
  • Produce and disseminate resulting intelligence reporting and case paperwork.
  • Provide support to broader DDP and DI HUMINT objectives.
  • Demonstrate sound judgement on security, risk and legal issues associated with debriefing.

Essential skills:

  • Excellent communication skills/comfortable communicating with a diverse range of individuals
  • Ability to manage risk effectively in a complex operating environment
  • Proven experience and skill in report writing
  • Ability to travel, sometimes at short notice, across the UK
  • Full UK Driving License

The successful candidate will be expected to have passed the Defence Debriefing Course (DDC) or will be required to do so within the first 6 months of employment.

Desirable Skills:

  • Recent strategic debriefing experience or equivalent interviewing skills.
  • An understanding of the Defence intelligence community, geo-politics and the wider intelligence community.
  • Recognised qualification or demonstrable ability in a relevant language (e.g. Arabic, Pashto, Farsi, Russian)

Licences

UK Driving Licence

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Making Effective Decisions
  • Delivering at Pace
  • Leadership
  • Seeing the Big Picture

There are a wide variety of employee benefits for civil service staff in DI, including (this list is not exhaustive):

  • Salary Payroll Giving
  • Financial Education Resources
  • Bicycle Purchase Advance & Cycle to Work Scheme
  • Holiday, Season Ticket, Tenancy Deposit & Work Space Salary Advance Loans
  • Free Parking (not available at Main Building)
  • Generous Pension Scheme with employer contribution between 26.6% & 30.3%
  • Death in Service Benefit
  • Up to 30 days’ Annual Leave, and one Privilege Day
  • Special Leave (including Study Leave and Volunteering Leave)
  • Adoption, Maternity, Paternity and Shared Parental Leave
  • Childcare Vouchers
  • On-Site Nursery & Childcare at some MOD sites
  • Flexible Working Hours
  • Discounted Healthcare Packages
  • Eyesight Tests and Spectacles
  • Free On-Site Gyms at many sites
  • Employee Assistance Programme
  • In-Year Reward and Thank You Schemes
  • Talent Schemes
  • Defence Discounts
  • Microsoft & Vodafone Employee Discount Schemes
  • Boundless and Civil Service Sports Council Memberships available
  • On-site shops, restaurants & cafes at most sites

Senior Fraud Analyst

Stoke Gifford, South West England, BS34 8JH : City of Westminster, London (region), SW1A 2HB

Job summary

Fraud Defence is the central counter-fraud function for the MOD. It takes the strategic lead for fraud, corruption and other economic crime matters across Defence, it represents the MOD as the victim of fraud and drives the MOD’s coordinated response to fraud. Fraud Defence provides subject expertise to inform risk decisions by Defence senior stakeholders on fraud & corruption; is the single reporting gateway for economic crime and whistle-blower concerns, undertakes investigations and coordinates training and awareness.

This position is advertised at 37 hours per week.

Job description

The Analysis & Intelligence team provides a wide range of assessed products to support and direct this work. Its primary roles are to provide a trusted single version of the truth on the threat to the MOD from fraud & corruption; to provide statistical and related management information (MI), provide advice and research to underpin decision making, policy development and evaluation within MOD; and to support the production of relevant National Statistics on Defence.

The team’s work is high profile and demanding but is extremely rewarding and provides an excellent insight into the workings of the MOD as a department of state. Collaboration is at the heart of how we work. The team works closely with a wide range of diverse stakeholders across MOD, UK Government, across Defence Industry and internationally.

The work is challenging and varied but is extremely rewarding and provides an excellent insight into the workings of the MOD.

Person specification

Reporting to the Analytics and Intelligence Counter Fraud Manager your will have responsibility for:

• Project managing data analytic assignments to detect fraud, including overseeing external assistance and ensuring projects are delivered efficiently and in line with the Fraud Defence risk-based analytics programme.

• Being accountable for the collection, collation and dissemination of meaningful analysis, allocating work streams and managing 1 x C2 Analyst.

• Undertaking a range of analytical activities designed to identify and detect fraud, error and loss.

• Continuously improving the analytics products, including the inclusion of new data sets, innovative tests and software.

• Producing detailed analysis of the Fraud Defence Case Management System, creating interactive dashboards and ad-hoc data visualisation packages.

• Collating, evaluating and analysing information from a variety of internal and external sources, producing high quality analytical products.

• Contributing to the development of Strategic Assessments and Control Strategies and develop assessed intelligence products.

• Assessing the value of analysis in line with the control strategy and intelligence requirement carrying out further research when required to maximise value and determine the appropriate dissemination route.

• Maintaining networks of subject matter experts throughout the MOD, supporting internal and cross-Government working groups and governance boards.

• Ensuring GDPR compliance through the production of Privacy Impact Assessments/Bulk Date Analysis Assessments, data records management, data retention policy and data sharing agreements.

Behaviours

We’ll assess you against these behaviours during the selection process:

  • Working Together
  • Making Effective Decisions
  • Changing and Improving
  • Managing a Quality Service
  • Communicating and Influencing
  • Leadership
  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • Civil Service pension with an average employer contribution of 27%

Deputy Director – Data Protection Officer

Bristol, Cardiff, Croydon, Edinburgh, Leeds, Manchester, Newcastle-upon-Tyne, Nottingham, Stratford, Telford, Worthing

Job summary

HM Revenue and Customs (HMRC) is one of the UK’s largest organisations, with over 65,000 employees, collecting over £716 billion in tax revenue.

The role of Data Protection Officer is a critical role at the heart of HMRC.

The world is changing, and for HMRC to be effective in these times, it needs to be joined up, innovative and efficient. Data, the driving force of the world’s modern economies, is central to making that happen.

Improving how HMRC collects, uses, and safeguards data continues to be a high priority for the department. This is a key element in building a trusted modern tax administration system fit for the challenges and opportunities of the 21st century, as set out in the government’s 10-year Tax Administration Strategy.

HMRC touches the lives of almost everyone in the country and ensuring we keep that data secure and well governed is of utmost importance.

As one of the largest data controllers in the UK, HMRC handles billions of records every year and has well-established systems and controls for safe and secure collection and the onward sharing of personal data in accordance with UK data protection legislation.

If you are ready for your next challenge and are interested in joining our team, we look forward to hearing from you.

Job description

As DPO, you will lead an independent and dynamic team that collaborates across HMRC. You will have the opportunity to demonstrate your skills, knowledge and experience in blending capability, passion, and influence to forge a data protection culture in HMRC. This is a demanding role with significant leadership and assurance responsibilities across the span of data protection issues arising from a UK and international context. It carries a requirement to act independently within the organisation with direct access to senior levels.

This exciting, high-profile role is an opportunity to confidently lead HMRC further along its compliance journey: to respect data privacy rights and protect personal information of our 50 million individual customers, 5 million business customers, and 65,000 employees. You will work with HMRC senior stakeholders and with the Information Commissioners Office, the UK’s Regulator for data protection.

Responsibilities

  • Upholding citizens’ rights and privacy by making data protection a key operational priority for HMRC.
  • Ensuring ExCom is sighted on and understands HMRC’s compliance risk landscape, in line with ExCom’s accountability, providing evidence and assurance on their risk exposure.
  • Advising and guiding HMRC on its strategic risk priorities for data protection and information governance.
  • Working in partnership with senior stakeholders to achieve compliance and effectively holding operational teams to account.
  • Leading, directing and defining the resources necessary for the ambitious plan of work under the GDPR Programme and enabling the transition into BAU capability.
  • Providing strategic direction to business areas and embed the right data protection culture and awareness specific to their roles.
  • Leading on HMRC’s international data protection obligations and data sharing impacts.
  • Acting as the executive on a number of Senior Boards.
  • Understanding, educating, and advising HMRC on the wider data protection landscape and trends across Government, the Regulator and Industry.

For full details about the role, key responsibilities, and person specification, and how to apply, please download and review the Candidate Information pack.

Person specification

This is a senior leadership role in one of the nation’s busiest and most complex public sector information and technology teams. As Deputy Director, Data Protection Officer, every day will bring fresh professional challenges and an opportunity to make a positive impact on a national stage. 

The successful candidate will be an adept leader, working across a broad and intellectually stimulating portfolio.

Essential Criteria:

  • Expertise in national and European data protection laws and practices, including an in-depth understanding of UKGDPR and the Data Protection Act 2018.
  • Experience of implementing GDPR in a similar organisation either in the public or private sectors.
  • Proven track record of working in partnership with regulators and operational areas.
  • Demonstrated ability to manage senior stakeholders up to Board level.
  • Ability to lead and energise a team of data protection practitioners, instilling a clear narrative as to the importance of data protection and driving a culture of personal and professional development within the team.
  • Strong communication skills, with the ability to break down and disseminate the key data protection requirements, bringing the law to life for all relevant stakeholders and audiences across the department. 

Desirable Criteria:

  • Knowledge and understanding of HMRC, its objectives and functions and how this impacts on the processing of personal data across its operations.

As a Civil Service employee, you’ll be entitled to a large range of benefits.

This includes:

  • 25 days annual leave on entry, increasing on a sliding scale to 30 days after 5 years’ service. This is in addition to your public holidays.
  • Interest-free loans allowing you to spread the cost of an annual travel season ticket or a new bicycle.
  • A competitive contributory pension scheme that you can enter as soon as you join and where we will make a significant contribution to the cost of your pension. Your contribution comes out of your salary before any tax is taken and will continue to provide valuable benefits for you and your family if you are too ill to continue to work or die before you retire.
  • Flexible working patterns and access to Flexible Working Schemes allowing you to vary your working day as long as you work your total hours.
  • Generous paid maternity and paternity leave which is notably more than the statutory minimum offered by many other employers.
  • Use of onsite facilities (where applicable).
  • Occupational sick pay.

Enquire now

The first step in our joining process is to submit your CV. This will be read to determine the appropriate joining route and you will then be sent an email with a link to the relevant application form.

  • Please upload your CV here