At a Glance
- Tasks: Lead strategic security initiatives and advise senior stakeholders on cyber and information risks.
- Company: Join HM Revenue & Customs, a key player in government security and digital information.
- Benefits: Flexible working patterns, inclusive environment, and opportunities for career growth.
- Other info: Work across government to shape security practices and influence policy.
- Why this job: Make a real impact on national security while developing your expertise in a supportive community.
- Qualifications: Experience in security policy and risk management, with strong leadership skills.
The predicted salary is between 36000 - 60000 € per year.
Join to apply for the Principal Security and Information Professional role at HM Revenue & Customs. HMRC Security is part of HMRC’s Chief Digital Information Office (CDIO) and plays a vital role in assessing business and reputational risks across one of the largest IT estates in Europe. Within HMRC Security, Cyber Security Technical Services (CSTS) and the Government Security Centre for Cyber (Cyber GSeC) are integral teams responsible for ensuring that all colleagues have the capability to fulfil their security responsibilities and develop the skills needed to detect, prevent, and respond to evolving security risks and threats.
Our vision is to be recognised as a centre of expertise and excellence, working collaboratively across government to deliver holistic, customer‑centric cyber security services. This includes consultancy support that adapts to emerging technologies and the ever‑changing threat and risk landscape. In this role, you will be part of a multi‑discipline team and a supportive security community both within HMRC and across government. You will play a leading role in enabling HMRC to manage security, data protection, and information risks effectively across business areas.
Working in partnership with senior stakeholders, you may provide strategic insight and advisory support on a wide range of topics including cyber, physical and personnel security, data protection, and information management. At HMRC, we are committed to creating a great place to work for all our colleagues – an inclusive and respectful environment that reflects the diversity of the society we serve. We aim to maximise the potential of everyone who chooses to work with us, offering a range of flexible working patterns and support to help you build a fulfilling career.
Key Responsibilities- Providing strategic advisory support to senior stakeholders on cyber, physical, personnel, data protection and information management risks, enabling informed decision‑making and embedding proportionate controls.
- Leading as a security and information professional, championing and sharing best practice and embedding government security culture and directing a team with responsibility for setting direction, coaching, quality assurance and performance management.
- Promoting a culture of continuous improvement by driving high performance, encouraging shared ownership of outcomes and influencing others to work corporately in support of broader HMRC objectives.
- Acting as a key representative within senior leadership teams across lines of business, contributing to strategic planning, business alignment, risk governance and regulatory compliance.
- Translating security and information policy into practice, supporting implementation of policies and controls tailored to business priorities and risk appetite.
- Promoting a strong organisational culture around security, data protection and information management through stakeholder engagement and leadership.
- Bringing business insight back into central teams, shaping service improvement, policy development and transformation.
- Acting as an escalation point for complex or high‑risk issues, including incidents, assurance matters, or strategic challenges.
- Contributing to CSTS leadership, including potential involvement in the CSTS Senior Leadership Team (SLT), and supporting identification of capability needs across the wider function.
- Representing HMRC in cross‑government or cross‑departmental forums, helping influence broader policy and delivery approaches.
Demonstrated ability to influence and advise senior stakeholders at board level. Proven experience in shaping or translating security and/or information management policy and risk into business‑aligned action. Strong leadership experience with strategic direction setting capabilities. Exceptional integrity and judgement in handling sensitive information. Clear and confident communicator with experience producing high‑quality written and verbal outputs tailored to senior audiences. Significant experience advising on security and/or data protection and information risks within large, complex, and high‑risk environments. This may include providing strategic and operational guidance, influencing senior stakeholders and shaping organisational approaches to managing cyber, physical, personnel, and information security risks.
Qualifications- You must also hold, or be willing to work towards, one of the Qualifications listed below.
- Familiarity with relevant frameworks such as NIST, CAF, ISO 27001 or the ICO Accountability Framework.
- Knowledge of legislative requirements as UK GDPR, DPA 2018, Public Records Act, CRCA.
- Knowledge of risk and assurance methodologies, including threat identification, risk assessment, and control design.
- Experience working across organisational or departmental boundaries to support shared risk, policy, or governance goals.
- Applied understanding of Secure by Design principles, incident response processes, or regulatory compliance requirements.
- Background in leading or contributing to policy development, governance models or service improvement initiatives in the security or data/information domain.
- Working knowledge of HMRC’s operating environment, business areas or technical estate (or a similar large public sector organisation).
Seniority level: Mid‑Senior level
Employment type: Full‑time
Job function: Information Technology and Management
Industries: Government Administration and Government Relations Services
Available Locations: Bristol, Cardiff, East Kilbride, Edinburgh, Manchester, Telford, Worthing
Principal Security and Information Professional in Manchester employer: HM Revenue & Customs
HM Revenue & Customs (HMRC) is an exceptional employer that prioritises inclusivity and professional growth within a supportive environment. With a commitment to flexible working patterns and a culture of continuous improvement, employees are empowered to develop their skills in a dynamic security landscape while contributing to the safety and integrity of one of Europe's largest IT estates. Joining HMRC means being part of a collaborative community dedicated to excellence in cyber security and information management, making a meaningful impact across government.
StudySmarter Expert Advice🤫
We think this is how you could land Principal Security and Information Professional in Manchester
✨Tip Number 1
Network like a pro! Reach out to current or former employees at HMRC on LinkedIn. A friendly chat can give us insider info and maybe even a referral, which can really boost our chances.
✨Tip Number 2
Prepare for the interview by researching HMRC's recent projects and challenges in cyber security. We want to show that we’re not just interested in the role but also in how we can contribute to their mission.
✨Tip Number 3
Practice common interview questions related to security and information management. We should be ready to discuss our experience and how it aligns with HMRC’s goals, especially around risk management and compliance.
✨Tip Number 4
Don’t forget to follow up after the interview! A quick thank-you email can keep us fresh in their minds and shows our enthusiasm for the role. Plus, it’s a great way to reiterate our fit for the position.
We think you need these skills to ace Principal Security and Information Professional in Manchester
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in security and information management. Use keywords from the job description to show that you understand what HMRC is looking for.
Showcase Your Leadership Skills:Since this role involves leading a team and influencing senior stakeholders, be sure to include examples of your leadership experience. Talk about how you've driven high performance and promoted a culture of continuous improvement in previous roles.
Be Clear and Concise:When writing your application, clarity is key! Make your points straightforward and avoid jargon. Remember, you want to communicate effectively with senior audiences, so keep it professional yet approachable.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets seen by the right people. Plus, you’ll find all the details you need to make your application stand out!
How to prepare for a job interview at HM Revenue & Customs
✨Know Your Stuff
Make sure you’re well-versed in the key responsibilities of the Principal Security and Information Professional role. Brush up on your knowledge of cyber security, data protection, and risk management frameworks like NIST and ISO 27001. Being able to discuss these topics confidently will show that you’re serious about the position.
✨Showcase Your Leadership Skills
Since this role involves leading a team and influencing senior stakeholders, be prepared to share examples of your leadership experience. Think of specific situations where you’ve set direction, coached others, or driven high performance. This will demonstrate your capability to manage and inspire a team effectively.
✨Engage with Stakeholders
Highlight your experience in engaging with senior stakeholders and how you’ve provided strategic advisory support in the past. Prepare to discuss how you’ve translated complex security policies into actionable business strategies, as this is crucial for the role at HMRC.
✨Cultural Fit Matters
HMRC values an inclusive and respectful environment, so be ready to discuss how you promote a strong organisational culture around security and information management. Share your thoughts on fostering collaboration and continuous improvement within teams, as this aligns with their objectives.