Security and Information Risk Advisor in Edinburgh

Security and Information Risk Advisor in Edinburgh

Edinburgh Full-Time 48544 - 57155 £ / year (est.) No working from home possible
Registers of Scotland

At a Glance

  • Tasks: Strengthen cyber security and manage information risks in a dynamic environment.
  • Company: Registers of Scotland, a leader in land and property registration.
  • Benefits: Competitive salary, generous annual leave, and excellent pension contributions.
  • Other info: Join a diverse team committed to professional development and inclusion.
  • Why this job: Make a real impact on public service while working flexibly and collaboratively.
  • Qualifications: Experience in information security and risk management is essential.

The predicted salary is between 48544 - 57155 £ per year.

The base salary for this role is £48,544-£57,155. This job qualifies for Digital, Data and Technology Annual Pay supplement, 20% is included in the total remuneration above.

Pension: 28.97% of base salary (RoS contribution)

Annual leave: 38 days annual holiday, increasing to 42 days with length of service.

Duration: Permanent

Working Pattern: 35 hours per week. We are a flexible employer and will consider a variety of working patterns.

Location: This will be a hybrid role with office attendance as required at either Meadowbank House (Edinburgh) or St Vincent Plaza (Glasgow). It is expected that you would attend the office regularly during your initial training and learning period.

Number of vacancies: One

Grade: SEO

Closing date: 10 February 2026 - 23:59

Registers of Scotland (RoS) is a world-leading pioneer in land and property registration. We hold the answer to the question, "Who owns Scotland?" We are a modern, digital organisation and our success relies on building a diverse team of dedicated, skilled and motivated people.

Inclusion

We welcome applications from all backgrounds and are committed to building a diverse workforce that reflects Scotland. We particularly welcome applications from underrepresented groups in technology and design. Your unique perspective and experience will strengthen our team's ability to create services that work for all our communities.

The role

An experienced Security and Information Risk Advisor (SIRA) is required to play a pivotal role in strengthening and maturing our organisation’s cyber security posture. You will provide expert guidance on the identification, analysis, and treatment of information security risks, and support the continued development, operation, and improvement of our Information Security Management System (ISMS).

This is a key position within Information Security Risk and Assurance. In this role, you will offer technical information security expertise across both established and emerging services, ensuring compliance with Registers of Scotland (RoS) policies, standards, and relevant legislation and frameworks. Working collaboratively with technical and non-technical teams, you will help embed effective security controls, improve security outcomes, and foster awareness of threats and best practice.

You will also contribute to the continual enhancement of our policies, standards, processes, and controls, as well as support organisational reporting and assurance activities across on-premise and cloud environments.

On a typical day you will…

  • Formulate strong relationships between the Information Security and Risk function and business teams, both technical and non-technical.
  • Promote Information Security and Risk Services offered.
  • Conduct technical assurance activities of systems, services, and products.
  • Assist stakeholders in understanding and fulfilling their information security roles and responsibilities.
  • Provide advice and guidance on security strategies to manage identified risks and ensure adoption and adherence to standards.
  • Obtain and act on vulnerability information and conduct security risk assessments and business impact analysis on complex information systems.
  • Contribute to the development of information security policy, standards, and guidelines.
  • Interpret information assurance and security policies and apply these in order to manage risks.
  • Provide advice and guidance to ensure adoption of and adherence to information assurance architectures, strategies, policies, standards, and guidelines.
  • Use control testing information to support information assurance assessments.
  • Collection and dissemination of relevant information and risk management information.
  • Deliver sessions and workshops for the scoping, identification, and analysis of security risks to the confidentiality, integrity, and availability of information assets, and propose appropriate controls and actions for risk remediation.
  • Observe instances of Non-Conformance, providing details of findings and the motivation for the issue.
  • Undertake internal audit/assurance activities to observe and evaluate ISMS processes and Security Controls and provide internal stakeholders with reports that outline findings and areas for improvement of compliance.
  • Deliver Supply Chain risk assessment and assurance activities for identified suppliers and 3rd parties that have access to RoS information.

This job is for you if you want…

  • Work with purpose: we strive to provide the best public service and set the bar for land and property registration worldwide.
  • Flexible and hybrid working: work when and where it’s best for you and your stakeholders, depending on the role and team requirements.
  • Benefits: enjoy pay progression, pension contributions of up to 28.97%, up to a year’s parental leave, and 38 days annual holiday, increasing to 42 days with length of service.
  • Investment in professional development: we invest in all our people so that they have the right skills to be productive and confident in their job.
  • Diversity and Inclusion: We are an ‘Investor in People’ and a ‘Disability Confident’ employer. We are inclusive, stronger together, and committed to putting our people first.
  • Positive work culture: RoS is an agile, digital organisation using leading-edge technology. Colleagues understand their role in achieving our strategy and have the autonomy to deliver.

To learn more about RoS and the benefits we offer visit our careers pages or watch this short video. Hear directly from our colleagues about their experience of working within our Digital, Data and Technology teams on our website.

Click 'Apply' to view our full advert and application process.

Security and Information Risk Advisor in Edinburgh employer: Registers of Scotland

Registers of Scotland (RoS) is an exceptional employer that prioritises employee well-being and professional growth, offering a competitive salary, generous pension contributions, and up to 42 days of annual leave. With a commitment to diversity and inclusion, RoS fosters a positive work culture where employees can thrive in a flexible hybrid working environment while contributing to meaningful public service in land and property registration. Join us to be part of a modern, digital organisation that values your unique perspective and invests in your development.

Registers of Scotland

Contact Details:

Registers of Scotland Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security and Information Risk Advisor in Edinburgh

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Registers of Scotland, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Registers of Scotland

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Registers of Scotland. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security and Information Risk Advisor in Edinburgh

Cyber Security Expertise
Information Security Risk Assessment
Technical Assurance Activities
Vulnerability Management
Information Security Management System (ISMS)
Compliance with Policies and Standards
Risk Management

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Registers of Scotland insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Registers of Scotland that you’re committed to staying ahead in the game.

How to prepare for a job interview at Registers of Scotland

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Registers of Scotland to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Registers of Scotland.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.