C1 - Temporary Promotion - Security Risk and Assurance Manager - Social Security Scotland in Glasgow

C1 - Temporary Promotion - Security Risk and Assurance Manager - Social Security Scotland in Glasgow

Glasgow Temporary No working from home possible
Scottish Government

At a Glance

  • Tasks: Lead a skilled team in managing security risks and ensuring robust governance.
  • Company: Join Social Security Scotland, a vital public service organisation.
  • Benefits: Enjoy a competitive salary, hybrid working, and a £4000 annual pay supplement.
  • Other info: Flexible working options and opportunities for professional growth in a supportive environment.
  • Why this job: Make a meaningful impact on public services while advancing your career in cybersecurity.
  • Qualifications: Proven experience in security risk management and knowledge of information security standards.

Are you an experienced information security professional looking for your next leadership challenge? Social Security Scotland is seeking a Security Risk and Assurance Manager to join our Digital Risk & Security Branch on a 12-month temporary basis (expected to extend to 15 months) to provide maternity leave cover.

This is a fantastic opportunity to lead a skilled team of Information and Security Officers and Security Risk Advisors, ensuring the agency maintains robust security governance, risk management and assurance arrangements. You'll play a key role in safeguarding the confidentiality, integrity and availability of information across the organisation while driving forward our ambitious security assurance, governance and risk programme.

As Security Risk and Assurance Manager, you will lead the delivery of security risk management, assurance, policy development, supply chain security assurance and security awareness activities across Social Security Scotland. Working closely with the Head of Security Assurance, senior stakeholders and colleagues across Digital, Delivery & Change you will ensure security controls remain effective, proportionate and aligned to organisational risk appetite and public sector security standards.

This is a high-profile and rewarding role, offering the opportunity to influence security strategy, support critical public services and make a meaningful difference to the people who rely on Social Security Scotland.

Responsibilities

  • Lead and manage the Security Risk and Assurance Team, ensuring delivery of high-quality cyber risk and assurance activities.
  • Act as the organisation's subject matter expert for Cyber Security Risk Management and Assurance, providing advice to stakeholders and project teams.
  • Lead cyber security risk assessments, assurance reviews and governance activities for systems, services and projects.
  • Oversee system release assurance processes, ensuring security requirements are met before implementation.
  • Manage the planning and delivery of IT Health Checks, vulnerability assessments and remediation activities.
  • Prioritise and allocate team workloads, ensuring timely delivery of objectives and continuous improvement of assurance services.
  • Support delivery of the Cyber Security Strategy and Cyber Assessment Framework (CAF) programme.
  • Produce security risk and assurance reporting for governance groups, senior management and key stakeholders.
  • Maintain and enhance Security Risk and Assurance processes, ensuring alignment with government and industry best practice, including ISO 27001 and CAF.
  • Promote security awareness, training and a strong security culture across the organisation.
  • Contribute to leadership team activities and represent Security Risk and Assurance within relevant governance forums.

Qualifications

Success Profiles We use an assessment framework called ‘Success Profiles’ which lists the elements we test and provides detailed descriptions of each. For this opportunity, the following Success Profile elements will be assessed:

  • Experience: Demonstrable knowledge and experience of leading and managing a security risk, assurance and compliance function.
  • Specialist knowledge and understanding of information security standards with demonstrable experience in interpreting and applying information assurance legislation and policies (ISO27001, NIST, SG Cyber Resilience Framework, NCSC Cyber Assessment Framework, GDPR, DPA 2018, etc).
  • Demonstrable experience of applying risk management methodologies and their implementation.
  • In-depth knowledge and understanding of both internal and external information security risks to information which could affect confidentiality, integrity and availability.

Please apply online, providing a Supporting Statement (of no more than 500 words) providing evidence of how you demonstrate the Success Profiles noted above. Please note that a CV is not required for this opportunity.

If you are interested in this opportunity, you should seek permission from your manager and C-band manager before applying on a level transfer (TLT) basis. If applying on Temporary Promotion you should inform your manager and C-band manager from the outset of your intention to apply. If successful in your application, your release must be agreed by your line manager and C-band manager or relevant unit head. Please note that the post is only open to individuals who have satisfactorily completed their probationary period.

This is a Government Digital and Data (GDD) role within the Cyber Security and Information Assurance job family. Candidates who are not currently members of the GDD Profession, or who belong to a different GDD job family, will be required to complete a GDD technical assessment before an appointment can be confirmed.

This opportunity is for 12 months will likely be extended to 15 months to cover maternity leave.

This post is part of the Government Digital and Data (GDD) profession and currently attracts a £4000 annual GDD pay supplement, which is paid monthly - pay supplements are reviewed regularly.

Our standard hours are 35 hours per week, and we offer a range of flexible working options, depending on the needs of the role. We embrace a hybrid working style where all colleagues will spend time in either our Glasgow or Dundee offices. There is an expectation of a minimum 2 days per week in your assigned location.

This role is only available to existing permanent civil servants who have successfully completed their probation period within Social Security Scotland, Scottish Government Main or Common Citizenship organisations. Social Security Scotland are a Disability Confident Employer. We will consider and implement any reasonable adjustments you may require throughout the recruitment process and during the course of your employment, should you be successful in securing a post.

If you feel you may require assistance with any part of our recruitment process, please contact us at recruitment@socialsecurity.gov.scot.

If you experience any difficulties accessing our website or completing the online application form, please contact the Resourcing Team via recruitment@socialsecurity.gov.scot.

If you have any questions about the role please contact Antony Bernstein at Antony.Bernstein@socialsecurity.gov.scot.

C1 - Temporary Promotion - Security Risk and Assurance Manager - Social Security Scotland in Glasgow employer: Scottish Government

The Scottish Government offers a dynamic and supportive work environment, where you can make a significant impact on customer service and safeguarding across Scotland. With a strong focus on employee development and innovation, you will have access to numerous growth opportunities while working alongside a dedicated team committed to excellence in public service. Join us in shaping a high-performing organisation that values collaboration and strives for transformative results.

Scottish Government

Contact Details:

Scottish Government Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land C1 - Temporary Promotion - Security Risk and Assurance Manager - Social Security Scotland in Glasgow

Get Engaged in Cybersecurity Communities

Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like Scottish Government.

Showcase Your Skills Publicly

Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.

Stay On Top of Temp Opportunities

Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like Scottish Government.

Make Contact with Recruiters Specialising in Cybersecurity

Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like Scottish Government.

We think you need these skills to ace C1 - Temporary Promotion - Security Risk and Assurance Manager - Social Security Scotland in Glasgow

Leadership Skills
Information Security Management
Cyber Security Risk Management
Risk Assessment
Assurance Reviews
Policy Development
Supply Chain Security Assurance

Some tips for your application 🫡

Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives Scottish Government a clear view of your capabilities right off the bat.

Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.

Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at Scottish Government; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!

Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at Scottish Government.

How to prepare for a job interview at Scottish Government

Brush Up on Technical Skills

Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with Scottish Government for the C1 - Temporary Promotion - Security Risk and Assurance Manager - Social Security Scotland, be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.

Show Your Problem-Solving Prowess

Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!

Demonstrate Your Adaptability

As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at Scottish Government.

Bring Relevant Certifications

If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the C1 - Temporary Promotion - Security Risk and Assurance Manager - Social Security Scotland role at Scottish Government.