Lead Cyber Security Engineer (Identity & Payments) in Glasgow

Lead Cyber Security Engineer (Identity & Payments) in Glasgow

Glasgow Full-Time 55000 - 65000 £ / year (est.) No working from home possible
Scottish Government

At a Glance

  • Tasks: Lead the secure design and operation of cutting-edge government platforms.
  • Company: Join the Scottish Government's Digital Directorate, shaping public services.
  • Benefits: Flexible working hours, competitive salary, and a £4,000 annual pay supplement.
  • Other info: Collaborative environment with opportunities for mentorship and career growth.
  • Why this job: Make a real impact on Scotland's digital security and public services.
  • Qualifications: Experience in cyber security and leading security operations.

The predicted salary is between 55000 - 65000 £ per year.

We are looking for experienced Cyber Security Engineers to lead on the secure design and operation of high-profile and leading-edge government common platforms. You’ll join a multi-disciplinary agile team, and work on the latest set of Cloud and Security technologies.

This is a great opportunity for Cyber Security Engineers with a deep technical understanding of the latest technologies, and proven experience leading the deployment of modern security tooling to provide Extended Threat Detection and Response, Patch and Vulnerability Management, Security Automation, Protective Monitoring, Identity & Access Management, and more, across the entire development life-cycle.

While the technology you may work with is broad and varied, experience securing user-facing, web-based applications with AWS, GitHub, GitLab, Codespaces, Kubernetes, Okta, CrowdStrike, Sentinel, ExaBeam and similar technologies would be highly beneficial.

As an experienced Cyber Security Engineer, you’ll have the opportunity to shape secure digital services that matter — influencing the protection of systems used across the Scottish public sector and the millions of people who rely on them every day. Your guidance will help engineering teams embed secure development and operational best practice, strengthening our security posture and driving continuous improvement in how services are built, tested, and operated. Your expertise will be trusted, your perspective valued, and your leadership encouraged when identifying risks and proposing pragmatic solutions.

Collaboration is central to the role, working with colleagues across security, engineering, architecture, product, and service management. As a respected member of the community, your knowledge and experience will support others through mentoring, open knowledge-sharing, and meaningful contributions to governance decisions that shape our cyber resilience.

We are looking for two Security Engineers to join the Digital Directorate and play a key role in delivering secure, resilient digital public services across government. This is an exciting opportunity to support some of Scotland’s most significant, multi-million-pound digital programmes, including ScotPayments and ScotAccount, as well as other major national initiatives built on our emerging common platforms and services. These initiatives are key enablers of Scotland’s Digital Strategy, and form part of the Delivery Plan (2025 – 2028) for Sustainable Digital Public Services.

The roles form part of a growing and maturing security capability within the Digital Directorate. While you may provide focused support to specific programmes, you will also contribute to the Directorate security expertise that enables consistent, scalable security practices across government’s digital services.

Responsibilities:

  • Identify, design, and develop cyber security solutions across a wide variety of applications and infrastructure.
  • Engage with the Digital Technical Architecture team and support the design of technology solutions and architecture for a variety of projects and programmes.
  • Develop security operating procedures for use across multiple information systems or support compliance with them, including vulnerability management, incident response, protective security monitoring.
  • Apply routine security procedures appropriate to the role, such as patching, managing access rights, malware protection, or vulnerability testing with autonomy.
  • Champion secure design principles, frameworks, and standards for a digital service or programme.
  • Drive secure coding practices and champion them, mentoring the engineering team to be able to undertake these tasks.
  • Lead and translate security requirements into application design elements including documenting specific security criteria.
  • Design advanced audit points into digital services.
  • Act as a subject matter expert (SME) for CI/CD pipeline, infrastructure automation and cloud security, lead software debugging and guide engineers to resolve issues.
  • Create and deliver automated assurance against Technical Security guidance and configurations.

Success Profile:

Success profiles are specific to each job, and they include the mix of experience, skills and behaviours candidates will be assessed on.

Experience:

  • Lead Criteria 1 - Cyber Security Operations: Develop and support security procedures, ensuring compliance. Apply routine security measures autonomously and lead small teams in managing Cyber Security operations.
  • Lead Criteria 2 - Specific Security Technology and Understanding: Understand and articulate the impact of vulnerabilities on coding, designs, and systems. Specialise in specific systems and contribute to the overall security strategy.
  • Secure Design: Champion secure design principles and standards. Translate security requirements into detailed design elements and integrate advanced audit points into digital services.
  • Secure Development: Develop services using programming and scripting languages. Lead software debugging, guide developers, and implement solutions to prevent fraud and error.

Technical Skills:

This role is aligned to the Cyber Security Engineer job role within the Senior Cyber Security Engineer job family.

Behaviours:

  • Leadership (Level 4)
  • Changing and Improving (Level 4)

How to apply:

Apply online, providing a CV and Supporting Statement (of no more than 750 words) which provides evidence of how you meet each of the 4 Experience criteria listed in the Success Profile above. Candidates will have their applications assessed against all Experience criteria. If a large number of applications are received an initial sift will be conducted on the Lead Criteria highlighted above. Candidates who pass the initial sift will have their applications fully assessed against the remaining Experience criteria.

If invited for further assessment, this will consist of an interview and Government Cyber technical assessment where the behaviours, experiences and technical skills outlined in the Success Profile will be assessed.

Security checks:

Successful candidates must complete the Baseline Personnel Security Standard (BPSS) before they can be appointed. BPSS is comprised of four main pre-employment checks – Identity, Right to work, Employment History and a Criminal Record check (unspent convictions).

Pay Supplement:

This post is part of the Government Digital and Data (GDD) profession and currently attracts a £4,000.00 annual GDD pay supplement, which is paid monthly – pay supplements are reviewed regularly.

Equality Statement:

We are committed to equality and inclusion, and we aim to recruit a diverse workforce that reflects the population of our nation.

Find out more about our organisation, what we offer staff members and how to apply on our Careers Website.

Apply Before: Sunday 24th May (23:59)

Lead Cyber Security Engineer (Identity & Payments) in Glasgow employer: Scottish Government

The Scottish Government is an exceptional employer, offering a supportive and inclusive work environment where your expertise in cyber security can make a tangible impact on public services across Scotland. With a commitment to employee growth, flexible working arrangements, and a focus on collaboration within a multi-disciplinary team, you will have the opportunity to lead innovative projects that enhance the security of vital digital services. Join us to be part of a mission-driven organisation that values your contributions and fosters professional development in a dynamic and rewarding setting.

Scottish Government

Contact Details:

Scottish Government Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Lead Cyber Security Engineer (Identity & Payments) in Glasgow

Tip Number 1

Network like a pro! Reach out to your connections in the cyber security field, attend meetups, and engage in online forums. You never know who might have the inside scoop on job openings or can refer you directly.

Tip Number 2

Show off your skills! Create a portfolio showcasing your projects, especially those involving AWS, Kubernetes, or any of the tools mentioned in the job description. This will give potential employers a clear view of what you can bring to the table.

Tip Number 3

Prepare for interviews by brushing up on common cyber security scenarios and challenges. Be ready to discuss how you've tackled vulnerabilities or led security initiatives in past roles. Confidence is key!

Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search.

We think you need these skills to ace Lead Cyber Security Engineer (Identity & Payments) in Glasgow

Cyber Security Operations
Cloud Security
Identity & Access Management
Vulnerability Management
Security Automation
Protective Monitoring
AWS

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Lead Cyber Security Engineer role. Highlight your experience with the specific technologies mentioned in the job description, like AWS and Kubernetes, and showcase your leadership skills in cyber security operations.

Craft a Compelling Supporting Statement:Your supporting statement is your chance to shine! Use it to provide clear examples of how you meet each of the four experience criteria. Be specific and relate your past experiences directly to the responsibilities outlined in the job description.

Be Honest About Your Skills:While it's tempting to embellish your skills, honesty is key. If you're using AI tools to help with your application, ensure that everything you submit is truthful and reflects your own experiences. Plagiarism can lead to your application being withdrawn!

Apply Through Our Website:Don't forget to apply through our official website! It’s the best way to ensure your application gets to us directly. Plus, you'll find all the details you need about the role and the application process there.

How to prepare for a job interview at Scottish Government

Know Your Tech Inside Out

Make sure you have a solid grasp of the technologies mentioned in the job description, like AWS, Kubernetes, and Okta. Be ready to discuss how you've used these tools in past projects, especially in securing user-facing applications.

Showcase Your Leadership Skills

As a Lead Cyber Security Engineer, you'll need to demonstrate your ability to lead teams and mentor others. Prepare examples of how you've guided teams in implementing security best practices or resolved complex security issues.

Prepare for Technical Assessments

Expect a technical assessment as part of the interview process. Brush up on your knowledge of cyber security operations, vulnerability management, and secure coding practices. Practise explaining your thought process when tackling security challenges.

Emphasise Collaboration

Collaboration is key in this role. Be ready to discuss how you've worked with cross-functional teams in the past. Highlight your experience in sharing knowledge and contributing to governance decisions that enhance cyber resilience.