Chief Security Officer - HMRC - SCS2

Manchester Digital

Manchester

On-site

GBP 120,000 - 180,000

Full time

47 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

HMRC is seeking a Chief Security Officer to safeguard information assets and oversee security and data protection strategies at an enterprise level. You will chair governance, drive risk mitigation, and shape the security policy agenda across government.

You will lead a senior team, align security with business objectives, and manage complex, multi-location programs to protect critical assets and maintain public trust.

Qualifications

  • Deep understanding of information security principles, technologies and control frameworks; professional certifications preferred.
  • Proven strategic leadership in security, risk and compliance across large organisations.
  • Experience researching and implementing innovative security models such as Zero Trust and secure AI.

Responsibilities

  • Deliver security services across the organisation in an agile, risk-informed way to operate securely at scale.
  • Establish enterprise security governance, policy and assurance frameworks; liaise with internal and external partners.
  • Lead and develop security teams across locations, ensuring strong organisational resilience and regulatory compliance.

Skills

Executive security leadership
Information security principles
Zero Trust architectures
Stakeholder management
Security certifications (CISSP/CISM)

Education

CISSP / CISM certification

Job description

Location

Belfast, Birmingham, Cardiff, Edinburgh, Glasgow, Leeds, Liverpool, London, Manchester, Newcastle-upon-Tyne, Nottingham, Portsmouth, Telford, Worthing

About The Job

Job summary

About

Interested in helping to shape HMRC's digital future by developing and delivering a world-class security function? Hear from Daljit Rehal, Director General and Chief Digital and Information Officer, about why you should apply for the role:

Reporting to the Chief Digital and Information Officer (CDIO), the Chief Security Officer is a core member of the CDIO Senior Leadership Team, with overarching responsibility for safeguarding HMRC's information assets, managing security and data protection risks, and setting enterprise-wide security policies and standards across cyber, information, personnel and physical security. This role offers a unique opportunity to influence HMRC's security agenda across wider government.

Job Description
Security Operations & Risk Management
  • Deliver a range of technical security services across HMRC in an agile and risk-informed way, enabling the organisation to operate securely and effectively at scale.
  • Ensure security and privacy is by design and implementation and that appropriate controls exist throughout CDIO and the wider HMRC business.
  • Strengthen HMRC's personnel security position by designing and implementing an appropriate personnel security framework.
  • Establishes enterprise-level physical security policy, standards, and assurance frameworks; day-to-day operations are managed by HMRC's Estates function.
  • Drive the implementation and monitoring of compliance to relevant regulatory and government requirements (e.g., NCSC, ISO 27001).
  • Oversee the identification, evaluation, and reporting of legal and regulatory, IT, and cyber security risk to information assets.
  • Liaise with other functions (Finance, HR, Legal, Ethics) and third parties to ensure security and data protection risks are understood, considered, and satisfactorily mitigated.
Threat Response & Innovation
  • Strategic leadership to identify, understand and effectively address emerging threats such as AI attacks, ransomware, and supply chain vulnerabilities.
  • Ensure appropriate response to security incidents and drive continuous improvements by learning from them.
  • Drive innovation in security technologies such as Zero Trust architecture and secure AI adoption.
Governance, Architecture, and Influence
  • Facilitate an appropriate security governance structure; provide regular reporting on the status of the security and data protection programme to senior leaders, including the Executive Committee and Audit and Risk Committee.
  • Work with the Head of Architecture and Innovation to build alignment between the security and enterprise architectures.
  • Implement and drive policy changes across HMRC and the wider government. Represent HMRC on relevant cross-government boards and engage with the Government Security Group to influence and help deliver the cyber, physical and personnel security policy agenda across government.
  • Liaise with external agencies, such as law enforcement and other advisory bodies, including National Technical Authorities.
  • Build and nurture external networks consisting of peers in government and industry to address common trends, findings, incidents, and cybersecurity risks.
Accountability & Public Trust
  • Define and report on security performance metrics to demonstrate accountability and effectiveness.
  • Promote public trust through transparent security practices and effective communication.
Person specification
Essential Criteria
  • Professional Expertise & Standards - demonstrates a deep and current understanding of information security principles, technologies, and control frameworks. This is evidenced by relevant security qualifications and practical experience, alongside professional certifications such as CISSP, CISM, or equivalent. Shows a strong commitment to delivering against recognised industry standards and best practices.
  • Executive Security Leadership - proven strategic leadership in managing security, risk and compliance across large, complex organisations and technology environments. Brings an outstanding track record of shaping and delivering enterprise-wide security programmes that support organisational resilience and regulatory compliance.
  • Technical Authority & Innovation - extensive technical expertise across multiple domains of security and compliance, with the ability to exercise independent judgment and make high-impact decisions. Demonstrates a forward-looking approach to emerging threats, including experience in researching and implementing innovative solutions such as Zero Trust architectures, secure AI, and other cutting-edge security models.
  • Strategic Influence & Stakeholder Management - exceptional influencing, negotiation, and relationship-building skills, with a proven ability to engage and maintain trust with senior stakeholders across government, industry, and third-party providers. Able to align security strategy with broader organisational goals through effective cross-functional collaboration.
  • Organisational Change & Vision - demonstrable experience in anticipating and preparing for major organisational or technological shifts, including emerging cyber threats. Confidently leads through uncertainty, ensuring the organisation remains agile and informed.
  • Team Leadership & Development - proven ability to build, lead, and develop high-performing teams across multiple locations. Skilled in empowering senior managers and specialists within the security and compliance disciplines, fostering a culture of excellence, accountability, and continuous improvement.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Chief Security Officer
Chief Security Officer

Global Resourcing • England

On-site
GBP 100,000 - 162,500
Chief Information Security Officer
Chief Information Security Officer

FCDO Services • Tathall End, Peacehaven

Hybrid
GBP 75,000 - 82,000
Free shuttle bus between MK and Hansl?
Excellent benefits
Civil Service Pension
Senior Lead Security Operations Analyst - Companies House - G7
Senior Lead Security Operations Analyst - Companies House - G7

Manchester Digital • Manchester

Hybrid
GBP 90,000 - 130,000
Cyber Security Governance and Risk Management Principal
Cyber Security Governance and Risk Management Principal

Government Digital Service • Manchester

On-site
GBP 110,000 - 140,000
Principal Cyber Security Governance & Risk Leader
Principal Cyber Security Governance & Risk Leader

Government Digital Service • Manchester

On-site
GBP 110,000 - 140,000
Principal Cyber Security Governance & Risk Leader
Principal Cyber Security Governance & Risk Leader

Government Digital Service • Greater London

On-site
Confidential
Cyber Security Governance and Risk Management Principal
Cyber Security Governance and Risk Management Principal

Government Digital Service • Greater London

On-site
GBP 70,000 - 90,000
Chief Information Security Officer
Chief Information Security Officer

FCDO Services • Hanslope

Hybrid
GBP 75,000 - 82,000
Hybrid working
Free shuttle bus
Chief Information Security Officer
Chief Information Security Officer

SilverShoots • Cardiff, Glasgow, Greater London

Hybrid
GBP 130,000 - 180,000
Chief Information Security Officer
Chief Information Security Officer

Ofgem • Greater London

Hybrid
GBP 70,000 - 117,000