
Enable job alerts via email!
Generate a tailored resume in minutes
Land an interview and earn more. Learn more
A government agency in the UK is seeking a Security and Information Risk Advisor to enhance its cyber security posture. This hybrid role involves guiding teams on information security risks, conducting assessments, and ensuring compliance with policies and standards. The ideal candidate will have strong analytical skills and relevant certifications such as CISSP. Benefits include a competitive salary, flexible working patterns, and professional development opportunities.
Security and Information Risk Advisor
Put your career on the map
Grade: SEO
Total Remuneration: £58,252- £68,586
Pay Supplement: The base salary for this role is £48,544-£57,155. This job qualifies for Digital, Data and Technology Annual Pay supplement, 20% is included in the totalremunerationabove.
Pension: 28.97% of base salary (RoS contribution)
Annual leave: 38 days annual holiday, increasing to 42 days with length of service.
Duration: Permanent
Working Pattern: 35 hours per week. We are a flexible employer and will consider a variety of working patterns; compressed hours, term time working or part time working on a case-by-case basis, depending on the role and departmental requirements.
Location: This will be a hybrid role with office attendance as required at either Meadowbank House (Edinburgh) or St Vincent Plaza (Glasgow). It is expected that you would attend the office regularly during your initial training and learning period.
Department: Information, Security, Risk & Assurance
Directorate: Policy and Corporate Services
Role Reports to: Head of Information, Security, Risk & Assurance
Number of vacancies: One
Closing date: Tuesday 10 February 2026- 23.59
About Registers of Scotland (RoS) Registers of Scotland is a world-leading pioneer in land and property registration. We hold the answer to the question, "Who owns Scotland?" We are a modern, digital organisation and our success relies on building a diverse team of dedicated, skilled and motivated people.
The role
An experienced Security and Information Risk Advisor (SIRA) is required to play a pivotal role in strengthening and maturing our organisation’s cyber security posture. You will provide expert guidance on the identification, analysis, and treatment of information security risks, and support the continued development, operation, and improvement of our Information Security Management System (ISMS).
This is a key position within Information Security Risk and Assurance. In this role, you will offer technical information security expertise across both established and emerging services, ensuring compliance with Registers of Scotland (RoS) policies, standards, and relevant legislation and frameworks. Working collaboratively with technical and nontechnical teams, you will help embed effective security controls, improve security outcomes, and foster awareness of threats and best practice.
You will also contribute to the continual enhancement of our policies, standards, processes, and controls, as well as support organisational reporting and assurance activities across on premise and cloud environments.
On a typical day you will…
Please review the full role profile.
This job is for you if you want…
To learn more about RoS and the benefits we offer visit our careers pages or watch this short video. Hear directly from our colleagues about their experience of working within our Digital, Data and Technology teams on our website.
Essential criteria - Your Skills and Attributes for Success
Experience/Technical: We will assess you against the following technical skills and experience during the application and assessment process:
Experience
Behaviours
Please read full behaviour descriptors and stage information.
Stage one - Application Process
To apply, click on 'Apply now' and complete the online application form. You will need to submit:
1) Making effective decisions: Describe a recent example where you carried out a technical information security risk assessment. Outline how you scoped the assessment, the frameworks or methodologies you applied, and the steps you took to identify, analyse, and evaluate the risks. Explain how you distinguished between threats, vulnerabilities, and resulting risks, including how CIA factors influenced your approach. Describe how you communicated findings and recommendations to non-technical stakeholders.
2) Managing a quality service: Describe your working knowledge and experience with National Cyber Security Centre (NCSC) publications. Provide a specific example of where you have applied this knowledge in practice, referring to relevant NCSC frameworks. Explain how you used these publications to inform your approach to identifying, assessing, and managing information security risks. Outline your experience of supplier assurance activities post tender, including how you assess and validate compliance certifications.
Please note:
Stage two – assessment
If successful at the application stage, you will be invited to an in-person interview at our Meadowbank House office in Edinburgh, which will include:
Information on Success Profiles
For further information on Success Profiles.
Indicative Recruitment Timetable
* Please note dates may be subject to change.
Feedback
Feedback will only be provided if you progress to interview stage.
Reserve List
In the event that further posts are required, a reserve list of successful candidates will be kept for up to 12 months.
Nationality and immigration status
In general, only nationals from the countries listed are eligible for employment in the Civil Service. Detailed provisions on eligibility can be reviewed here.
Security
Successful candidates must undergo a Level 1 Disclosure check. Individuals working with government assets must complete baseline personnel security standard checks.
Equality, diversity and inclusion
We welcome applications from disabled candidates. We are committed to diversity and inclusion. See our EDI strategy. If you require adjustments to the recruitment process, contact talent@ros.gov.uk.
DDaT supplement
This post is part of the Digital, Data and Technology profession (DDAT) and attracts a pay supplement. The supplement may go up or down based on market activity.
For further information relating to RoS, including pay & benefits, the Civil Service Code, the complaints process, and use of AI in the application/recruitment process, please view our additional information page online.
Please view our additional information page online.