Senior Information and Cyber Security Officer

Scottish Government

Glasgow

Hybrid

GBP 70,000 - 90,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid working
Disability Confident Employer
GDD pay supplement
Flexible working options

Job summary

Social Security Scotland is seeking a Senior Information and Cyber Security Officer to strengthen governance, risk management, and compliance across the organisation. You will work with the Cyber Security Risk and Assurance Manager to mature the ISMS and assurance activities, guiding risk-based decisions.

The role requires deep expertise in information security standards, regulatory requirements, and stakeholder engagement to deliver auditable security outcomes and resilient controls.

Qualifications

  • In-depth knowledge of information security standards like ISO/IEC 27001 and NIST SP 800-53, with understanding of GDPR and DPA 2018 requirements.
  • Proficiency in identifying, assessing, and mitigating information security risks and implementing controls.

Responsibilities

  • Independently undertake risk management activities within security governance.
  • Lead security risk assessments, threat assessments, and ensure compliance with regulations.
  • Provide tailored security advice to stakeholders to remediate identified risks.
  • Provide expert security guidance to enable auditable decisions by risk or service owners.
  • Lead security governance groups to promote strong practices and maintain the organisation's cyber posture.
  • Support ISMS development and third-party assurance activities.
  • Contribute to awareness initiatives and incident response to contain threats.

Skills

ISO 27001
NIST SP 800-53
GDPR & DPA 2018
ISMS
Risk management
Security governance
Threat assessment
Stakeholder engagement

Job description

Job Description

Are you ready to make a real impact in cyber security? We're looking for an experienced Senior Information and Cyber Security Officer to join our Digital Risk and Security branch at Social Security Scotland. In this key role, you'll help drive our Security Risk and Assurance programme and strengthen our governance, risk management, and compliance frameworks.

You’ll work at the heart of our security function - partnering with the Cyber Security Risk and Assurance Manager and contributing to the ongoing development of our governance, risk, and compliance capabilities across the organisation.

The ideal candidate can:

  • Apply deep expertise in governance, risk management, and assurance, using ISO 27001, NIST 800-53, GDPR, and DPA 2018 to strengthen organisational security.
  • Identify, analyse, and mitigate cyber risks, giving stakeholders clear, actionable advice that enables well‑informed, auditable decisions.
  • Engage and influence stakeholders, lead policy, compliance, and third‑party assurance activities, and drive the maturity of security frameworks and the ISMS.
  • Contribute to security projects, build security awareness across the organisation, and support incident response to contain and resolve threats.
Responsibilities
  • Independently undertake risk management activities within a given area of practice or expertise, usually within established security and risk management governance structures.
  • Lead the analysis and derivation of business-supporting security needs, undertake Cyber Security related risk assessments, conduct tailored threat assessment and other risk management activities, and ensure activities are consistent with applicable regulations and legislation.
  • Provide tailored advice to a range of stakeholders on how to remedy identified risks by proportionately applying security capabilities, using published guidance, standards, and drawing on a range of experts as well as personal expertise.
  • Provide expert security advice that highlights Cyber Security related risks, so risk or service owners can make well‑informed and auditable decisions.
Security Leadership & Governance
  • Serve as a key point of contact for security advice and guidance.
  • Lead security governance groups to promote and maintain strong security practices.
  • Help maintain the organisation's desired cyber security posture in line with its risk appetite.
  • Provide leadership and guidance to a small team of security professionals to ensure high-quality service delivery.
Risk Management & Compliance
  • Identify, assess, and manage cyber threats and risks to protect organisational assets.
  • Conduct compliance audits to ensure adherence to internal and external security requirements.
  • Perform internal and external security assessments to evaluate controls and drive continuous improvement.
  • Support teams in identifying vulnerabilities, conducting risk and impact assessments, and implementing protective actions.
Policies, Standards & ISMS
  • Develop and maintain information security policies, procedures, standards, and guidelines.
  • Provide guidance to support the effective adoption of security policies and standards.
  • Support and enhance the organisation's Information Security Management System (ISMS).
Third-Party & Supplier Assurance
  • Work with third parties to obtain independent assurance on the effectiveness of security controls.
  • Oversee third-party security by assessing supplier controls and ensuring compliance with organisational requirements.
Security Projects & Consultancy
  • Lead the design, procurement, and implementation of security projects to strengthen the organisation's security posture.
  • Deliver specialist security consultancy to support successful project outcomes.
Awareness & Incident Response
  • Contribute to the development and delivery of a security awareness programme that strengthens the organisation's security culture.
  • Support incident response activities to contain, investigate, and resolve security incidents.
Qualifications
Success Profiles

We use an assessment framework called 'Success Profiles' which lists the elements we test and provides detailed descriptions of each. Find out more about the framework here.

Experience
  1. In-depth knowledge of information security standards like ISO/IEC 27001 and NIST SP 800-53, combined with understanding of current legislation such as DPA 2018 and GDPR. Proven ability to interpret and apply these standards and legal requirements to ensure compliance and integrate best practices into organisational operations.
  2. Comprehensive understanding of internal and external information security risks, and proficiency in identifying, assessing, and implementing administrative, physical, and technical controls to mitigate these risks effectively.
Behaviours
  • Leadership - Level 3
  • Delivering at Pace - Level 3

You can find out more about Success Profiles Behaviours here

Technical / Professional Skills

This role is aligned to Lead Cyber Security Risk Manager within the Digital, Data and Technology Profession.

Please review the following to understand the skill expectations: Cyber Security Risk Manager - Cyber security: advisory - gov.scot

These skills will be tested during the Technical Assessment if you are successful at sift stage. They will not be assessed at application stage.

Expected Timeline (subject to change)

Sift - week commencing 5th October

Interview - week commencing 19th October

Location - In Person in either Dundee or Glasgow

Reserve List

In the event that there are more successful candidates than posts available, a reserve list will be kept for up to 12 months.

About Us

Social Security Scotland is an Executive Agency of the Scottish Government. Our benefits help people from all walks of life in Scotland. We offer rewarding careers and employ people across Scotland in a wide range of professions and roles. We are committed to recruiting a diverse workforce that is representative of the clients we serve. Find more about us here.

We offer a supportive and inclusive working environment along with a wide range of employee benefits. Find out more about what we offer.

As part of the UK Civil Service, we uphold the Civil Service Nationality Rules.

GDD Pay Supplement

This post is part of the Government Digital and Data (GDD) profession and currently attracts a £4,000 annual GDD pay supplement, which is paid monthly. Pay supplements are reviewed regularly.

Working Pattern

Our standard hours are 35 hours per week and we offer a range of flexible working options, depending on the needs of the role. We embrace a hybrid working style where all colleagues will spend time in either our Glasgow or Dundee offices. There is an expectation of a minimum 2 days per week in your assigned location, which will be either Glasgow or Dundee. If you have specific questions about the role you are applying for, please contact us.

Security Checks

This post requires the successful candidate to clear additional National Security Vetting clearance (Security Check) before a start date can be offered. Further information regarding National Security Vetting clearance can be found here - United Kingdom Security Vetting: Applicant - GOV.UK (United Kingdom Security Vetting: Applicant - GOV.UK)

Equality Statement

Social Security Scotland are committed to equality and inclusion, and we aim to recruit a diverse workforce that reflects the population of our nation.

Social Security Scotland are a Disability Confident Employer. We will consider and implement any reasonable adjustments you may require throughout the recruitment process and during the course of your employment, should you be successful in securing a post. If you feel you may require assistance with any part of our recruitment process, please contact us at Recruitment@socialsecurity.gov.scot

Find out more about our commitment to diversity and how we offer and support recruitment adjustments for anyone who needs them.

Right to Work in the UK

Social Security Scotland is an approved sponsor under the UK Visa and Immigration (UKVI) Skilled Worker route. Please note that UK immigration guidance, including skill and salary thresholds and eligible occupations, is reviewed regularly and subject to change. If you require visa sponsorship, you should check the latest criteria to confirm whether this role meets current requirements before applying. You can find further advice at Skilled Worker visa: Overview - GOV.UK

Further Information

Social Security Scotland's recruitment processes are underpinned by the recruitment principles of the Civil Service Commissioner, which outline that selection for appointment be made on merit on the basis of fair and open competition - Recruitment - Civil Service Commission

If you feel at any time your application has not been treated in accordance with the values in the Civil Service Code and/or if you feel the recruitment has been conducted in such a way that conflicts with the Civil Service Commissioner's Recruitment Principles, you can make a complaint, by contacting Social Security Scotland at recruitment@socialsecurity.gov.scot in the first instance. If you are not satisfied with the response you receive you can contact the Civil Service Commissioner.

The successful candidate will be expected to remain in post for a minimum of 3 years unless successful in gaining promotion to a higher Band or Grade.

Find out more about our organisation, what we offer staff members and how to apply on our Careers Website.

Read our Candidate Guide for further information on our recruitment and application processes.

If you experience any difficulties accessing our website or completing the online application form, please contact the Resourcing Team via recruitment@socialsecurity.gov.scot

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Cyber Security Analyst (IAM)
Principal Cyber Security Analyst (IAM)

Social Security Scotland • Glasgow

Hybrid
GBP 90,000 - 120,000
Hybrid working
Principal Cyber Security Analyst (IAM)
Principal Cyber Security Analyst (IAM)

Scottish Government • Glasgow

Hybrid
GBP 65,000 - 90,000
Hybrid working (Glasgow/Dundee)
£4,000 annual GDD pay supplement
Senior Technical Delivery Manager (Fixed Term Appointment)
Senior Technical Delivery Manager (Fixed Term Appointment)

Social Security Scotland • Glasgow

Hybrid
GBP 75,000 - 100,000
Product Owner
Product Owner

Social Security Scotland • Glasgow

Hybrid
GBP 65,000 - 90,000
Hybrid working
Employee benefits
Content Designer
Content Designer

Social Security Scotland • Glasgow

Hybrid
GBP 32,000 - 52,000
Business Analyst
Business Analyst

Social Security Scotland • Glasgow

Hybrid
GBP 45,000 - 65,000
Hybrid working
Cyber SOC Lead Ref No: 3594
Cyber SOC Lead Ref No: 3594

Skills Development Scotland • Glasgow

Hybrid
GBP 90,000 - 120,000
Flexible working
Wellbeing program
Senior Information and Cyber Security Officer
Senior Information and Cyber Security Officer

The Scottish Government • Glasgow

On-site
GBP 70,000 - 90,000
Senior Information and Cyber Security Officer
Senior Information and Cyber Security Officer

Work For Scotland • Glasgow, Dundee

Hybrid
GBP 65,000 - 90,000
Senior Tax Specialist
Senior Tax Specialist

Scottish Government • City of Edinburgh

Hybrid
GBP 70,000 - 90,000
Hybrid working
Flexible working arrangements