GOVTALENT.UK

Security Risk & Assurance Principal (Ref: 84123)

This opening expired 7 months ago.
Location(s):
East Midlands (England), East of England, London (region), North East England, North West England, Scotland, South East England, South West England, Wales, West Midlands (England), Yorkshire and the Humber
Salary:
£54,358 to £66,670
Job grade:
Grade 7
Business area:
Information Technology (IT), Analytical
Contract type:
Permanent
Working pattern:
Full-time

About the job

Job summary

This position is based nationally

Job description

We encourage applications from people from all backgrounds and aim to have a workforce that represents the wider society that we serve. We pride ourselves on being an employer of choice. We champion diversity, inclusion and wellbeing and aim to create a workplace where everyone feels valued and a sense of belonging. To find out more about how we do this visit: https://www.gov.uk/government/organisations/ministry-of-justice/about/equality-and-diversity.

Security Risk and Assurance Principal (G7)

The MoJ Information Security Team sits at the heart of the Ministry of Justice, enabling good security practices through the provision of security policies, guidance and education, by understanding cyber security risks from all parts of the Ministry of Justice, including the wider Justice sector and providing assurance to the departmental Senior Information Risk Owner, the Permanent Secretary and other senior stakeholders that these risks are being effectively managed in the delivery of MoJ objectives.

The role of the Security Risk and Assurance Principal is to lead a small team of risk and security professionals to deliver security risk and assurance activities across the MoJ.  This will include scoping and leading the programme of cyber security assurance across the MoJ, and measuring confidence levels that the security features, practices, procedures, and architecture of an information system bring about and enforce the security policy.

The Security Risk and Assurance Principal will be able to challenge non-compliance with required standards covering the most complex risk. They apply their understanding of information security and the organisational context to provide insight into the security implications of proposed business and technical changes, acting as a trusted advisor in communicating these effectively to technical and non-technical stakeholders.

The Security Risk and Assurance Principal will also mentor and support others in good risk management practices to enable and empower them to manage residual risk well.

Initiate and lead improvements to processes, policies and guidance resulting from risk and assurance activities and trends.

All members of the team are expected to help develop the MoJ Security Function as a centre of excellence for the department and to contribute to building a brilliant and diverse team that is a welcoming place for all.

Typical role expectations and responsibilities

Lead the implementation and delivery of security assurance processes, including GovAssure and supplier assurance activities across the MoJ, to support the overarching assurance programme. Lead on the communication of assessment and assurance outcomes to stakeholders in ways that support effective security, risk management and decision-making, and advise stakeholders on their approach to risk assessment in the context of their business outcomes.

Lead engagements with Justice Digital and Information Assurance colleagues, or supervise third party suppliers, to gather and audit evidence of the performance of technical services and organisational processes against security baselines, controls and requirements. Track the evidence provided using key performance indicators to feed into security dashboards.

Use business knowledge and technical expertise to translate evidence gathered from complex data sets into senior stakeholder reporting and recommendations for strategic risk improvement initiatives.

Identify and report on trends arising from assurance assessments across the MoJ and make sure appropriate remediation plans are in place and being actively managed.

Align risk decisions and advice with relevant regulation, policy and standards to provide proportional, practical advice that is tailored to the local environment, and advise on any residual risk for the most complex scenarios. Escalate risks to more senior stakeholders when needed and take responsibility for closure of follow up actions.

Provide direction on input into the development and enablement of security policy and security culture by collaborating with the Security Policy, Culture, Awareness and Education team through insights on trends identified from security risks and assurance activities. Assure the ongoing appropriateness of policy in accordance with regulation and wider departmental and government policies.

Play a leading role in building the network of security partners across government and national technical authorities, and within industry. Contribute to cross-government conversations on security risk and assurance.

Make substantial contributions to submissions and reports for senior MoJ officials, including presenting at senior boards, and oversee efforts needed to respond to requests and advisories received from government partners where needed.

Monitor the efficiency and effectiveness of security processes across the organisation, and lead continuous improvement efforts, including improving methods of escalation or reporting where necessary. Maintain and grow their knowledge of industry and government best practices. Apply new concepts and thinking to develop and innovate security risk and assurance frameworks, policies, processes and tooling.

Maintain understanding of local and strategic threat environments and trends affecting the landscape, and apply this to inform and provide context in decision-making and planning. Communicate tailored threat information to relevant local stakeholders within the organisation

Lead a small team of risk and security professionals, planning and tracking delivery against objectives, developing team skills, motivation and well-being. At times the team may include external third party delivery partners and require tracking of this delivery and spend.

About you:
You will need experience of working well within a security, technology or risk team, and be able to demonstrate successful prior experience of leading, mentoring and motivating a small team. You will be able to demonstrate examples of your own motivation to grow your leadership and management skills and abilities.

You will demonstrate an understanding of cyber security, technology and risk, and show commitment to continue to grow your awareness of current and emerging technologies and their impact on existing security practices.

You will be able to communicate well and confidently with a variety of stakeholders, up to board level, and relay technical information to a non-technical audience.

You will possess excellent analytical and problem-solving skills, adopting a positive approach and displaying flexibility of mind when encountering new situations. You will display attention to detail and discretion in dealing with confidential topics and senior stakeholders.

You will need to be analytical and inquisitive, probing for information where appropriate to understand business context and reasoning. You will be a trusted partner for your areas of the organisation and demonstrate an understanding of how to appropriately challenge security decisions, including those made by senior stakeholders.

Person specification

Please refer to Job Description

Benefits

Alongside your salary of £54,358, Ministry of Justice contributes £15,165 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.

Things you need to know

Selection process details

This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours and Experience.https://justicejobs.tal.net/vx/candidate/cms/About%20the%20MOJ

Feedback will only be provided if you attend an interview or assessment.

Security

Successful candidates must undergo a criminal record check. Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check (opens in a new window).

See our vetting charter (opens in a new window). People working with government assets must complete baseline personnel security standard (opens in new window) checks.

Nationality requirements

This job is broadly open to the following groups:

  • UK nationals
  • nationals of the Republic of Ireland
  • nationals of Commonwealth countries who have the right to work in the UK
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
  • individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
  • Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Further information on nationality requirements (opens in a new window)

Working for the Civil Service

The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.

We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window). The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria. The Civil Service also offers a Redeployment Interview Scheme to civil servants who are at risk of redundancy, and who meet the minimum requirements for the advertised vacancy.

Added: 7 months ago