Back to search

Data Protection Strategic Lead - 12 Months F/T (Ref: 18512)

Civil Service

Job Description

Job summary

This is a Nationally based role

Job description

Overview of SIG

SID is part of the Service Transformation Group. The Group oversees the building of a strategic vision for modernising and digitising our legacy systems, generating a coordinated plan across the MoJ and its agencies for transformation, and tracking delivery of this transformation.

Security and information management are fundamental building blocks of enabling the department to deliver. We have highly skilled experts working collaboratively with the department, Government Security Group and other partners to enable the whole of the MoJ to function securely, lawfully and transparently.

We identify, manage, and mitigate MoJs security, data protection and information risks, and provide assurance against those risks. Were also home to the Counter Fraud Centre of Expertise. Part of our mission is to up-skill the department so that security becomes second nature to our people and partners

Team Profile The remit of the Data Protection Team covers Headquarters, the five Executive Agencies and 12 Arms Length Bodies.

Their work includes:

  1. Monitoring and overseeing compliance with data protection legislation and MoJ personal data policies
  2. Advising on Data Protection Impact Assessments
  3. Acting as the point of contact with the Information Commissioners Office
  4. Receiving requests from data subjects who wish to exercise their rights to - access, restrict, rectify or erase - their personal data.

Summary

The Role

Were recruiting a Data Protection Strategic Lead here at MoJ (Ministry of Justice) Security and Information Directorate, to be part of our warm and collaborative Data Protection Team.

Knowledge and information are the lifeblood of the MoJ. They can transform the way we deliver public services as well as the relationship between government and public. It is important for the Department to show that we are capable of handling information carefully as well as making it readily available and widely accessible wherever we can and should.  Managing information well can have a direct impact on our ability to deliver core services to our customers.

The Security and Information Directorate is responsible for helping business groups across the department manage and use personal information in a manner compatible with the law.  Its core function is to promote compliance with the Data Protection Act (DPA) 21018 and the UK General Data Protection Regulation across policies, projects, processes and services which involve personal data, through the provision of bespoke advice, training and guidance to business areas.

Reporting to a Deputy Data Protection Officer you will have a leading role in contributing to improvements to the way the department manages its personal data including responsibility for promoting adherence to and providing guidance across a vast spectrum of business areas on information legislation; you will also be part of the management of high impact incidents involving personal data.

Responsibilities, Activities and Duties

The job holder will be required to carry out the following responsibilities, activities, and duties:

Key Responsibilities of the role:

  • Provide advice and guidance on data protection issues for the MoJ and to make decisions on whether to report data breaches to the ICO.
  • Contribute to regular commissions from Government departments to identify the most critical activities and likely risks.
  • Act as point of contact for several of the MoJs Executive Agencies and Arms Length Bodies and the central workstreams covering commercial and contract management, HR, finance and digital/ technology functions. Generating a common interpretation of emerging cross-government guidance, to provide specific interpretations to cultivate a strong MoJ approach towards achieving compliance.
  • Explore and promote critical deliverables on a department-wide basis.
  • Maintaining relationships with appropriate teams / stakeholders in support of delivering UK GDPR/DPA18/DUAA25 compliance across MoJ technology systems.
  • Providing compliance advice and guidance on:
  • The transparency requirements of the UK GDPR and the DPA18
  • Data Protection-by-design and default throughout the data journey and across multiple platforms.
  • The ability of the Department to evidence proactive supplier management and compliance, with expected standards (as a data controller).
  • A long-term compliance plan for information held within systems across the MoJ estate, including new and legacy systems.
  • An incident management process for data incidents and assessing whether data breaches should be reported to the ICO.
  • Providing in the above in liaison with appropriate technical information assurance professionals within the business including:
  • The Information Assurance Leads
  • Senior Information Risk Owners (SIROs) and their delegated Information Asset Owners (IAOs)
  • Senior technical and non-technical stakeholders across Government, including Government Digital Service and Open Government Data

Person Specification:

Essential

The successful role-holder will have:

  • A current, and constantly renewed, understanding of both UK GDPR and the DPA 18/ DUAA25 especially regarding the processing of data for law enforcement purposes and must be able to recognise, and advise upon, the potential impacts of such on MoJs existing and emerging technology systems / projects.
  • A proven track record in developing and leading information assurance strategy in government, including stakeholder engagement, specifically in relation to risk.
  • Proven leadership experience in an information / data management setting.
  • Experience and knowledge of existing working practices within government, including technical security advice, risk management, off-shoring, data protection impact assessments, governance and compliance.
  • Proven ability to adapt to changing priorities and maintain focus and alignment of the teams activities - including experience of the management of a team of information security / assurance specialists.
  • Experience of engaging with stakeholders and staff to resolve business issues and ensure effective and efficient delivery of services.
  • In a comparable business environment, experience of providing evidence based, risk balanced advice to seniors, presenting complex considerations in clear and non-technical terms.
  • Be an effective communicator, who can; discuss and understand technical security controls or systems alongside security professionals and software developers.
  • Explain technical concepts to senior leaders and stakeholders.
  • Communicate risk in a neutral way to allow understanding of impact and likelihood.
  • Demonstrate strong written and verbal communication skills.
  • Be capable of thinking in the style of a threat-actor, to avoid complacency or over-confidence in how we defend the Departments information.
  • Be passionate about technology, technical transformation and technical information security, where keeping up to date is just part of how you work.
  • A data protection/GDPR qualification e.g. CIPP/E or CIPM.

Desirable  

  • Experience of providing data protection advice within a law enforcement or criminal justice environment.
  • Experience of advising on the responsible and lawful use of emerging technologies, AI governance and data ethics

This list is at present and is not intended to be exhaustive. The job holder is expected to accept reasonable alterations and additional tasks of a similar level that may be necessary.

Application Process This vacancy will be assessed using Success Profiles to assess behaviours and technical expertise. The application process will require 250 word STAR format for the identified behaviours, the submission of a CV and a statement of suitability to evidence how you meet the essential and technical criteria required for the role.

In the Civil Service, we use Success Profiles, a flexible framework, to assess candidates against a range of elements using a variety of selection methods, therefore giving you the opportunity to demonstrate the various elements required to be successful in the role.

The sift will be based on the following behaviour:

  • Leadership (lead behaviour)

Leadership will be the lead behaviour, so if there a lot of applicants we will sift solely on this. Note: due to the volume of applications we receive we are unable to provide feedback after the CV review (sift) stage.

Shortlisted candidates will be invited to attend a panel interview and will be requested to deliver a 5-minute presentation with slides to demonstrate their technical analyst skills, plus answer 3 behaviour-based questions.

  • Delivering at pace Interview
  • Working together Interview

Hours of Work/Working Pattern

37 hour working week (standard).

Person specification

Please refer to the Job Description

Yodel are hiring now

Working at Yodel, they promise to support you, develop you and give you all the tools you need to do a great job. They have a range of opportunities across the UK now - why not see if Yodel have the perfect role for you?

See Yodel jobs

Good luck with your application