Back to search

Deputy Chief Information Security Officer

Civil Service

Job Description

Job summary

The MOD's digital teams ensure we remain among the most technologically advanced Armed Forces in the world. We develop and lead in cutting-edge data science, automation, and cybersecurity solutions to protect the UK and its interests, at home and abroad. Our mission also goes beyond the battlefield by leading humanitarian efforts and driving innovation that impacts lives across the globe.

Watch our video to see what we do!

Job description

This role places cyber security at the heart of UK Defence. This is a rare opportunity to step into a senior cyber leadership role with real national impact. Youll shape and lead cyber risk strategy for key digital capabilities, influencing outcomes across Defence while focusing on delivery within your specific remit. Working at the centre of decision-making, youll engage senior leaders, embed secure-by-design principles, and strengthen the resilience of systems that support the UKs security today and into the future.

Working under the National Armaments Digital & Data Chief Information Security Officer (NAD D&D CISO) mandate, youll drive accountability for secure capability delivery in support of the Defence Cyber Resilience Strategy. This is a high-impact role where youll shape cyber direction, influence senior leaders, and manage risk across a complex organisation, acting as a trusted advisor to enable innovation while strengthening resilience and cyber culture.

What youll be doing

  • Set and lead cyber risk strategy across a complex digital environment, driving secure-by-design across programmes and services.
  • Establish and embed effective governance, risk and compliance frameworks, ensuring alignment with Defence policy and evolving threats.
  • Provide assurance on audit, compliance and reporting, while ensuring consistent application of core security principles.
  • Use data and tooling to strengthen cyber insight and assess risk across NAD D&D capabilities, informing the wider Defence picture.
  • Act as a key cyber security lead within the wider Defence community, influencing stakeholders and building strong partnerships.
  • Lead, develop and inspire a high-performing cyber workforce, promoting a strong security culture across the organisation.

Youll lead cyber incident response and risk management, ensuring effective oversight of high-risk systems and driving continuous improvement in mitigation and resilience. The role is responsible for holding delivery programmes to account for the development, testing, and maintenance of robust incident response plans, working closely with Defence incident reporting teams. It plays a key part in strengthening organisational readiness by assuring, challenging, and enhancing response capabilities across NAD-D&D.

More information on the role can be found on The Government Security Profession Career Framework: Government Security Profession career framework.

Person specification

Were seeking a confident, credible cyber leader with a proven track record of strengthening security in complex, high-stakes environments. Youll bring deep experience in Cyber and Information Security, with the ability to design and embed effective risk management frameworks that drive continuous improvement. Youll excel at engaging and influencing senior audiences, translating complex technical risks into clear, actionable business insight, and shaping strategic decisions on risk posture, investment and compliance. Youll champion a positive cyber culture, helping the organisation meet its obligations while delivering a secure, high-quality service.

With strong analytical thinking and sound judgement, youll bring clarity to risk, set direction and drive plans through to impact. Youll also lead responses to incidents, audits and remediation activity, ensuring robust plans are in place and effectively delivered.

When submitting your CV, please highlight your career history and experience relevant to this role. Additionally, refer to the "Things You Need to Know" section of the advert and provide a personal statement (max. 1250 words) demonstrating the essential criteria listed below

  • Describe your experience of managing cyber security governance, risk and compliance aspects within an organisation.
  • Provide an example of when you have managed a Cyber Security incident, the approach used and the outcome.
  • Describe your experience of leading, managing and developing a team and of resources not owned by the organisation.

Want to learn more? Join our Candidate Brief

Get a real insight into the role by joining an informal session with senior members of the team, where they will share what were looking for and give you the opportunity to ask questions. The session will take place on the date listed below and to register, please email [email protected] with the CSJ reference number, your name and email address, and well send you a Microsoft Teams invite.

  • 27/07/26 at 5pm

Please note:

  • This position is advertised at 37 hours per week.
  • This role is open to UK sole nationals only.
  • Developed Vetting (DV) clearance is required. If you do not already hold this, you will need to obtain it if appointed to the role.
  • There will be regular travel to other sites (approximately 24 times per month), in addition to attendance at the MOD Main Building.
  • At the time you will be assessed under the relevant criteria to ensure you meet the Digital Skills Allowance eligibility. Allowance values are determined by capability level and your substantive grade: Level 1 (Developing) 6,000, Level 2 (Proficient) 12,000and Level 3 (Accomplished) 18,000. London locations may attract an allowance of up to 3,300 per annum.

Yodel are hiring now

Working at Yodel, they promise to support you, develop you and give you all the tools you need to do a great job. They have a range of opportunities across the UK now - why not see if Yodel have the perfect role for you?

See Yodel jobs

Good luck with your application