Back to search

Head of Cyber Security

Civil Service

Job Description

Job summary

The UK Hydrographic Office (UKHO) is seeking an experienced cyber security leader to join its Technology Directorate as Head of Cyber Security (CISO). Reporting to the Chief Digital & Technology Officer, you will lead the organisation's cyber security strategy, governance, risk management and security operations.

As UKHO's cyber security lead, you will work with executive leaders to ensure cyber risks are identified, understood and managed effectively, protecting critical services, sensitive information and national security interests. You will provide leadership across cyber operations, incident response, security assurance, secure-by-design delivery and resilience, while strengthening security awareness and accountability across the organisation.

Working closely with the Ministry of Defence, government security partners, suppliers and internal stakeholders, you will support strategic decision-making and drive continual improvement in cyber maturity and resilience.

We are looking for a proven cyber security professional with experience of developing strategy, leading teams, managing risk in complex environments and advising senior leaders. Strong leadership, stakeholder management and governance skills are essential, alongside recognised qualifications such as CISSP, CISM, CCSP or equivalent.

This is an opportunity to lead cyber security for a nationally important organisation, ensuring the resilience, security and integrity of the UK's hydrographic and geospatial services.

Hybrid working

This job role can be worked on a hybrid basis, which is an informal, non-contractual and voluntary arrangement, working between the office in Taunton and remotely within the UK.

Office attendance is expected 60% of the time. There will be a requirement to attend meetings at higher classifications which will mean office attendance is required.

Job description

  • Provide strategic leadership for cyber security across the organisation, ensuring security priorities support business objectives, operational resilience and national security requirements.
  • Act as the organisations senior cyber security adviser, giving expert guidance to executives and senior leaders on cyber risk, threats, incidents and investment decisions.
  • Own the cyber risk and assurance framework, ensuring risks are identified, assessed, reported and managed appropriately, with clear recommendations for leadership action.
  • Lead the organisations cyber security operations, overseeing threat monitoring, vulnerability management, incident response and recovery activities to maintain a strong security posture.
  • Ensure security is embedded into technology programmes, projects, procurement activities and enterprise architecture, promoting a secure-by-design approach to change delivery.
  • Develop and maintain effective cyber security policies, standards and governance processes, ensuring compliance with MOD, government and regulatory requirements.
  • Build and lead a high-performing cyber security capability, developing skills, setting priorities, managing suppliers and driving continuous improvement across people, process and technology.
  • Strengthen organisational cyber resilience and security culture through stakeholder engagement, awareness initiatives, assurance activities and collaboration with MOD, government and industry partners.

Person specification

  • Proven experience leading cyber security strategy, risk management and resilience within a complex, regulated or mission-critical organisation.
  • Demonstrable ability to advise and influence executive leaders, translating complex cyber and technology risks into clear business decisions.
  • Strong track record of leading cyber security operations, incident response, assurance activities and continuous security improvement programmes.
  • Deep understanding of cyber security governance, secure-by-design principles, regulatory compliance and risk-based decision making.
  • Experience building, leading and developing high-performing cyber security teams, including the management of suppliers and outsourced services.
  • Relevant professional cyber security qualifications (e.g. CISSP, CISM, CCSP or equivalent) supported by ongoing professional development and a commitment to maintaining technical credibility.

Yodel are hiring now

Working at Yodel, they promise to support you, develop you and give you all the tools you need to do a great job. They have a range of opportunities across the UK now - why not see if Yodel have the perfect role for you?

See Yodel jobs

Good luck with your application