Security and Information Risk Advisor (4728)
- Civil Service
- Full Time
- Dundee
- 39,767 - 45,472
Job Description
Job summary
GDD Pay Supplement
This post is part of the Government Digital and Data (GDD) profession and currently attracts a 4,000 annual GDD pay supplement, which is paid monthly - pay supplements are reviewed regularly.
Job description
Responsibilities
- Conduct risk-based assurance reviews of internal solutions and third-party suppliers, assessing control effectiveness, identifying risks and vulnerabilities, and recommending remediation activities to support compliance and informed risk-based decision-making.
- Manage complex risks, issues, remediation activities, and lessons learned, applying appropriate risk methodologies and advising on risk impact, tolerance, and mitigation strategies.
- Design and review secure system architectures, applying architectural principles, patterns, and appropriate levels of rigour to deliver effective business outcomes.
- Assess the impact of vulnerabilities, emerging technologies, and developments in security technologies on existing and future systems, recommending appropriate responses and controls.
- Build and maintain effective stakeholder relationships, managing expectations, resolving issues, and facilitating discussions on complex or high-risk matters, often within challenging timescales.
- Represent the security profession and communicate complex technical and risk concepts to a wide range of audiences, both internally and externally.
- Apply knowledge of systems, security, policy, business architecture, and legal or regulatory requirements to develop secure technical solutions and controls.
Person specification
Success Profiles
We use an assessment framework called Success Profiles which lists the elements we test and provides detailed descriptions of each. Find out more about the framework here.
For this post, the following Success Profile elements will be assessed:
Experience:
- Knowledge of information security standards like ISO/IEC 27001 and NIST SP 800-53, combined with understanding of current legislation such as DPA 2018 and GDPR. Proven ability to interpret and apply these standards and legal requirements to ensure compliance and integrate best practices into organisational operations.
- Demonstrable ability to evaluate the effectiveness of technical, physical, procedural, and personnel controls, recommend improvements, and work with stakeholders to implement proportionate risk mitigation measures that strengthen the organisation's overall security posture.
Behaviours:
- Communicating and Influencing - Level 3
- Delivering at Pace - Level 3
You can find out more about Success Profiles Behaviours here.
Technical/Professional Skills:
This role is aligned to Security and Information Risk Advisor within the Government Digital and Data Profession.
These skills will be tested during the Technical Assessment if you are successful at sift stage. They will not be assessed at application stage. Please review the following to understand the skill expectations: Security and information risk - Information Assurance and Security: Security and information risk - gov.scot