Senior Information and Cyber Security Officer

Company: Scottish Government
Apply for the Senior Information and Cyber Security Officer
Location: Dundee
Job Description:

Salary – £49,401 – £59,152 (plus a £5,000 Digital, Data and Technology (DDaT) pay supplement after a 3 month qualifying period)

Location – Dundee or Glasgow

Hours – 35 hours per week

Closing Date – 16th April 2026 at 23:55

Reference – 3512

Employment Type – Permanent

Overview

Are you ready to make a real impact in cyber security? We’re looking for an experienced Senior Information and Cyber Security Officer to join our Digital Risk and Security branch at Social Security Scotland. In this key role, you’ll help drive our Security Risk and Assurance programme and strengthen our governance, risk management, and compliance frameworks.

You’ll work at the heart of our security function—partnering with the Cyber Security Risk and Assurance Manager and contributing to the ongoing development of our governance, risk, and compliance capabilities across the organisation.

The ideal candidate can:

  • Apply deep expertise in governance, risk management, and assurance, using ISO 27001, NIST 800‑53, GDPR, and DPA 2018 to strengthen organisational security.
  • Identify, analyse, and mitigate cyber risks, giving stakeholders clear, actionable advice that enables well‑informed, auditable decisions.
  • Engage and influence stakeholders, lead policy, compliance, and third‑party assurance activities, and drive the maturity of security frameworks and the ISMS.
  • Contribute to security projects, build security awareness across the organisation, and support incident response to contain and resolve threats.

DDaT Pay Supplement

This post is part of the Scottish Government Digital, Data and Technology (DDAT) profession and as a member of the profession you will join the professional development system. The post attracts a £5,000 annual DDAT pay supplement, applicable after a 3‑month competency qualifying period. The payment will be back‑dated to your start date in the role. Pay supplements are reviewed regularly and there is one currently underway; changes will be communicated when the review is concluded.

Main Duties

  • The Senior Information and Cyber Security Officer identifies, understands and mitigates cyber‑related risks, providing advice to help risk or service owners make well‑informed risk‑based decisions.
  • Independently undertakes risk management activities within a given area of practice or expertise, usually within established security and risk management governance structures.
  • Leads the analysis and derivation of business‑supporting security needs, undertakes cyber security related risk assessments, conducts tailored threat assessment and other risk management activities, and ensures consistency with applicable regulations and legislation.
  • Provides tailored advice to stakeholders on remedying identified risks by proportionately applying security capabilities and drawing on published guidance, standards, and experts.
  • Highlights cyber security related risks, enabling risk or service owners to make well‑informed and auditable decisions.

Security Leadership & Governance

  • Serves as a key point of contact for security advice and guidance.
  • Leads security governance groups to promote and maintain strong security practices.
  • Maintains the organisation’s desired cyber security posture in line with its risk appetite.
  • Provides leadership and guidance to a small team of security professionals to ensure high‑quality service delivery.

Risk Management & Compliance

  • Identifies, assesses, and manages cyber threats and risks to protect organisational assets.
  • Conducts compliance audits to ensure adherence to internal and external security requirements.
  • Performs internal and external security assessments to evaluate controls and drive continuous improvement.
  • Supports teams in identifying vulnerabilities, conducting risk and impact assessments, and implementing protective actions.

Policies, Standards & ISMS

  • Develops and maintains information security policies, procedures, standards, and guidelines.
  • Provides guidance to support effective adoption of security policies and standards.
  • Supports and enhances the organisation’s Information Security Management System (ISMS).

Third Party & Supplier Assurance

  • Works with third parties to obtain independent assurance on the effectiveness of security controls.
  • Oversees third‑party security by assessing supplier controls and ensuring compliance with organisational requirements.

Security Projects & Consultancy

  • Leads the design, procurement, and implementation of security projects to strengthen the organisation’s security posture.
  • Delivers specialist security consultancy to support successful project outcomes.

Awareness & Incident Response

  • Contributes to the development and delivery of a security awareness programme that strengthens the organisation’s security culture.
  • Supports incident response activities to contain, investigate, and resolve security incidents.

Further Information

Social Security Scotland are a Disability Confident Employer. We will consider and implement any reasonable adjustments you may require throughout the recruitment process and during the course of your employment, should you be successful in securing a post. If you feel you may require assistance with any part of our recruitment process, please contact us at Recruitment@socialsecurity.gov.scot.

#J-18808-Ljbffr…

Posted: March 29th, 2026