Technical Security Lead

Information Commissioner’s Office

The ICO exists to empower you through information, https://ico.org.uk/about-the-ico/jobs/


Requirements of the role

Location: Hybrid

Contracted to our Wilmslow, London, Edinburgh, Cardiff or Belfast office, however, we offer flexible home and office-based working opportunities. There will be times when you will be expected to attend the office to collaborate with colleagues or travel due to business need. 

Why work for the ICO?

Pay progression scheme.
Hybrid and flexible working options. 
25 days paid holiday per year, plus privilege and public holidays.
Flexi leave (up to 26 additional days leave per year).
Pension (employer contribution around 28.9%).
Online discount scheme to save money at major supermarkets, retailers, gyms, restaurants, insurance providers and many more.
Health Cash Plan.
Fantastic development opportunities to learn and progress.
Further details can be found on the benefits section of our website .

Job summary

The ICO Cyber security team is expanding. This represents an exciting time to join the team, bringing your experience and capabilities as well as potential to learn and develop, in a high profile and dynamic environment. The Cyber Security team is part of our wider Digital, Data and Technology (DDaT) directorate, and ensures that we support the objectives of secure by design.

The Information Commissioner’s Office (ICO) is the independent regulator of information rights. In a data-driven world, we provide advice, guidance, and support to organisations enabling compliance with their obligations, as well as protecting individuals and their personal data.

As an employer, we are passionate about making a positive difference to the lives and careers of our people, and we empower you to be curious, impactful, collaborative and respectful.

Job description

This post is responsible for leading technical security delivery for the ICO linked to our obligations of the UK Government Cyber Security Strategy and based on the outcomes defined in Functional Standard “GovS 007 – Security”.

Focused on key areas of technical controls, Security by Design, security engagement for new development and system changes, staff education and ensuring the adherence to corporate policies, controls, and industry best practices.

You will lead and deliver technical security engagements across the ICO providing Security requirements, Advice and Guidance, technical leadership and oversight of security controls for all new developments, or technical changes to existing systems or services.

In collaboration with the wider Cyber Security team, the ICO Digital, Data and Technology product owners; you will review all areas of technical security and best practices, including ensuring our high value assets are secured and controlled in line with the corporate, business and technical risk appetites, and the production of security opinion reports on gaps, risks and mitigation recommendations.

You will also lead the delivery of secure by design, through the production, review and publishing of baseline security requirements aligned to relevant security frameworks and other guidance. e.g. NCSC CAF, NIST CSF, CSA CCM and Gov Functional Standards. Which will include providing technical security advice guidance and oversight to Technical Design Authority, Change Advisory Board and Data Protection Impact Assessment forums.

As part of the Cyber Security Team, you will provide technical expertise and practical experience to drive ICO processes, policies and education, and to deliver appropriate and proportionate direction, on technical security issues and challenges.

You will be cognisant of the threat landscape across the regulatory sector and at national levels; and that our technical controls for our key systems and assets are appropriately secured, assessed and monitored.

Supporting the creation and updating of technical baseline security requirements, for the core ICO services, will be a key delivery of the role.

Key responsibilities:

Lead the delivery of secure by design principles and guidance
Delivery of technical security requirements in collaboration with the wider DDaT and Cyber Security team.
Align Project and change security governance with the relevant security frameworks
Lead the delivery of security opinion reports providing specialist advice and technical leadership
Technical security collaboration both internally to the ICO and with external partners


View on member website

View

 Location

Wilmslow

 Contract type

Full time, Permanent

 Profession

Cyber, Data, Security


 Working pattern

Flexible working, Hybrid

 Closing Date

03/05/2025