CS Interview Coach

HQ Armed Forces Recruiting – Security and Compliance Deputy Lead

Ministry of Defence

Department
Ministry of Defence
Location
Bristol
Openings
1 post
Grade
SEO
Salary
£46,040
Closing
10 days left
Profession
DDaT, Operational Delivery
Contract
Permanent
Security clearance
SC
Working pattern
Flexible working, Full-time, Job share, Part-time
Apply on Civil Service Jobs

Job summary

Want to be at the forefront of delivering secure and compliant digital services for Defence? Join Headquarters Armed Forces Recruiting and help drive the security and assurance activities that underpin a transformational new approach to Armed Forces recruitment.

As Security and Compliance Deputy Lead, you will play a pivotal role in embedding Secure by Design principles, overseeing security risk management, and ensuring adherence to Defence security policies and accreditation requirements. Working across organisational boundaries with Defence Digital, security authorities and industry partners, you will help protect critical systems, support informed risk-based decision making, and enable the successful delivery of a high-profile national programme. This is an exceptional opportunity to influence security strategy, support innovation, and contribute directly to Defence capability and national security.

Would you like to be involved in the start of an exciting new way to deliver recruitment of Armed Forces personnel, for the Royal Navy, Army, and the Royal Air Force?

Headquarters Armed Forces Recruiting (HQ AFR) will deliver integrated tri-service recruitment for the Armed Forces to build and maintain force levels able to meet Defence outputs. The Armed Forces Recruiting Service (AFRS) contract has recently been awarded to Team Serco and collaborative transition activity has now commenced.

A role in HQ AFR is a superb opportunity. You will be at the forefront of a significant change, shaping the future recruitment for all three Services into a tri-Service delivery from 2027 and into steady state. Senior staff across Defence are keeping a keen interest in AFRS, meaning it is high profile, collaborative and engaging environment. You will be working within a diverse team, including military personnel, civilians, and external providers, which provides opportunities for learning and networking. The role offers a real chance to develop skills and demonstrate capabilities, which will provide clear tangible evidence to support you to potentially fulfil your career progression ambitions in the future.

You'd be contributing to the Armed Forces' ability to attract and retain the best talent, ultimately supporting national security.

If you're looking for a challenging, rewarding, and transformative role, this could be a great fit for you.

This position is advertised at 37 hours per week.

Due to the nature of the role, part time and job share arrangements may be considered, subject to the requirement that full-time hours are fully covered (or business needs are met).

What they’re looking for

  • If you can deliver high-class service in a fast-paced environment, you are the type of person we are looking for!
  • We seek a proficient individual who can showcase their expertise and abilities in line with the following essential criteria:
  • Building shared vision and values
  • Promoting and facilitating change
  • Ability to operate sensitively in a fast-paced environment
  • Security assurance experience
  • In addition to the above, although not crucial, it is desirable to have experience in the following:
  • Knowledge of MOD policies, governance, related ethics and strategy
  • Experience in presenting data to inform decision making
  • Experience working with and implementing SbD

Behaviours you’ll be assessed on

This advert says the panel will score you against these behaviours at SEO level. Each one links to worked examples.

Job description

The Security and Compliance Deputy Lead will be an essential member of the Digital & Data team, reporting directly to the Design Assurance Lead. This role is focused on ensuring the Authority's adherence to security policies and risk management frameworks, with an emphasis on Secure by Design, incident management and escalation of security incidents. The security and Compliance Lead is responsible for defining and overseeing the Authority's security approach, selecting risk assessment methodologies, and ensuring compliance with policy. This role will involve close collaboration with internal and external stakeholders to manage risk effectively.

Key responsibilities:

  • Management of programme's Secure by Design (SbD) activity; including liaison with COMD HQ AFR, CyDR Assessor, Network Operating Authority, and the Partner. Accountable for appropriate Security Risk Management processes.
  • Responsible for defining the Authority's security approach, selection of risk assessment methods and identification of control frameworks; ensuring programme compliance with policy e.g. JSP440, JSP 453
  • Lead for SbD and wider accreditation, ensuring Authority and the Partner adhere to policy.
  • Collaborate with Design Assurance for Compliance and Risk matters, including maintenance of security risk registers, mitigations, assumptions, and dependencies.
  • Represent the Authority at Partner security forums and Working Groups.
  • Development and maintenance of Threat Assessments, ensuring the Authority and Partner understand and adhere to security responsibilities.
  • Responsible for ensuring all activity meets JSP 453 accreditation, or assurance as stipulated by policy.
  • Completion of SbD self-assessments and ensuring the Partner’s compliance to Authority processes, procedures and legalities (contract/schedules).
  • Collaborate with the Partner and Authority to ensure engagement with SOC and SPOC in response to incident management.
  • Authority lead for escalating and reporting security related incidents (inc. WARP). Responsible for ensuring technical risk raised by the Partner is elevated to Authority stakeholders.
  • Be the Authority lead for security assurance of any and all AI enable changes, and any Penetration or Ethical Hacking activity, supporting Team Serco governance and change boards.
  • Provide support to Information Technology Security and Risk resolution management.

Nationality requirements

This job is broadly open to the following groups:

  • UK nationals
  • nationals of the Republic of Ireland
  • nationals of Commonwealth countries who have the right to work in the UK
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
  • individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
  • Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service

Further information on nationality requirements (opens in a new window)

Selection process

This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours, Experience and Technical skills.

Your suitability for the role will be assessed using the Success Profile elements that have been chosen for this campaign and includes technical skills (Government Digital and Data Profession Capability Framework - Government Digital and Data Profession Capability Framework). Each element will be scored accordingly, and the successful candidate will be appointed on merit.

Please ensure that at the application and interview stages of the campaign you review the Success Profiles Framework link for information on format and style to assist you in the demonstration of your skills and experience. You have 250 words to answer each Behaviour (competency style).

Candidates will be required to provide CV details to include job history and previous skills and experience.

Candidates will be required to provide a statement of suitability in no more than 500 words which should demonstrate how your experience meets the essential criteria of the role.

At sift, you will be assessed against your CV, Statement of suitability and the following:

Behaviours

  • Making Effective Decisions
  • Seeing the Big Picture
  • Changing and Improving

Technical Skills

  • DDaT - Communication - Practitioner
  • DDaT – Designing Secure Systems - Working
  • DDaT – Enabling & informing risk-based decisions - Working

Applications will be sifted on all Success Profile elements, but in the event of a high number of applications, the sift will be conducted on your Statement of suitability and CV.

At interview, you will be assessed against the following:

Behaviours

  • Communicating and Influencing
  • Working Together
  • Managing a Quality Service

Technical Skills

  • DDaT – Security Technology - Working
  • DDaT – Understanding security implications of transformation - Working
  • DDAT – Communication (Security architect) - Working

Further information:

A minimum of 3 full working days’ notice will be provided for interviews.

The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.

As a result of the changes to the UK immigration rules which came into effect on 1 January 2021, the Ministry of Defence will only offer sponsorship for a skilled worker visa under the points-based system, where a role has been deemed to be business critical. This role does not meet that category, and we will not sponsor a visa. It is therefore NOT open to applications from those who will require sponsorship under the points-based system.

Should you apply for this role and be found to require sponsorship, your application will be rejected and any provisional offer of employment withdrawn.

The Ministry of Defence requires all candidates who are successful at interview to declare any outside interests. These declarations will be discussed with successful candidates following the interview process and before a formal offer of employment is made, as some outside interests may not be compatible with MOD civilian roles. This will not, in the majority of cases, prevent employment in MOD, but it is a measure that must be taken to ensure that appropriate mitigations can be put in place to manage any potential, perceived or actual conflicts of interest from the first day of employment.

The Ministry of Defence adopts a zero-tolerance approach to unacceptable behaviours, which includes bullying, harassment, sexual harassment, discrimination, and victimisation. You will not be eligible and will not be considered for this post if you have been dismissed from a role for such unacceptable behaviours within the last five years. This will also apply if you resign or otherwise leave a role but, because of an adverse decision, would have been dismissed for gross misconduct had you continued in that employment. Pre-employment checks will be carried out.

Feedback will only be provided if you attend an interview or assessment.

Practise before you apply

Civil Service panels score every answer against the Success Profiles behaviours at SEO level. Practise STAR answers and get them marked against the same framework.

Start practising free

3 free questions · No card needed

Similar vacancies

Interview articles for SEO roles

All articles

Browse more like this