CS Interview Coach

Information and Cyber Risk Assurance Advisor

Department for Energy Security & Net Zero

Department
Department for Energy Security & Net Zero
Location
London, Birmingham, Salford, Bristol, Cardiff, Edinburgh, Darlington
Openings
1 post
Grade
Grade 7
Salary
£56,900 to £69,765
Closing
17 days left
Profession
Finance, Operational Delivery
Contract
Permanent
Security clearance
DV
Working pattern
Flexible working, Full-time
Apply on Civil Service Jobs

Job summary

The Integrated Corporate Services (ICS) is a shared corporate service. It provides corporate services (HR, Finance, Digital, Commercial, Security and Estates) across the Department for Energy Security & Net Zero (DESNZ) and the Department for Science, Innovation & Technology (DSIT).

Our team of over 400 professionals will be leading the way in how these functions will be delivered in the future. Our ambition is to be the leading provider of integrated corporate services for government and set the standard for quality, efficiency, and innovation in our field.

We offer great working benefits including a world-class pension, flexible working options and a career where your learning and development is taken seriously. We are enormously proud to be a Disability Confident Leader employer. We support candidates with adjustments throughout our recruitment process. Information about disability confidence and just some examples of the adjustments that you can request can be found in the reasonable adjustment section below.

Find Out More

You can also follow our LinkedIn Careers Page: https://www.linkedin.com/showcase/desnz-careers/

What they’re looking for

  • Lead cyber security risk management and assurance activities within established governance frameworks.
  • Identify, analyse and assess cyber risks to information, systems, platforms and business processes, including threat assessments and risk-based exceptions.
  • Derive and assess security requirements aligned to legislation, policy and recognised standards. Provide proportionate security advice to technical and non-technical stakeholders.
  • Partner with ICS Digital to support live services, incident management, escalations and remediation activities.
  • Provide clear, evidence-based advice on cyber risk, impact and mitigation, enabling informed and auditable business decisions.
  • Produce high-quality risk assessments, assurance reports, recommendations and briefing material for senior stakeholders.
  • Deliver GovAssure activities, including WebCAF development, evidence management, remediation planning and future assurance preparation.
  • Provide security assurance for applications, platforms and services through Secure by Design reviews, penetration testing, architectural governance and go-live assurance.
  • Support cyber security operations, including incident response, operational escalations and on call Duty Officer responsibilities.
  • Develop and maintain cyber security policies, standards and guidance through consultation and governance processes.
  • Act as a trusted advisor to ICS customer including, DESNZ and Arm's Length Bodies, representing the security function at boards, forums and governance groups.
  • Represent ICS and the Department at cross-government security forums, contributing to standards, guidance and best practice.
  • Provide technical leadership and line management to cyber security professionals, supporting capability development, quality assurance and succession planning.
  • Support and deputise for the Deputy Chief Information Security Officer, escalating significant cyber risks and providing leadership when required.
  • As a line manager, set objectives, support development and manage the performance of team members.
  • As a line manager, you will be responsible for working with your members of staff to define their objectives, as well as managing their development and performance.
  • Essential Criteria
  • Information Risk Management: Experience conducting and reviewing cyber risk assessments, evaluating security controls and reporting security risks.
  • Applied Security: Ability to derive security requirements through threat, vulnerability and impact analysis, and apply appropriate security controls.
  • Threat Understanding: Knowledge of the cyber threat landscape and ability to communicate business impacts and risks clearly.
  • Communication: Ability to explain cyber risks, assurance outcomes and recommendations to technical and non-technical audiences.
  • Stakeholder Engagement: Strong relationship-building skills, with experience influencing senior stakeholders and communicating assurance, audit and investigation outcomes.
  • Security Governance and Assurance: Experience reviewing technical and architectural documentation and providing proportionate security assurance.
  • Leadership: Experience providing technical leadership, coaching and line management to cyber security professionals.
  • Desirable Criteria
  • GovAssure: Experience supporting GovAssure or equivalent assurance frameworks, contributing to assessments and recommending remediation activities.
  • Experience representing an organisation or security function in cross government forums, working groups or initiatives.
  • Experience deputising for a senior security leader and supporting escalation and management of material cyber risks.

Behaviours you’ll be assessed on

This advert says the panel will score you against these behaviours at Grade 7 level. Each one links to worked examples.

Job description

Are you interested in joining a high performing team of security professionals? If you are ready to challenge yourself and become a member of a specialist security team, then we have a great opportunity for you.

We need an organised, proactive and flexible individual to provide Information and Cyber Security Risk Management and Assurance functions for ICS HMG customers including — the Department for Energy Security & Net Zero - and within the Departmental Security Unit (DSU), including support to Arm’s Length Bodies.

The Information & Cyber Risk Assurance Advisor identifies, understands and advises cyber related risks affecting information, systems, platforms and business processes. They identify and evaluate security risks across complex digital services and operational environments and proactively provide proportionate, evidence based advice to stakeholders at a variety of levels. The role supports delivery by enabling well informed, auditable, risk based decisions while maintaining appropriate security standards.

The role is operational delivery and technical combining cyber risk management, GovAssure delivery, application and platform assurance and operational security support. The postholder will also provide technical leadership, line management and support and deputise for the Deputy Chief Information Security Officer when required. Your role will also serve as the lead for ICS and its customers on cyber incidents - often at pace – including within significant cross Government activities, contributing your expertise and supporting your peers. When the need arises, you will be expected to deputise for the Deputy CISO.

While some elements of this role can be delivered remotely, the successful candidate will be expected to work from our contracted office a minimum of 40-60% of their time. Regular visits will be required to London and other offices. If not based in the London office, frequent travel to London or other Places for Growth offices may be required, including at short notice or on the same day.

Nationality requirements

This job is broadly open to the following groups:

  • UK nationals
  • nationals of the Republic of Ireland
  • nationals of Commonwealth countries who have the right to work in the UK
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
  • individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
  • Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service

Further information on nationality requirements (opens in a new window)

Selection process

This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours, Experience and Technical skills.

As part of the application process you will be asked to complete a CV, personal statement and a behaviour statement. Further details around what this will entail are listed on the application form.

Please use your personal statement (in no more than 750 words) to outline how your experience and skills fulfil the essential criteria for the post.

Applications will be sifted on a behavioural statement and personal statement.

Please note - the CV incorporated into the application form is for information purposes only and will not be scored.

In the event of a large number of applicants, applications will be sifted on the personal statement only.

Candidates who pass the initial sift may be progressed to a full sift, or progressed straight to assessment/interview.

The interview will consist of behaviour and technical questions, as well as a presentation.

Sift and interview dates to be confirmed.

Further Information

This role is full time only. Applicants who wish to work an alternative pattern are welcome to apply however your preferred working pattern may not be available and you should discuss this with the vacancy holder before applying.

Reasonable Adjustment

We are proud to be a disability confident leader and we welcome applications from disabled candidates and candidates with long-term conditions.

Information about the Disability Confident Scheme (DCS) and some examples of adjustments that we offer to disabled candidates and candidates with long-term health conditions during our recruitment process can be found in our DESNZ Candidate Guidance. A DESNZ Plain Text Version of the guidance is also available.

We encourage candidates to discuss their adjustment needs by emailing the job contact which can be found under the contact point for applicants section.

If you are experiencing accessibility problems with any attachments on this advert, please contact the email address in the 'Contact point for applicants' section.

If successful and transferring from another Government Department a criminal record check may be carried out.

New entrants are expected to join on the minimum of the pay band.

A location based reserve list of successful candidates will be kept for 12 months. Should another role become available within that period you may be offered this position.

Candidates who meet the minimum benchmark may be placed on a Reserve List for consideration for similar roles, including those at a lower grade. Candidates who narrowly miss the benchmark and are not placed on the Reserve List may still be considered for an offer in a similar role at a lower grade.

Please note terms and conditions are attached. Please take time to read the document to determine how these may affect you.

Any move to the Department for Energy, Security and Net Zero from another employer will mean you can no longer access childcare vouchers. This includes moves between government departments. You may however be eligible for other government schemes, including Tax Free Childcare; for further information visit the Childcare Choices website.

DESNZ does not normally offer full home working (i.e. working at home); but we do offer a variety of flexible working options (including occasionally working from home).

DESNZ cannot offer Visa sponsorship to candidates through this campaign. DESNZ holds a Visa sponsorship licence but this can only be used for certain roles and this campaign does not qualify.

In order to process applications without delay, we will be sending a Criminal Record Check to Disclosure and Barring Service /Disclosure Scotland on your behalf.

However, we recognise in exceptional circumstances some candidates will want to send their completed forms direct. If you will be doing this, please advise Government Recruitment Service of your intention by emailing Pre-EmploymentChecks.grs@cabinetoffice.gov.uk stating the job reference number in the subject heading.

For further information on the Disclosure Scotland confidential checking service telephone: the Disclosure Scotland Helpline on 0870 609 6006 and ask to speak to the operations manager in confidence, or email Info@disclosurescotland.co.uk

Applicants who are successful at interview will be, as part of pre-employment screening, subject to a check on the Internal Fraud Database (IFD). This check will provide information about employees who have been dismissed for fraud or dishonesty offences. This check also applies to employees who resign or otherwise leave before being dismissed for fraud or dishonesty had their employment continued. Any applicant’s details held on the IFD will be refused employment.

A candidate is not eligible to apply for a role within the Civil Service if the application is made within a 5 year period following a dismissal for carrying out internal fraud against government.

Feedback

Feedback will only be provided if you attend an interview or assessment.

Practise before you apply

Civil Service panels score every answer against the Success Profiles behaviours at Grade 7 level. Practise STAR answers and get them marked against the same framework.

Start practising free

3 free questions · No card needed

Similar vacancies

Interview articles for Grade 7 roles

All articles

Browse more like this