Women in Tech
Chief Information Security Officer - Disclosure & Barring Service - SCS1

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Location
Remote working (anywhere in the UK)
About The Job
Job summary
DBS was established under the Protection of Freedoms Act 2012 on 1 December 2012, working from two sites, which are Liverpool and Darlington. We operate on behalf of government delivering Disclosure functions in England, Wales, Jersey, Guernsey and the Isle of Man, and Barring functions for England, Wales, and Northern Ireland. We function within a framework of legal and regulatory requirements and that includes work with a range of external organisations including other government departments, regulators, and trade bodies.
We provide a service that enables organisations in the public, private and voluntary sectors to make better informed, safer recruitment and other decisions. We do this by providing information to enable them to determine whether individuals are unsuitable or unable to undertake certain work, particularly with occupations involving regular contact with vulnerable groups, including children.
Our Strategy
Our current Strategy sets out our purpose, vision, and the impacts we want to achieve. Our strategy was co-created with our staff and has been supported by insight from our various partners, and throughout, you will find our ambitions to be achieved. Everything that we do within DBS, from developing our strategic intent, to the day-to-day operational delivery of our services, is underpinned by constant considerations of safeguarding, quality, sustainability, value for money, and diversity and inclusion. Our strategic objectives aim to enhance our effectiveness, influence, and customer satisfaction while fostering a supportive environment for everyone.
Equality, Diversion, and Inclusion at DBS
DBS is committed to fostering an environment that values individual differences and ensures fair treatment to unlock the full potential of staff and better support customers. Equality, diversity, and inclusion (EDI) are core to driving organisational success and we have developed specific equality objectives for DBS.
Every decision and activity will be considered through an EDI lens, aiming to build an inclusive culture, improve policies and practices, gain external assurances, and become a leading voice of good practice in EDI.
Read More
For further information, please see below for a collection of DBS strategies and business plans:
- DBS strategies - GOV.UK
- DBS business plans - GOV.UK
Job Description
Job Purpose:
The Chief Information Security Officer will provide senior organisational leadership for information, cyber, operational security and data protection across DBS, setting and implementing a clear strategy that supports DBS’s organisational strategy, safeguarding mission, digital transformation priorities, statutory data protection duties and wider government security expectations. The role will also act as DBS’s Data Protection Officer, providing independent advice, challenge and assurance on compliance with UK GDPR, the Data Protection Act 2018, law enforcement processing requirements where applicable, organisational data protection policies and ICO expectations. The role will be accountable for the effective operation of security controls, monitoring, incident management, vulnerability management, supplier security and operational security assurance across live services and change activity. The role will evaluate DBS’s current information and cyber security maturity, define the level of maturity needed for a modern, resilient and digitally enabled safeguarding organisation, and lead the practical plan to close that gap. The post holder will create the environment, culture and operating model needed to protect DBS information, personal data, technology and services, enabling innovation to happen safely, lawfully and securely while ensuring DBS can prepare for, detect, respond to and recover from cyber attacks.
This is a senior leadership role, not a purely technical cyber post. The successful candidate will be expected to understand risks across DBS, advise the Board, Executive Team, SIRO and senior leaders on how to mitigate cyber, information and data protection risks in their areas and future plans, and ensure the information security, cyber security and data protection aspects of crisis management are effective. As Data Protection Officer, they must be involved in a timely manner in issues relating to the protection of personal data, provide expert advice on data protection obligations and DPIAs, monitor compliance, support awareness and training, and act as a contact point for the Information Commissioner’s Office. They will translate complex cyber, information risk, privacy and resilience issues into clear choices for executive decision-makers, while building a capable, sustainable and accountable security and data protection function that supports DBS’s transition to modern digital services, a secure-by-design model and a stronger Target Operating Model.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Corporate Duties
- Act as DBS’s senior organisational leader for information security, cyber security, operational security and data protection, setting direction and providing clear, evidence-based advice to the Executive Director of Technology and Innovation, Board, Executive Team, Audit and Risk Committee, SIRO and senior risk owners.
- Create, own and lead the DBS information, cyber and operational security strategy and roadmap, ensuring it directly supports the organisation’s strategy, safeguarding mission, digital transformation, live service resilience and wider government security strategy, including Government Functional Standard GovS 007: Security, the Government Cyber Security Standard, the Cyber Assessment Framework, GovAssure, Secure by Design principles and relevant NCSC guidance.
- Lead the organisation in implementing the information, cyber and operational security strategy, turning strategic intent into clear priorities, funded delivery plans, measurable outcomes, operational controls and mature security practices embedded across DBS.
- Act as DBS’s Data Protection Officer, operating with the independence, senior access, expertise and resources required by data protection law, and providing advice, challenge and assurance on UK GDPR, the Data Protection Act 2018, law enforcement processing requirements where applicable and wider data protection obligations.
- Shape a new cyber operating model for DBS, defining the right balance of in-house capability, specialist consultancy, supplier support and managed services, with clear accountabilities, decision rights and routes for increasing maturity over time.
- Be accountable for operational security across DBS technology services, ensuring effective security monitoring, protective controls, access management, vulnerability management, threat intelligence, security operations, incident triage and remediation are in place and operating effectively.
- Build organisational confidence in cyber security by translating technical risk into plain English, proportionate choices and practical action for executive, operational and delivery audiences.
- Advise the Board, Executive Team and senior leaders on organisational cyber and information risk, helping them understand their accountabilities and make proportionate decisions to mitigate risk in current operations, change programmes and future plans.
- Advise the Board, Executive Team, SIRO, Information Asset Owners and senior leaders on data protection risk, privacy by design, lawful processing, data sharing, retention, data subject rights, personal data breaches and the implications of new services, technology and operating models.
- Promote a culture where secure behaviours, cyber awareness and good information handling are understood as core responsibilities for everyone, not just the security function.
- Work as a senior member of the Technology and Innovation leadership team, contributing to departmental strategy, prioritisation, culture, financial control, supplier management and the successful delivery of DBS’s technology ambitions.
- Represent DBS with Home Office, Cabinet Office, Government Security, NCSC and other external partners where required, ensuring DBS is aligned to relevant government security policy, standards, assurance expectations and good practice.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Operational Delivery Duties
- Evaluate the current status and maturity of DBS information and cyber security, using recognised government and industry frameworks where appropriate, and define the practical route to the level of maturity required for a modern, resilient and digitally enabled safeguarding organisation.
- Establish effective cyber governance, reporting and assurance, giving senior leaders a clear view of risk, control effectiveness, investment choices, incidents, vulnerabilities and supplier exposure.
- Own and continually improve the operational security model for DBS, including security operations, monitoring, alerting, incident triage, vulnerability management, patching oversight, privileged access controls, protective monitoring, threat-led assurance and supplier operational security performance.
- Ensure DBS can demonstrate alignment with relevant government security requirements and assurance routes, including GovS 007, the Government Cyber Security Standard, CAF profiles, GovAssure, Secure by Design, NCSC guidance, the Technology Code of Practice and applicable data protection and information assurance obligations.
- Monitor DBS compliance with UK GDPR, the Data Protection Act 2018, applicable law enforcement processing requirements, organisational data protection policies and ICO expectations, ensuring responsibilities are clear, evidence is maintained and improvement actions are tracked to completion.
- Provide advice on Data Protection Impact Assessments, privacy by design, records of processing activity, data sharing, data subject rights, retention, lawful basis, special category data, criminal offence data and personal data breach management.
- Act as the primary contact point for the Information Commissioner’s Office on data protection matters and ensure DBS can evidence timely, well-governed handling of regulatory engagement, personal data breaches and data protection assurance activity.
- Work with service owners, product teams, architecture, suppliers and operational teams to ensure security controls remain effective in live service, are monitored through clear metrics, and are improved where risk, threat or operational performance requires it.
- Determine the controls, capabilities, investment, skills, supplier arrangements and behavioural changes needed to reach the target level of maturity and hold delivery partners to account for progress.
- Ensure DBS is prepared for cyber-attacks and can detect, respond to and recover from incidents, with clear crisis arrangements, tested playbooks, escalation routes, communication plans and links into wider business continuity, operational resilience and crisis management arrangements.
- Provide senior security leadership into major change and digital transformation, including any major transformation of platforms, data, integration and service modernisation activity.
- Lead proportionate security assurance across new products, systems, services and suppliers so that security is designed in early, risks are understood, decisions are auditable and innovation can proceed safely rather than being slowed by late-stage security intervention.
- Develop cyber awareness, data protection awareness, information handling discipline and good security behaviours across DBS, embedding practical guidance, learning and leadership messages that make secure, lawful and responsible handling of information part of everyday
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location