Rodeo
Get started

HM Revenue & Customs

Chief Security Officer

London
£150k/yr
Posted about 24 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Belfast, Birmingham, Cardiff, Edinburgh, Glasgow, Leeds, Liverpool, London, Manchester, Newcastle-upon-Tyne, Nottingham, Portsmouth, Telford, Worthing

Job Summary

Reporting to the Chief Digital and Information Officer (CDIO), the Chief Security Officer is a core member of the CDIO Senior Leadership Team, with overarching responsibility for safeguarding HMRC's information assets, managing security and data protection risks, and setting enterprise-wide security policies and standards across cyber, information, personnel and physical security. This role offers a unique opportunity to influence HMRC’s security agenda across wider government.

Job Description

Security Operations & Risk Management

  • Deliver a range of technical security services across HMRC in an agile and risk-informed way, enabling the organisation to operate securely and effectively at scale.
  • Ensure security and privacy is by design and implementation and that appropriate controls exist throughout CDIO and the wider HMRC business.
  • Strengthen HMRC’s personnel security position by designing and implementing an appropriate personnel security framework.
  • Establishes enterprise-level physical security policy, standards, and assurance frameworks; day-to-day operations are managed by HMRC’s Estates function.
  • Drive the implementation and monitoring of compliance to relevant regulatory and government requirements (e.g., NCSC, ISO 27001).
  • Oversee the identification, evaluation, and reporting of legal and regulatory, IT, and cyber security risk to information assets.
  • Liaise with other functions (Finance, HR, Legal, Ethics) and third parties to ensure security and data protection risks are understood, considered, and satisfactorily mitigated.

Threat Response & Innovation

  • Strategic leadership to identify, understand and effectively address emerging threats such as AI attacks, ransomware, and supply chain vulnerabilities.
  • Ensure appropriate response to security incidents and drive continuous improvements by learning from them.
  • Drive innovation in security technologies such as Zero Trust architecture and secure AI adoption.

Governance, Architecture, and Influence

  • Facilitate an appropriate security governance structure; provide regular reporting on the status of the security and data protection programme to senior leaders, including the Executive Committee and Audit and Risk Committee.
  • Work with the Head of Architecture and Innovation to build alignment between the security and enterprise architectures.
  • Implement and drive policy changes across HMRC and the wider government. Represent HMRC on relevant cross-government boards and engage with the Government Security Group to influence and help deliver the cyber, physical and personnel security policy agenda across government.
  • Liaise with external agencies, such as law enforcement and other advisory bodies, including National Technical Authorities.
  • Build and nurture external networks consisting of peers in government and industry to address common trends, findings, incidents, and cybersecurity risks.

Accountability & Public Trust

  • Define and report on security performance metrics to demonstrate accountability and effectiveness.
  • Promote public trust through transparent security practices and effective communication.

Person specification

Essential Criteria

  • Professional Expertise & Standards - demonstrates a deep and current understanding of information security principles, technologies, and control frameworks. This is evidenced by relevant security qualifications and practical experience, alongside professional certifications such as CISSP, CISM, or equivalent. Shows a strong commitment to delivering against recognised industry standards and best practices.
  • Executive Security Leadership - proven strategic leadership in managing security, risk and compliance across large, complex organisations and technology environments. Brings an outstanding track record of shaping and delivering enterprise-wide security programmes that support organisational resilience and regulatory compliance.
  • Technical Authority & Innovation - extensive technical expertise across multiple domains of security and compliance, with the ability to exercise independent judgment and make high-impact decisions. Demonstrates a forward-looking approach to emerging threats, including experience in researching and implementing innovative solutions such as Zero Trust architectures, secure AI, and other cutting-edge security models.
  • Strategic Influence & Stakeholder Management - exceptional influencing, negotiation, and relationship-building skills, with a proven ability to engage and maintain trust with senior stakeholders across government, industry, and third-party providers. Able to align security strategy with broader organisational goals through effective cross-functional collaboration.
  • Organisational Change & Vision - demonstrable experience in anticipating and preparing for major organisational or technological shifts, including emerging cyber threats. Confidently leads through uncertainty, ensuring the organisation remains agile and informed.
  • Team Leadership & Development - proven ability to build, lead, and develop high-performing teams across multiple locations. Skilled in empowering senior managers and specialists within the security and compliance disciplines, fostering a culture of excellence, accountability, and continuous improvement.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Salary and Benefits

Alongside your salary of £150,000, HM Revenue and Customs contributes £43,455 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).

  • Learning and development tailored to your role
  • An environment with flexible working options
  • A culture encouraging inclusion and diversity
  • A Civil Service pension with an employer contribution of 28.97%

Artificial Intelligence

Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.

Selection Process Details

For full selection process details please see attached Candidate Pack.

Feedback will only be provided if you attend an interview or assessment.

This role has a minimum assignment duration of 3 years. An assignment duration is the period of time a Senior Civil Servant is expected to remain in the same post to enable them to deliver on the agreed key business outcomes. The assignment duration also supports your career through building your depth of expertise.

As part of accepting this role you will be agreeing to the expected assignment duration set out above. This will not result in a contractual change to your terms and conditions. Please note this is an expectation only, it is not something which is written into your terms and conditions or indeed which the employing organisation or you are bound by. It will depend on your personal circumstances at a particular time and business needs, for example, would not preclude any absence like family friendly leave. It is nonetheless an important expectation, which is why we ask you to confirm you agree to the assignment duration set out above.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Security

Successful candidates must undergo a standard (or equivalent) criminal record check.

Successful candidates must meet the security requirements before they can be appointed. The level of security needed is developed vetting (opens in a new window).See our vetting charter (opens in a new window).

People working with government assets must complete baseline personnel security standard (opens in new window) checks.

Nationality Requirements

This Job Is Broadly Open To The Following Groups

  • UK nationals
  • nationals of the Republic of Ireland
  • nationals of Commonwealth countries who have the right to work in the UK
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
  • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
  • individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
  • Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service

Further information on nationality requirements (opens in a new window)

Working for the Civil Service

The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.

We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).

The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.

The Civil Service also offers a Redeployment Interview Scheme to civil servants who are at risk of redundancy, and who meet the minimum requirements for the advertised vacancy.

Diversity and Inclusion

The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).

This vacancy is part of the Great Place to Work for Veterans (opens in a new window) initiative.

Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.

Contact Point for Applicants

Job Contact

Name: Josh Irving
Email: josh.irving@sandersonplc.com

Recruitment Team

Email: scs.resourcing@hmrc.gov.uk

Further Information

Appointment to the Civil Service is governed by the Civil Service Commission’s Recruitment Principles. You have the right to complain if you feel a department has breached the requirement of the Recruitment Principles. In the first instance, you should raise the matter directly with the department concerned. If you are not satisfied with the response, you may bring your complaint to the Commission. For further information on bringing a complaint to the Civil Service Commission please visit their web pages: http://civilservicecommission.independent.gov.uk/civil-service-recruitment/complaints/

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Information Security
Risk Management
Cyber Security
Data Protection
Personnel Security
Physical Security
Governance
Stakeholder Management
Strategic Leadership
Incident Response
Zero Trust Architecture
Secure AI Adoption
Compliance
Policy Development
Enterprise Architecture
Team Leadership

Location

London, England, United Kingdom

Sign up to applySee more jobs like this