Scottish Government
Senior Information and Cyber Security Officer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Are you ready to make a real impact in cyber security? We’re looking for an experienced Senior Information and Cyber Security Officer to join our Digital Risk and Security branch at Social Security Scotland. In this key role, you’ll help drive our Security Risk and Assurance programme and strengthen our governance, risk management, and compliance frameworks.
You’ll work at the heart of our security function - partnering with the Cyber Security Risk and Assurance Manager and contributing to the ongoing development of our governance, risk, and compliance capabilities across the organisation.
The ideal candidate can:
- Apply deep expertise in governance, risk management, and assurance, using ISO 27001, NIST 800-53, GDPR, and DPA 2018 to strengthen organisational security.
- Identify, analyse, and mitigate cyber risks, giving stakeholders clear, actionable advice that enables well-informed, auditable decisions.
- Engage and influence stakeholders, lead policy, compliance, and third-party assurance activities, and drive the maturity of security frameworks and the ISMS.
- Contribute to security projects, build security awareness across the organisation, and support incident response to contain and resolve threats.
RESPONSIBILITIES
Responsibilities
- Independently undertake risk management activities within a given area of practice or expertise, usually within established security and risk management governance structures.
- Lead the analysis and derivation of business-supporting security needs, undertake Cyber Security related risk assessments, conduct tailored threat assessment and other risk management activities, and ensure activities are consistent with applicable regulations and legislation.
- Provide tailored advice to a range of stakeholders on how to remedy identified risks by proportionately applying security capabilities, using published guidance, standards, and drawing on a range of experts as well as personal expertise.
- Provide expert security advice that highlights Cyber Security related risks, so risk or service owners can make well-informed and auditable decisions.
Security Leadership & Governance
- Serve as a key point of contact for security advice and guidance.
- Lead security governance groups to promote and maintain strong security practices.
- Help maintain the organisation’s desired cyber security posture in line with its risk appetite.
- Provide leadership and guidance to a small team of security professionals to ensure high-quality service delivery.
Risk Management & Compliance
- Identify, assess, and manage cyber threats and risks to protect organisational assets.
- Conduct compliance audits to ensure adherence to internal and external security requirements.
- Perform internal and external security assessments to evaluate controls and drive continuous improvement.
- Support teams in identifying vulnerabilities, conducting risk and impact assessments, and implementing protective actions.
Policies, Standards & ISMS
- Develop and maintain information security policies, procedures, standards, and guidelines.
- Provide guidance to support the effective adoption of security policies and standards.
- Support and enhance the organisation’s Information Security Management System (ISMS).
Third-Party & Supplier Assurance
- Work with third parties to obtain independent assurance on the effectiveness of security controls.
- Oversee third-party security by assessing supplier controls and ensuring compliance with organisational requirements.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Security Projects & Consultancy
- Lead the design, procurement, and implementation of security projects to strengthen the organisation’s security posture.
- Deliver specialist security consultancy to support successful project outcomes.
Awareness & Incident Response
- Contribute to the development and delivery of a security awareness programme that strengthens the organisation’s security culture.
- Support incident response activities to contain, investigate, and resolve security incidents.
QUALIFICATIONS
Success Profiles
We use an assessment framework called ‘Success Profiles’ which lists the elements we test and provides detailed descriptions of each. Find out more about the framework here [https://www.gov.scot/publications/success-profiles-candidate-guide/].
For this post, the following Success Profile elements will be assessed:
Experience
- In-depth knowledge of information security standards like ISO/IEC 27001 and NIST SP 800-53, combined with understanding of current legislation such as DPA 2018 and GDPR. Proven ability to interpret and apply these standards and legal requirements to ensure compliance and integrate best practices into organisational operations.
- Comprehensive understanding of internal and external information security risks, and proficiency in identifying, assessing, and implementing administrative, physical, and technical controls to mitigate these risks effectively.
Behaviours
- Leadership – Level 3
- Delivering at Pace – Level 3
You can find out more about Success Profiles Behaviours here [https://www.gov.scot/publications/success-profiles-candidate-guide/pages/behaviour-levels/]
Technical / Professional Skills
This role is aligned to Lead Cyber Security Risk Manager within the Digital, Data and Technology Profession.
Please review the following to understand the skill expectations: Cyber Security Risk Manager - Cyber security: advisory - gov.scot [https://www.gov.scot/publications/cyber-security-advisory/pages/cyber-security-risk-manager/#Cyber%20security%20risk%20manager%20lead]
These skills will be tested during the Technical Assessment if you are successful at sift stage. They will not be assessed at application stage.
How to Apply
Apply online, you must provide a CV and Supporting Statement (of no more than 750 words) which provides evidence of how you meet the Experience and Behaviours listed in the Success Profiles above.
Artificial Intelligence (AI) tools can be used to support your application, but all statements and examples provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, and presented as your own) applications will be withdrawn and internal candidates may be subject to disciplinary action.
Please see our candidate guidance [https://www.gov.scot/publications/recruitment-candidate-guide/pages/introduction/]for more information on acceptable and unacceptable uses of AI in recruitment.
An initial sift may be completed using the CV and Supporting Statement against the first Experience criteria. Candidates who pass the initial sift will have their applications fully assessed.
Please note there may be a telephone interview prior to the final interview stage.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Successful candidates will be invited to an interview which will assess the Experience and Behaviours, and a technical assessment comprising a short presentation which will assess the Technical Skills.
Full details of the interview and assessment process will be shared with shortlisted candidates once the sift has been completed.
We aim to provide feedback on request. However, where a large number of applications are received, it may not be possible to give feedback to candidates who are not invited to interview or assessment. Feedback will be available on request to all candidates who attend an interview or assessment.
Expected Timeline (subject to change)
Sift - week commencing 5th October
Interview – week commencing 19th October
Location - In Person in either Dundee or Glasgow
Reserve List
In the event that there are more successful candidates than posts available, a reserve list will be kept for up to 12 months.
About Us
Social Security Scotland is an Executive Agency of the Scottish Government. Our benefits help people from all walks of life in Scotland. We offer rewarding careers and employ people across Scotland in a wide range of professions and roles. We are committed to recruiting a diverse workforce that is representative of the clients we serve. Find more about us here [https://www.socialsecurity.gov.scot/]
We offer a supportive and inclusive working environment along with a wide range of employee benefits. Find out more about what we offer [https://www.jobs.gov.scot/what-we-offer]
As part of the UK Civil Service [https://www.civil-service-careers.gov.uk/about-us/], we uphold the Civil Service Nationality Rules [https://www.gov.scot/publications/recruitment-candidate-guide/pages/nationality-requirements/].
GDD Pay Supplement
This post is part of the Government Digital and Data (GDD) profession and currently attracts a £4,000 annual GDD pay supplement, which is paid monthly. Pay supplements are reviewed regularly.
Working Pattern
Our standard hours are 35 hours per week and we offer a range of flexible working options, depending on the needs of the role. We embrace a hybrid working style where all colleagues will spend time in either our Glasgow or Dundee offices. There is an expectation of a minimum 2 days per week in your assigned location, which will be either Glasgow or Dundee. If you have specific questions about the role you are applying for, please contact us.
Security Checks
This post requires the successful candidate to clear additional National Security Vetting clearance (Security Check) before a start date can be offered. Further information regarding National Security Vetting clearance can be found here - United Kingdom Security Vetting: Applicant - GOV.UK (United Kingdom Security Vetting: Applicant - GOV.UK [https://www.gov.uk/guidance/united-kingdom-security-vetting-applicant])
Equality Statement
Social Security Scotland are committed to equality and inclusion, and we aim to recruit a diverse workforce that reflects the population of our nation.
Social Security Scotland are a Disability Confident Employer. We will consider and implement any reasonable adjustments you may require throughout the recruitment process and during the course of your employment, should you be successful in securing a post. If you feel you may require assistance
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location