Security and Information Risk Advisor (4728)
Security and Information Risk Advisor (4728)
Closing Date - 31st August 2026 at 23:55
Reference - 4728
Employment Type - Permanent
Overview
Are you ready to drive effective information security risk management for a vital public service? Join us as a Security and Information Risk Advisor within our Digital Risk & Security branch, where your expertise will guide our commitment to protecting Social Security Scotland.
As a Security and Information Risk Advisor, you will play a pivotal role in providing advice and guidance on the effective specification, implementation, and operation of cyber security controls. Collaborating closely with various stakeholders, you will conduct security risk assessments, investigate major breaches, and contribute to the development of information security policies, standards, and guidelines. This is a key technical position within Digital Risk & Security, focusing on ensuring compliance with legislation, regulation, and relevant standards.
Typical role level expectations
- Provide advice and guidance on security strategies to manage identified risks and ensure adoption and adherence to standards.
- Obtain and act on vulnerability information and conduct security risk assessments and business impact analyses on complex information systems.
- Investigate major security breaches and recommend appropriate control improvements.
- Contribute to development of information security policy, standards and guidelines.
- Interpret information assurance and security policies and apply these to manage risks.
- Use control testing information to support information assurance assessments.
Responsibilities
- Conduct risk-based assurance reviews of internal solutions and third-party suppliers, assessing control effectiveness, identifying risks and vulnerabilities, and recommending remediation activities to support compliance and informed risk-based decision-making.
- Manage complex risks, issues, remediation activities, and lessons learned, applying appropriate risk methodologies and advising on risk impact, tolerance, and mitigation strategies.
- Design and review secure system architectures, applying architectural principles, patterns, and appropriate levels of rigour to deliver effective business outcomes.
- Assess the impact of vulnerabilities, emerging technologies, and developments in security technologies on existing and future systems, recommending appropriate responses and controls.
- Build and maintain effective stakeholder relationships, managing expectations, resolving issues, and facilitating discussions on complex or high-risk matters, often within challenging timescales.
- Represent the security profession and communicate complex technical and risk concepts to a wide range of audiences, both internally and externally.
- Apply knowledge of systems, security, policy, business architecture, and legal or regulatory requirements to develop secure technical solutions and controls.
Further Information
Social Security Scotland are a Disability Confident Employer. We will consider and implement any reasonable adjustments you may require throughout the recruitment process and during the course of your employment, should you be successful in securing a post. If you feel you may require assistance with any part of our recruitment process, please contact us at [email protected].
#J-18808-LjbffrEmail me jobs like this
"Security and Information Risk Advisor (4728)" in Dundee
One click to unsubscribe, any time. We only use your address for this alert.