As a Council, we are striving to champion cyber and information security and are in the midst of delivering an incredibly ambitious agenda for change with a large emphasis on technological innovation. A key role in leading and delivering this change is the Head of Information Security.
As part of this senior leadership role, you will be required to provide leadership across and beyond the Council to support, guide and direct the implementation of appropriate technical and organisational measures to ensure a level of security appropriate to the risk for all information assets.
Key Responsibilities
Strategy
- Develop and deliver business-aligned information security strategic objectives
- Establish and refresh annually a comprehensive information security framework and program.
- Create and report on information security success targets.
- Maintain a yearly information security roadmap aligned with business risk appetite.
- Present roadmap status updates to the board and executives.
Risk Management
- Conduct business and information security risk assessments.
- Maintain an Information Security Management System
- Manage third-party information security risk framework and program.
- Facilitate responses to internal and external security audits and assessments.
- Perform risk assurance reviews and assist in cyber insurance policy assessments.
Governance
- Provide guidance to board, executives, and business units on information security and risk.
- Develop executive-level security updates and reports for governance purposes.
- Lead the development of information security policies, standards, and controls.
- Collaborate with Information Governance to meet privacy legislation requirements.
Operations
- Deliver council-wide information security training and awareness programs.
- Develop and test incident response plans and manage incidents effectively.
- Coordinate penetration tests, disaster recovery, and business continuity planning.
- Ensure vulnerability and patch management services meet service levels.
- Oversee and manage the effectiveness of MDR, SIEM, and SOAR services.
- Own security risk assessments for applications, infrastructure, and network architecture.
Understanding the Business
- Develop a deep understanding of council, partners and local businesses, where relevant.
- Keep abreast of industry, regulatory, statutory and contractual obligations.
Regulatory Requirements
- Ensure compliance with council policies and regulatory requirements, including but not limited to the PSN, DPST, CAF, PCI-DSS and achievement of CAF for Local Government standards
Experience needed
Strong Cyber leadership credentials including experience of successfully driving the cyber security agenda in a complex matrixed organisation, preferably in a local government authority.
Proven ability to shape and then successfully execute an enterprise-level cyber security strategy in both technical, policy and process areas.
Demonstrable experience of use and implementation of cyber security frameworks and practices, including adoption of CAF for Local Government and evolving Information Security Management Systems/Risk Frameworks.
Demonstrated capability to plan over short, medium and long-term timeframes and adjust plans and resource requirements accordingly, whilst ensuring alignment with desired outcomes and organisational risk appetite.
Highly effective oral and written communication and an ability to provide clear and concise advice to senior management regarding cyber security.
Excellent stakeholder influencing skills at a senior level, with proven ability to engage support across the organisation for the cyber agenda.
A leadership style of leading from the front, ensuring visibility, effectively engaging and communicating to staff and delivery partners regarding the criticality of cyber security and risk management.
Extensive experience of executing cyber security approaches which conform to standard patterns of good practice. An expert in IT Risk Management with practical experience of delivering risk and information system control management.
Professional certifications such as CISM, CISSP, CISA as a minimum.