> Markdown version of [/jobs/ext/3059151-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/3059151-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer - **Company:** Public Sector - **Location:** Aberdeen, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Security Management, Cyber Threat Analysis - **Published:** September 25, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1d5a64301d322bf3 ## About the Role * Hands on: willing to both govern and personally deliver key parts of GBE's security capability. * A senior security leader - CISO, deputy CISO or head of security - with a track record in complex, fast-moving organisations, including standing up or substantially rebuilding a security function. * Ownership of security strategy, risk and assurance at executive level, including presenting risk clearly and honestly to boards and audit committees. * Operational depth: accountability for detection, response and incident management, including choosing and directing the right delivery model - in-house, managed service or hybrid. * Depth in security standards and compliance - the NCSC Cyber Assessment Framework, government security standards or comparable regulated regimes - and a record of turning them into practical, proportionate controls. * Desire to keep abreast of the changing landscape of the security and regulatory environment GBE will be exposed to, and the changing nature of GBE's business. * Demonstrable expertise in strategic cyber security planning, cyber security governance, cyber risk management, security architecture and cyber incident management. * Experience securing major technology transitions: cloud adoption, separations from shared or outsourced services, and programmes delivered through multiple partners. * Accountability for the security of personal data under UK GDPR, including breach response. * The communication skills and credibility to make security clear and compelling to executives, boards and non-specialists. * Comfort operating where structures, processes and ways of working are still being established, with the pragmatism to make sound decisions at pace with imperfect information., * Experience in the energy, utilities or critical national infrastructure sectors, including an appreciation of operational technology and the resilience expected of energy systems. * Experience in government, arm's-length bodies or other high-assurance settings, including working with the NCSC. * Experience exiting shared or outsourced services and standing up independently owned security operations. * Recognised security qualifications (such as CISSP or CISM), or an equivalent demonstrable record. Personal Qualities: * Takes ownership, shows confidence in decision-making, and is willing to challenge constructively * Focuses on delivering meaningful outcomes and making a positive, lasting impact * Works collaboratively, valuing different perspectives and building inclusive relationships * Proactive and adaptable, with a curiosity to explore new ideas and improve ways of working * Resilient and resourceful in a fast-paced environment ## Description The role reports to the Chief Digital & Information Officer and is one of the small leadership group standing up GBE's digital function, alongside the CDIO and the Enterprise Architect & Innovation. The postholder is the senior executive accountable for advising on, coordinating and assuring GBE's approach to the NCSC Cyber Assessment Framework and the security of personal data under UK GDPR, and ensures GBE meets the standards expected of both a public body and the energy sector - a sector where the resilience bar is deliberately high., * Take ownership of the security decisions made during the establishment phase: review the recorded decision log, confirm or adjust the recommendations against the evidence, and carry them into delivery. * Establish GBE's security operating model and minimum security requirements as the standard all delivery - internal and partner - works to, leveraging best practice and selecting which of the established ICS security foundations within DESNZ GBE carries forward. * Decide and implement the delivery model for detecting and responding to attacks, with accountability agreed in writing at every stage of the separation from shared services. * Confirm the standards GBE must meet, close the priority gaps, and stand up the assurance regime that reports through the Digital Investment Governance Committee to the Audit, Assurance and Enterprise Risk Committee. * Secure the establishment of GBE's own environments - cloud, collaboration, and staff identity and access - as they stand up, so that new services launch on secure foundations. * Establish incident response for real: plans, roles, on-call arrangements and exercises that prove GBE can handle an incident, not just describe one. * Baseline GBE's security maturity, agree the target state and publish a prioritised security improvement roadmap with clear ownership and measures of progress. * Build security requirements into GBE's procurements and strategic partner framework, and assure the first major deliveries against them. * Build the case and the plan for GBE's permanent security function, growing the capability in step with the estate it protects. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)