> Markdown version of [/jobs/ext/3257128-senior-information-and-cyber-security-officer](https://www.wearedevelopers.com/jobs/ext/3257128-senior-information-and-cyber-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information and Cyber Security Officer - **Company:** Scottish Government - **Location:** Glasgow, UK - **Experience:** Expert - **Salary:** £48,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Information Security Management System, Cybercrime - **Published:** September 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0ecbe1033aa8022b ## About the Role * In-depth knowledge of information security standards like ISO/IEC 27001 and NIST SP 800-53, combined with understanding of current legislation such as DPA 2018 and GDPR. Proven ability to interpret and apply these standards and legal requirements to ensure compliance and integrate best practices into organisational operations. Comprehensive understanding of internal and external information security risks, and proficiency in identifying, assessing, and implementing administrative, physical, and technical controls to mitigate these risks effectively. * ## Description You'll work at the heart of our security function - partnering with the Cyber Security Risk and Assurance Manager and contributing to the ongoing development of our governance, risk, and compliance capabilities across the organisation., * Apply deep expertise in governance, risk management, and assurance, using ISO 27001, NIST 800-53, GDPR, and DPA 2018 to strengthen organisational security. * Identify, analyse, and mitigate cyber risks, giving stakeholders clear, actionable advice that enables well-informed, auditable decisions. * Engage and influence stakeholders, lead policy, compliance, and third-party assurance activities, and drive the maturity of security frameworks and the ISMS. * Contribute to security projects, build security awareness across the organisation, and support incident response to contain and resolve threats., Please see our candidate guidance for more information on acceptable and unacceptable uses of AI in recruitment. An initial sift may be completed using the CV and Supporting Statement against the first Experience criteria. Candidates who pass the initial sift will have their applications fully assessed. Please note there may be a telephone interview prior to the final interview stage. Successful candidates will be invited to an interview which will assess the Experience and Behaviours, and a technical assessment comprising a short presentation which will assess the Technical Skills. Full details of the interview and assessment process will be shared with shortlisted candidates once the sift has been completed. We aim to provide feedback on request. However, where a large number of applications are received, it may not be possible to give feedback to candidates who are not invited to interview or assessment. Feedback will be available on request to all candidates who attend an interview or assessment., * Independently undertake risk management activities within a given area of practice or expertise, usually within established security and risk management governance structures. * Lead the analysis and derivation of business-supporting security needs, undertake Cyber Security related risk assessments, conduct tailored threat assessment and other risk management activities, and ensure activities are consistent with applicable regulations and legislation. * Provide tailored advice to a range of stakeholders on how to remedy identified risks by proportionately applying security capabilities, using published guidance, standards, and drawing on a range of experts as well as personal expertise. Provide expert security advice that highlights Cyber Security related risks, so risk or service owners can make well-informed and auditable decisions. * Security Leadership & Governance * Serve as a key point of contact for security advice and guidance. * Lead security governance groups to promote and maintain strong security practices. * Help maintain the organisation's desired cyber security posture in line with its risk appetite. Provide leadership and guidance to a small team of security professionals to ensure high-quality service delivery. * Risk Management & Compliance * Identify, assess, and manage cyber threats and risks to protect organisational assets. * Conduct compliance audits to ensure adherence to internal and external security requirements. * Perform internal and external security assessments to evaluate controls and drive continuous improvement. Support teams in identifying vulnerabilities, conducting risk and impact assessments, and implementing protective actions. * Policies, Standards & ISMS * Develop and maintain information security policies, procedures, standards, and guidelines. * Provide guidance to support the effective adoption of security policies and standards. Support and enhance the organisation's Information Security Management System (ISMS). * Third - Party & Supplier Assurance * Work with third parties to obtain independent assurance on the effectiveness of security controls. Oversee third-party security by assessing supplier controls and ensuring compliance with organisational requirements. * Security Projects & Consultancy * Lead the design, procurement, and implementation of security projects to strengthen the organisation's security posture. Deliver specialist security consultancy to support successful project outcomes. * Awareness & Incident Response * Contribute to the development and delivery of a security awareness programme that strengthens the organisation's security culture. * Support incident response activities to contain, investigate, and resolve security incidents. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Edit Your Future: Queerverse Radical AI](https://www.wearedevelopers.com/videos/909-edit-your-future-queerverse-radical-ai) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Scotland Public Holidays 2024](https://www.wearedevelopers.com/magazine/431-scotland-public-holidays-2024) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)