Apply Now
Details
Reference number
Salary
Civil Service Pension with an average employer contribution of 27%
Job grade
Contract type
Business area
Type of role
Information Technology
Security
Working pattern
Number of jobs available
Contents
Location
About the job
Job summary
The Forestry England IT team provides IT capabilities to the Forestry Commission; Forestry England, Forest Services and the Commissioners Office. This consists of the provision of managed services, systems and devices to ~1900 staff across a broad range of roles and diverse business functions across England, supporting the Forestry Commissions mission to manage, protect and expand the nations woods and forests. The team consists of highly-skilled in-house IT specialists, supported by third-party service-providers and suppliers.
This role provides a well organised and ambitious member of staff with an excellent opportunity to join the Forestry England IT Security, Risk and Compliance team, working to take forward and develop our IT governance, risk-awareness, security, and compliance obligations in a dynamic IT department, furthering the Forestry Commissions unique mission and heritage.
Job description
The IT Security Governance and Process Manager (ITSGPM) will take a lead role in ensuring that our IT Security Governance is robust, current, and fit for purpose, while fully complying with both legal and HM Government security requirements. Working under the direction of the IT Security Compliance & Risk Manager (ITCRM) to ensure effectiveness and consistency of approach. The ITSGPM will work to understand and identify the security-risks associated with Forestry Commission processes and security governance, review security governance frameworks. A large part of the work will include staff-collaboration, communicating and articulating security requirements, with ownership of security training and work to improve our security culture. The post holder will be an IT Security Manger with a particular focus on furthering our IT Security governance, and improving our security-culture and the security-behaviours of our staff. Your remit will cover Forestry England, Forest Services and the Commissioners Office.
Key Work Areas
Key Work Area 1 Improving Security Governance, Policy and Procedures
The post holder will have responsibility for overseeing, shaping and governing the IT security governance framework within Forestry England and will manage day-to-day security-governance and people-security requirements. Youll be our governance, personnel and behavioural-security Subject Matter Expert. Responsibilities will include:
- You will own the governance downstream processes of Manage, curate, and regularly review and amend existing and new IT Security articles of governance to ensure alignment to business direction, other security and information risk policies, legal requirements, government guidelines and sound business practices, to meet and enable business need.
- Youll drive the improvement and leveraging of our established framework of security-governance to best effect. Youll also lead on promoting this to the wider business and lead reporting on implementation, enforcement and compliance metrics.
- Youll be responsible for formal audit, assurance and accreditation programmes as directed, building upon the ITCRMs efforts to comply with internal requirements or through compliance with HMG obligations.
- Youll be accountable for monitoring, recording and reporting of security metrics across the IT estate for a variety of consumers and needs. Youll achieve this through collaboration with the IT Security Systems Manager and other IT roles. Youll lead on requirements but be guided by others of our capabilities.
- Youll own and lead projects and workstreams that support the IT Compliance & Risk Manager with governance and process implementation, and enforcement activities, which support the IT Security strategy, programme and policy development.
- Youll lead on reporting from your area of responsibility, and contributing this to the purpose of the Security and Risk Management Forum (SRMF) as required, reporting on events and incidents, articulating and addressing these in cultural and behavioural terms, and reporting on project progress and next-steps.
- Youll be a key member of various groups and be expected to play a pivotal role in Disaster Recovery, Incident Management and Business Continuity scenarios.
Key Work Area 2 Improving IT Security Behaviours and Culture
The post holder will be one of our IT Security Subject Matter Experts and will be jointly responsible for providing information, and approved advice and guidance across the business and for helping to drive beneficial IT security change.
- Youll ensure that pragmatic and workable IT security advice is provided to the wider business and stakeholders where appropriate. Provide an escalation point for IT process-driven and people-security risks and incidents, ensuring that staff and managers are provided with clear, unambiguous instruction to follow when you are mitigating or remediating risks or incidents.
- Promote compliance with, and continued awareness of, the IT Security governance framework. Provide input across the business to evaluate, encourage, guide or change security improvements within processes at all stages of task and business unit life-cycles, through planning, procurement, design, build, delivery and production. Youll focus on people-security to achieve this.
- Fully understand the environment, business processes, threats and risks that influence processes, information and staff. Work to identify areas where sub-optimal work-practices intersect and conflict with security requirements. Prioritise these so that available resources are effectively used to address training, communication and awareness needs.
- Youll drive the delivery of targeted cyber-training, delivering training content that is bespoke and tailored to specific groups, operational needs and audience capabilities. Youll steer the creation and use of existing training materials and programmes, and create and curate new content for other channels to cascade and deliver IT Security awareness-improvement throughout the business. Youll act as our behavioural and cultural Security Champion across other disciplines, driving beneficial security change.
- Ensure that the requirements of the role remain aligned with threats and risks, industry trends, changes of best practice advice and government guidance. Use that knowledge to raise awareness throughout the business to positively influence business strategy and culture.
Reporting Line
Reports directly to IT Compliance and Risk Manager.
Staff Responsibilities
This role will manage and engage as necessary with external consultancy resources, specifically our appointed Cyber Security consultancy. The position is expected to have responsibility for directing junior staff within the function.
Financial and Budget Responsibilities
Manage a delegated budget for programme activities. Jointly responsible for all aspects of ITSec financial management including forecasting and reporting of future IT Security requirements.
Working Relationships
You will be working closely with the IT Compliance and Risk Manager, the IT Security Systems Manager, colleagues within the Forestry England IT Team and the SRMF. You will create and maintain effective, positive relationships within scope of the role across all Forestry Commission departments and Business Units as well as 3rd parties, suppliers, consultancy services, and partner organisations.
Working Patterns
This is a full-time position but there is scope for flexible hours (working the hours that suit your lifestyle) within reason, and blended/hybrid working (you’ll be able to work from home when agreed).
Person specification
Essential Criteria
A formal qualification or accreditation in the field of IT Security, OR proven experience in a governance, communications, audit or IT Security role or very similar.
Strong demonstrable experience and knowledge within an enterprise or business IT environment across at least one of the following fields and as set out in this job description:
IT Security Governance, IT Security Compliance, IT Security Risk and IT Security Audit.
Enthusiasm for spreading security-awareness in writing and through presentation.
Strong familiarity with enterprise IT security or service-provision requirements.
The ability to write fluently, accurately and concisely with clarity.
Proven abilities documenting and presenting concise reports, explaining complex information to varied audiences.
Youll have a track record of good judgement and pragmatic decision making; communication skills with an ability to listen, influence and negotiate outcomes, and be able to speak, guide and assert with authority.
Youll have experience of managing challenging situations and circumstances with discretion, respecting confidentiality, with fairness, honesty and empathy.
There will be a requirement for occasional travel and work away from your reporting point. You must be prepared for this and hold a full UK driving licence. Driving is the only way to efficiently reach many of our business locations.
Location is flexible for this role, but based around use of one of the existing Forestry Commission offices in the North-east or South-west of England and blended home working. The post holder will be expected to occasionally travel throughout England with some overnight stays, including at the Bristol national office.
There will be an expectation that you contribute when unplanned requirements, such as security incidents or failures, necessitate additional hours of work over and above contractual hours of work.
Desirable Criteria
Strong relationship-building and collaboration skills, with experience of negotiation and problem solving.
Experience with policy and procedural creation.
A demonstrable track record in either training or communications.
Strong familiarity with typical Line of Business applications; Microsoft 365,(Teams, SharePoint, Outlook, Excel, Word).
A track-record of the ability to influence and guide senior IT leadership team on strategy direction and delivery.
Youll help identify opportunities to engage, promote and champion beneficial security changes. Youll be able to demonstrate that youve influenced projects and their delivery to ensure wider positive adoption and use.
An understanding of the requirements and principles of GDPR and the Data Protection Act 2018.
BCS professional membership or membership of other authoritative body
Awareness of IT service frameworks such as ITIL.
Ownership of your personal development to ensure you are equipped with the skills relevant to the proposition, now and in the future
Behaviours
We’ll assess you against these behaviours during the selection process:
Benefits
£9,684 towards you being a member of the Civil Service Defined Benefit Pension scheme.
Find out what benefits a Civil Service Pension provides.
- Learning and development tailored to your role
- An environment with flexible working options
- A culture encouraging inclusion and diversity
- A great, inclusive and friendly work-team with a supportive work environment
- A Civil Service pension with an average employer contribution of 27%
- This is a full-time role but with scope for blended/hybrid and flexible working (working from home at hours that suit you and us the most).
Things you need to know
Selection process details
Application Process
As part of the application process you will be asked to complete a CV detailing your job history, qualifications, and previous experience/skills.
You will also be asked to provide a personal statement (up to 1000 words) describing how you meet the essential criteria (detailed in the person specification) in the context of this role.
Sift for interview will be conducted based on the CV and personal statement.
Interviews
We may conduct online interviews with the use of Microsoft Teams. Candidates would therefore require access to a computer and internet at interview stage.
At interview you will be assessed against experience, behaviours and strength based questions.
Sift and interview dates to be confirmed.
Further Information
A reserve list may be held for a period of 12 months from which further appointments can be made.
Any move to Forestry Commission from another employer will mean you can no longer access childcare vouchers. This includes moves between government departments. You may however be eligible for other government schemes, including Tax Free Childcare. Determine your eligibility at https://www.childcarechoices.gov.uk
If successful and transferring from another Government Department a criminal record check may be carried out.
In order to process applications without delay, we will be sending a Criminal Record Check to Disclosure and Barring Service on your behalf. However, we recognise in exceptional circumstances some candidates will want to send their completed forms direct. If you will be doing this, please advise Government Recruitment Service of your intention by emailing Pre-EmploymentChecks.grs@cabinetoffice.gov.uk stating the job reference number in the subject heading.
New entrants are expected to join on the minimum of the pay band.
This role is full time only. Applicants who wish to work an alternative pattern are welcome to apply however your preferred working pattern may not be available and you should discuss this with the vacancy holder before applying.
Reasonable Adjustment
If a person with disabilities is put at a substantial disadvantage compared to a non-disabled person, we have a duty to make reasonable changes to our processes.
If you need a change to be made so that you can make your application, you should contact Government Recruitment Service via fcerecruitment.grs@cabinetoffice.gov.uk as soon as possible before the closing date to discuss your needs.
Complete the Assistance required section in the Additional requirements page of your application form to tell us what changes or help you might need further on in the recruitment process. For instance, you may need wheelchair access at interview, or if youre deaf, a Language Service Professional.
If you are experiencing accessibility problems with any attachments on this advert, please contact the email address in the ‘Contact point for applicants’ section.
Feedback will only be provided if you attend an interview or assessment.
Security
Nationality requirements
Working for the Civil Service
We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission’s recruitment principles (opens in a new window).
Apply and further information
You may want to save a copy for your records.
Contact point for applicants
Job contact :
- Name : Phil Brown
- Email : philip.brown@forestryengland.uk
Recruitment team
- Email : fcerecruitment.grs@cabinetoffice.gov.uk