Security and Information Risk Advisor
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Are you ready to drive effective information security risk management for a vital public service? Join us as a Security and Information Risk Advisor within our Digital Risk & Security branch, where your expertise will guide our commitment to protecting Social Security Scotland. If you are passionate about cyber security and have a keen interest in safeguarding critical information, to join our talented team and take the next step in your career.
TypicalRole Level Expectations
- Provide advice and guidance on security strategies to manage identified risks and ensure adoption and adherence to standards.
- Obtain and act on vulnerability information and conduct security risk assessments and business impact analyses on complex information systems.
- Investigate major security breaches and recommend appropriate control improvements.
- Contribute to development of information security policy, standards and guidelines.
- Interpret information assurance and security policies and apply these to manage risks.
- Use control testing information to support information assurance assessments.
- Conduct risk-based assurance reviews of internal solutions and third‑party suppliers, assessing control effectiveness, identifying risks and vulnerabilities, and recommending remediation activities to support compliance and informed risk‑based decision-making.
- Manage complex risks, issues, remediation activities, and lessons learned, applying appropriate risk methodologies and advising on risk impact, tolerance, and mitigation strategies.
- Design and review secure system architectures, applying architectural principles, patterns, and appropriate levels of rigour to deliver effective business outcomes.
- Assess the impact of vulnerabilities, emerging technologies, and developments in security technologies on existing and future systems, recommending appropriate responses and controls.~
- Build and maintain effective stakeholder relationships, managing expectations, resolving issues, and facilitating discussions on complex or high‑risk matters, often within challenging timescales.
- Represent the security profession and communicate complex technical and risk concepts to a wide range of audiences, both internally and externally.
- Apply knowledge of systems, security, policy, business architecture, and legal or regulatory requirements to develop secure technical solutions and controls.
We use an assessment framework called ‘Success Profiles’ which lists the elements we test and provides detailed descriptions of each. Find out more about the framework here.
For this post, the following Success Profile elements will be assessed:
Experience- Knowledge of information security standards like ISO/IEC 27001 and NIST SP 800‑53, combined with understanding of current legislation such as DPA 2018 and GDPR. Proven ability to interpret and apply these standards and legal requirements to ensure compliance and integrate best practices into organisational operations.
- Demonstrable ability to evaluate the effectiveness of technical, physical, procedural, and personnel controls, recommend improvements, and work with stakeholders to implement proportionate risk mitigation measures that strengthen the organisation's overall security posture.
- Communicating and Influencing
- Level 3 - Delivering at Pace
- Level 3
This role is aligned to Security and Information Risk Advisor within the Government Digital and Data Profession.
These skills will be tested during the Technical Assessment if you are successful at sift stage. They will not be assessed at application stage. Please review the following to understand the skill expectations:
Security and information risk
- Information Assurance and Security:
Security and information risk - gov.scot
We are holding a candidate information session for this role to provide you with information about the application and interview process as well as further information on the role and team.
We Will Be Talking About- The Security and Information Risk Advisor role and Digital Risk and Security team
- About Social Security Scotland
- Our recruitment process
- Q&A with the hiring…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: