- Company Name
- The Scottish Government
- Job Title
- Security and Information Risk Advisor
- Job Description
-
**Job title**
Security and Information Risk Advisor
**Role Summary**
Provide expert risk assessment and advisory services for cyber and information security across government digital services. Drive the development, implementation, and compliance of security policies, standards, and controls in cloud and complex information systems. Act as a trusted advisor to stakeholders, ensuring risk-based decisions and resilience against evolving threats.
**Expectations**
- Deliver clear, actionable advice on security strategy, risk mitigation, and assurance activities.
- Maintain up‑to‑date knowledge of industry standards (ISO 27001, NIST, PCI DSS, Cyber Essentials, CAF, GovAssure, HMG GovS 007).
- Communicate effectively with technical and non‑technical stakeholders, including senior officials, customers, and suppliers.
**Key Responsibilities**
1. Conduct comprehensive cyber‑security risk assessments, business impact analyses, threat assessments, and threat modelling for complex systems.
2. Define and assess security requirements to support business operations, regulatory compliance and strategic objectives.
3. Contribute to the creation, review, and maintenance of information‑security policy, standards, guidelines and assurance architecture.
4. Evaluate effectiveness of risk‑mitigation measures (e.g., penetration testing, monitoring) and recommend improvements.
5. Provide high‑level risk briefings and strategic advice to system owners, project teams and procurements.
6. Ensure alignment with relevant governance frameworks and secure adoption of standards and best practices.
7. Support assurance and compliance activities, including internal audits and external regulatory reviews.
**Required Skills**
- Proven knowledge of security architecture and integrated solution design.
- Experience managing cyber‑security risks in digital and cloud environments.
- Advanced understanding of ISO 27001, NIST, PCI DSS, Cyber Essentials, CAF, GovAssure, and HMG GovS 007 guidelines.
- Ability to perform and interpret risk assessments, threat modelling, and business impact analyses.
- Strong written and verbal communication, capable of presenting complex technical material to diverse audiences.
- Demonstrated ability to influence stakeholder expectations and secure adherence to security policies and controls.
**Required Education & Certifications**
- Bachelor’s degree (or equivalent) in Computer Science, Information Security, IT Governance, or related field.
- Professional certifications preferred: ISO 27001 Lead Implementer/Lead Auditor, CISSP, CISM, or equivalent.
---